#VisualStudio 1-click RCE, No Smartscreen warning, No trust need, No futher interaction need. Just download from internet, 1-click then pwn. But it will not be fixed, because Microsoft consider it's not a vulnerability😅
Today, we're announcing the immediate availability of the Ferrocene release candidate! We're also inviting you to our birthday party on October 4th, where we will meet online with guests, have fun conversations and unveil the Ferrocene product fully.
https://t.co/R68ct80sua
🚨 New Advisory: RWS WorldServer 🚨
https://t.co/giDUO6mWxe
The vulnerability allows to feasibly enumerate session tokens. While it was fixed by the vendor prior reporting, no concrete information is publicly available that this critical issue was fixed in v11.8.0.
#infosec
Okay, so why are we releasing a free tool to see which companies are exposing secrets?
A little while ago we started doing disclosure emails for every key leaked out, but we were shocked to with what we saw
Short 🧵
🎉 Go 1.20.6 and 1.19.11 are released!
🔐 Security: Includes security fixes for CVE-2023-29406 and Go issue https://t.co/TvnTCb3lMm
📢 Announcement: https://t.co/6ahFqq7ifS
📦 Download: https://t.co/OmPG7Q663K
#golang
📢📢📢 Accepted Talks and Speakers' Bios published 📢📢📢
Thanks to all who applied to our #CfP and to our reviewers, the list of accepted talks is now on our website. Detailed agenda will follow
https://t.co/X9lvNUOu1c
REMEMBER: Tickets sale starts tomorrow 3pm Zurich time 🥳
@N4hualH @CyberSleuth1@solminingpunk@BruteBee There might already be active exploitation on this. Check for files newer than the installation date in /netscaler/ns_gui/ /var/vpn/ /var/netscaler/logon/ /var/python/
"Sollte es jedoch Zero-Day-Exploits bei Messengerdiensten geben, müsse das BSI diese konsequenterweise verschweigen, wenn "andere Stellen" diese offenhalten wollten."
https://t.co/QUYzKazpOx
After holding the talks at @x33fcon
and @WEareTROOPERS
done, I also finally managed to write down my latest research about userland hook evasion:
https://t.co/h8EvPIz89z
"Log Centralization: The End Is Nigh?" https://t.co/jPu5VWqLrS <- a VERY incomplete thought blog that talks about centralized vs decentralized/federated/distributed approaches for dealing with logs, at scale.