We took home Master of Pwn at #Pwn2Own Berlin 2026 with 50.5 points, pwning Microsoft Edge, Exchange, Windows 11, and SharePoint.
Edge was the only successful Browser entry, Exchange earned the highest single-target prize — and no memory bugs this time.
#P2OBerlin
Cloud Security Engineer is not "DevOps plus a firewall."
You write SCPs blocking rogue regions. You build Terraform modules with encryption guardrails. You hunt IMDS credential theft across 200 accounts.
$90K to $300K+. 33% growth through 2032.
https://t.co/bOO5uFfDfS
DevOps City
Your DevOps infrastructure is a city. Everything runs smooth until an incident hits.
You're the mayor. Find what broke, fix it.
This round: CI/CD pipeline security.
https://t.co/oAdA9g7edR
#game#devops#cicd#devsecops
Hacking Renesas chips for cars: three glitching resources to boost your success. 🚙⚡🫨🔬👨🏻💻
More details on:
LinkedIn: https://t.co/07EtcGaitv
Substack: https://t.co/wZ1qhzcHWv
⚡ Potentially Critical RCE Vulnerability in OpenSSL - CVE-2025-15467 ⚡
The JFrog Security Research team is tracking a newly disclosed OpenSSL stack overflow vulnerability rated as High by OpenSSL, that may lead to remote code execution (RCE). This vulnerability was patched with other 11 moderate and low severity vulnerabilities.
The stack overflow can be triggered by sending a crafted CMS AuthEnvelopedData message with malicious AEAD parameters. While no official CVSS score has been assigned yet, based on its characteristics, we assess it may be rated at least High or even Critical by NVD.
Our team reproduced the issue by invoking the CMS_decrypt API directly, confirming that OpenSSL applications parsing untrusted CMS data via this API are vulnerable. Exploitation is also possible when using the `openssl cms` CLI to decrypt untrusted input.
A contextual analysis scanner for this CVE is now available for JFrog Advanced Security customers:
I wrote a C2 agent in pure PIC C (minus one constexpr). I'd love to hear any suggestions on how to handle memory management better or reduce the output size. Cheers! https://t.co/kBxidambs4
Our talk at #BHEU is done! Hope you all enjoyed it. 😉 A detailed blog is on the way, but in the meantime, check out the pre-alpha website https://t.co/lGRfqhmcVK for early access and the slides!
Huge thanks to @BlackHatEvents and my awesome co-presenter @_splitline_! 🐈