Send a GIF, crash a phone. The fix for CVE-2025-48631 missed a code path and the bug is still there. New blog post on how I found it
https://t.co/uK0oMhypb4
Conducted IoMT PT on one of the large manufacturers of different medical devices, critical flaw leads to access their azure!
Here is how:
TL;DR
Frontend application was running on kiosk mode, backend was win with restrictions such as application control, where you cant,
[1/n]
Started my smart contract auditing journey after completing the @CyfrinUpdraft course with @aiarena_@code4rena contest.
Reported 3 high severity bugs, waiting for the contest results to see how i performed.
#0day#research#bugbounty#informationsecurity https://t.co/hMzpulkHUW
How I *AM* able to abuse Akamai to abuse F5, to abuse all of their customers. This is a bug chain that doesn't require a bug on the target domain to exploit them. But what do I know, I am a freelance nobody.
Today I am finally releasing a new 3-part browser exploitation series on Chrome! This was written to help beginners break into the browser exploitation field.
Part 1 covers V8 internals such as objects, properties, and memory optimizations. Enjoy! https://t.co/bbFjOOzlOu
@LukasStefanko@artem_i_baranov yeah there is typo in the blog, or should i say learnt it saying 'transversal' instead of 'traversal' 😅. Thanks @artem_i_baranov for pointing out my mistake.