💥 Introducing "Dirty Frag"
A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail.
No race, no panic on failure, fully deterministic. ~9 years latent.
Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more.
Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation.
Details:
https://t.co/9nqku4svkY
NOPcon is back! Call for Papers is now open. After a long break, we’re opening the doors again to the community.
If you have something cool to share, this is your stage. Submit your work: https://t.co/oZYPf32tgt
#nopcon2026
The one last dance of my phd career is finally published. ropbot (or angrop) can generate ROP chains for x86/x64/arm/aarch64/mips/riscv. The old version of it is already adopted by Google's kernelctf program (and some other orgs ;) ). https://t.co/tL6QvlABP2
I just released our kernelCTF VSock 0-day write-up with @_qwerty_po . (exp196/exp197, CVE-2024-50264)
https://t.co/8UpGrVcDFF
We made history by being the first to exploit VSock in kernelCTF, expanding its known attack vectors. 🥳
It’s a pretty *simple* race condition, right?
Imagine opening a Discord message and suddenly your computer is hacked.
We discovered a bug that made this possible and earned a $5,000 bounty for it.
Here's the story and a beginner-friendly deep dive into V8 exploit development.
Watch: https://t.co/QtAro4fj4t
@StmCTF Bir takımdaki üye sayısı en az 2 (iki) ve en fazla 4 (dört) gerçek kişiden oluşabilir. -- kuralını ihlal etmişim tek başına oynamak yasakmış 🤣🤣😂😂
[#Zer0Con2025] - Announcements
'Challenge the norms, break boundaries'
Zer0Con2025 CFP / CFT is officially opened
📅Date: 10~11th April 2025
🏩 Venue: Fairmont Ambassdor Seoul, South Korea
🎟️Entry badge: 100 available
🌖 CFT status: Partially open due to limited space
🌕CFP status: Open
🌕Sponsor status: Open
For more: "zer0conadm at gmail"
Jaewon Min(@binerdd ) & Kaan Ezder(@kaanezder)
Fake it till you make it: Bypassing V8 Sandbox by constructing a fake Isolate
https://t.co/M7pUoEk2Ik
It’s been a busy month for our Gecko teams around the world… 🌍
Last month, we were in Paris for Hexacon.
This week we are in Seoul for POC.
Next week we are in Argentina for Ekoparty!
If you want to join an elite global VR team, you know what to do.
Ekoparty 2024 Binary Gecko Challenge 🇦🇷
Complete the challenge to get a ticket to our VIP dinner/party event in Buenos Aires during the conference.
Winners will also get an interview for a Security Researcher position at Binary Gecko.
https://t.co/1hKmSwQkhN