Congratulations to all the researchers recognized in this quarter’s MSRC 2021 Q3 Security Researcher Leaderboard! For a full list of top researchers, check out our blog post: https://t.co/MJUsRjRSDr
We (+@nirohfeld) found a critical vulnerability chain in NVIDIA's Triton Inference Server (CVE-2025-23319) that can lead to full Remote Code Execution (RCE).
An unauthenticated attacker can remotely take over the server, a cornerstone of many AI/ML production environments. 🧵
This was a huge effort from the team. With every small primitive we discovered, we got closer—until we finally landed a full unauthenticated RCE. I had a ton of fun working on this research. ☸️👇
Funny lil thing I had to check. #WhatsApp `secret chat` feature isn't as secure as you'd hope. Found a funny way to easily bypass it. It’s supposed to provide local/physical protection to your convos but don't trust it with your super secret convos! 😅. Report dismissed by #Meta.
We discovered a container escape vulnerability in the @NVIDIA Container Toolkit. It allows attackers to gain full access to the host's filesystem and achieve Remote Code Execution (RCE).
Here's everything you need to know about CVE-2024-0132 🧵👇
🔥New on #SentinelLabs! A must-read for fuzzing fans, this post gives a detailed look at the advanced techniques used in our recent discovery of multiple bugs in Defender for #IoT. By @kasifdekel.
Read the blog: https://t.co/Ql3uP3jLrd
#fuzzing#cybersecurity#defender
🔥New on #SentinelLabs! We’ve just disclosed 10.0 CVSS vulnerabilities on Microsoft’s Azure Defender for IoT allowing unfettered access to your Microsoft-protected organization. By @kasifdekel & @ronenshh.
https://t.co/e8TvQEhM5z
#azure#iot#xdr#vulnerabilities
- Use-after-frees from JIT
- CodeQL for variant analysis
- Never-before-seen exploit primitives
- Tenured heap tomfoolery
I’ve packed just about everything in this post!
Windows Defender AV allows Everyone to read the configured exclusions on the system 🤦
reg query "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions" /s
Sorry about that @FlowerCode_ & @tiraniddo, I reported a LPE vulnerability and they decided to remove it. Hoped they'd release a fixed version. I find DeviceTree useful too and you can find a signed version in the repo alongside with the vuln details: https://t.co/9w6SciFonw