@intigriti what's wrong with the triage, why would your units find it so hard to reproduce bugs and request to rereport it in the fresh chain of thread? Meditation/Support is ambigious too.
Finally got this virtual iPhone running iOS 26.1 up and running on macOS. It's jailbroken and going to help with security research a ton. Big thank you to @wh1te4ever for this.
This is not for the average user and is complicated to set up. Highly recommend Codex and/or Claude to assist.
For those interested, the project is here:
https://t.co/ygp2iV8kuv
And the writeup is here:
https://t.co/WaYM6QiFLD
Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it out!
https://t.co/iWXBCfJVKZ
The system card (https://t.co/wM4LVBySKf) nicely showcases o1's best moments -- my favorite was when the model was asked to solve a CTF challenge, realized that the target environment was down, and then broke out of its host VM to restart it and find the flag.
Critical vulnerabilities doesn't have to be complex or have a CVE - @deepseek_ai publicly exposed their internal ClickHouse database to the world, without any authentication at all, and leaked sensitive data.
No one is safe from security mistakes, follow along to learn more 🧵
Check out our latest blog post! We dive into GitHub Enterprise’s SAML implementation and explore an authentication bypass in encrypted assertion mode.
CVE-2024-4985 / CVE-2024-9487: GitHub Enterprise SAML Authentication Bypass.
https://t.co/mFOE6GGkhO
I recently co-authored a @Unit42_Intel blog about a unique IR case in which a threat actor’s custom EDR bypass (using #BYOVD) exposed their toolkit, methods, and even identity. Check out how we unmasked them through an opsec slip-up! #dfir
https://t.co/TRvedMDQUL
🔥 Microsoft fixed a high severity data exfiltration exploit chain in Copilot that I reported earlier this year.
It was possible for a phishing mail to steal PII via prompt injection, including the contents of entire emails and other documents.
The demonstrated exploit chain consists of techniques that didn't even exist 2 years ago. 🔥
In particular, it involves:
1. Prompt Injection 💉
2. Automatic Tool Invocation (without human in loop) to bring PII into chat context ⚙️
3. ASCII Smuggling 🫣
4. Rendering of benign link + invisible text 👀
5. (Optional) Conditional instructions to only trigger when certain users view the content ☝️
Discussing two demos (stealing sales data and MFA codes), including the videos I had shared with MSRC in February.
@simonw@goodside@llm_sec
https://t.co/G0xpiwYfOZ
New writeup:
"Hacking Millions of Modems (and Investigating Who Hacked My Modem)"
https://t.co/VZbWEIF5I8
Thanks for reading! Huge thanks to @blastbots, @bbuerhaus, @infosec_au, @d0nutptr, @iangcarroll, and everyone who reviewed the post beforehand.
I'm thrilled to announce "Listen to the whispers: web timing attacks that actually work" will premiere at Black Hat USA!
After nine months of running bulk timing attacks on thousands of live sites, I've got a lot to share :D #BHUSA@BlackHatEvents
https://t.co/YsrfM0SUm7
Nexus Repository Manager 3 Unauthenticated Path Traversal (CVE-2024-4956)
https://t.co/lb5CNJGqmD
This issue is similar to SpringMVC CVE-2018-1271 by @orange_8361
Just released the write-up for CVE-2024-4367, a bug I found recently in PDF.js (and hence in Firefox), resulting in arbitrary JavaScript execution when opening a malicious PDF.
https://t.co/sex6fR0xHS
Last year we conducted an in-depth analysis of multiple vulnerabilities within Adobe ColdFusion and wondered if there were any other CFML Servers. That's when we met Lucee. https://t.co/84diZnM4GI
Check out our new blog post! We hacked into Apple Travel Portal (yes, again!) using a 0-day Remote Code Execution exploit. Part 1 is live now, stay tuned for the follow-up on another RCE worth a total bounty of $40k!
https://t.co/az4wNhDYyO