We would really like to get one of those new footballs that are currently being used in the stadiums during the European Championship matches. Just curious. 😁 DMs are open! #uefa#football#soccer#EM2024#ballleak <3
Lovely to see the Email RFCs abused to embed a command injection payload in the local-part of the address! Nice work Michael Imfeld & @parzel2
https://t.co/W62GHIVjd0
Shells at midnight: Exploiting the flexibility of Email addresses for offensive purposes.
Today we are publishing a new blog post about our disclosure report on #MailCleaner#CVE-2024-3191: https://t.co/XGOqYaGJbo
@[email protected] will also present at @a41con today.
We identified critical vulnerabilities in MailCleaner. A command injection vulnerability can be exploited by sending an Email. Our report can be found here: https://t.co/UbjGuZEvCW
Kudos to https://t.co/2sZjAckbdt and https://t.co/ap3QfuqatP #MailCleaner#CVE-2024-3191 #Infosec
Unfortunately this is necessary:
8532a9e0e49991ffdc3bfe7b728513e254e288a86275c6473e3b42228641e5fa MZ-24-01_8641e5fa.pdf
(and please find us on mastodon as well: https://t.co/zoggUhAynt)
Today we release the proof-of-concept exploits for the vulnerabilities we identified in HP #Poly VoIP devices. At the #37C3 we presented how these issues allow an attacker with network access to gain RCE and transform your devices into wiretaps.
https://t.co/iDKna43HUC
How do you hack Internet-connected devices? Today, our colleagues @parzel2 and @[email protected] will present their research at the #37C3 on how to turn a Poly VoIP phone into a wiretap, giving beginners some starting points for own research projects. https://t.co/hp83SqwBqy
Joining us for a second year as sponsor is @mod0. Thanks for your continued support!
Register at https://t.co/ygNVnUlW7e for one of the last remaining in-person tickets.
#BSidesBerlin#appsec#infosec#BSides
Better make sure your password manager is secure -- or someone else will. We found critical security issues in the enterprise password manager Passwordstate that allowed to access passwords and gain a shell -- without any authentication #CVE-2022-3875 https://t.co/CaMPH9W9sp
We are excited to welcome onboard @mod0 as our Gold Sponsors this year!
Register at https://t.co/ygNVnUmtWM for one of the last remaining in-person tickets.
#BSidesBerlin#appsec#infosec#BSides"
We found a security issue in the latest @CrowdStrike#FalconSensor. The bug itself isn't worth a tweet as the severity is pretty low. However, we’d like to shed some light on a ridiculous vulnerability disclosure process with CrowdStrike. #CVE-2022-2841 https://t.co/HFtL0uBQ6v
Meet our #infosec-veteran @rexploit at @a41con! He will provide some insights on our #MeetingOwl research during his talk on Friday and is happy to meet-up on the hallway-track.
Well as some questions start coming up regarding the #MeetingOwl insecurities. Here are some short and clear infos. Details in our report. https://t.co/MsU3zJnHAu