Finally published the blog post about abusing @Zoom for remote attacks on endponits:
https://t.co/ExkeyYooBM
It was fun to present this at @BlackHatEvents
An interesting wrap-up presentation from the security researcher who found the COROS watch security vulnerabilities last year. Worth a watch if you're into geekery: https://t.co/dA7G5zWHnO
Today, a tech blog article by my colleague Christian Zäske titled "MeshHacks: Exploiting Linksys Intelligent Mesh from the Internet" concerning six security vulnerabilities in different Linksys routers was published.
https://t.co/WURPqYK3hl
Today, I have published a new YouTube video about browser swapping attacks, demonstrating and explaining a security issue in OAuth 2.0 that my colleague Jonas Primbs found.
https://t.co/pxydaAKMIJ
⌚ A sports watch you trust on every run…or do you?
At #hw_ioNL2025 Moritz Abrell takes us behind the scenes of the #COROSPACE3, where a routine BLE assessment spiralled into discovering hidden vulnerabilities & a public wake-up call for the vendor.
👉https://t.co/NqVUh0XkU5
I'm back home from the beautiful city of Bergamo and the awesome @nohatcon.
Today, we have published the security advisories concerning the Verbatim security update I was talking about on Saturday in my presentation "Your Security Update is Not Secure Enough".
Today, my colleague @moritz_abrell published a new tech blog article titled "Automated Patch Diff Analysis using LLMs", and it's about what its title suggests. 😄
If you're interested in LLM-based workflows and IT security, you should read it here:
https://t.co/XGbRcZ5YA6
Today, my new blog article titled "Voltage Glitching with the Pico Glitcher and Findus" was published.
You can find it on the SySS Tech Blog:
https://t.co/4jifAWrE1I
Check out our today published CVEs on @AudioCodes Session Border Controller and One Voice Operation Center.
Unauthenticated path traversal, hard-coded keys and unauthenticated persistent XSS.
https://t.co/7W9SDuryak
CVE-2024-52883
CVE-2024-52882
CVE-2024-52884
CVE-2024-52881
Today, I've published the security advisory SYSS-2024-085 (CVE-2024-38499) concerning a security vulnerability in the desktop and server management software CA Client Automation by @broadcom.
You can find further informationen in the SySS Pentest blog:
https://t.co/RAIhYTEnqo
I am currently working on version 2 of the PicoGlitcher (https://t.co/v9x5aaKkPD) to perform #FaultInjection and #VoltageGlitching. Here is a teaser what it can achieve. Version 2 is capable of basic pulse-shaping.
Today, SySS published several security vulnerabilities concerning the SICK products InspectorP61x, InspectorP62x, and TiM3xx. These issues were found by my colleagues Manuel Stotz and Tobias Jäger.
You can find further information in the SySS blog:
https://t.co/QLu9u25SgX