Can a hostile container sneak past your eBPF tracing? Sometimes, yes.
With @OSTIFofficial & @CloudNativeFdn we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…).
Work by @ndaprela & @suidpit👏
🔗 https://t.co/LktKoqX7it
🚨 New Open Source Audit Alert! 🚨
Shielder, with @OSTIFofficial & @AcademySwf, audited OpenEXR and MaterialX:
🔍 11 issues found (1 critical, 3 still to be published)
✔️ Most fixed, others planned
🗣️ to @ndaprela@smaury92@suidpit @Th3Zer0
Full details in the blog post ⬇️🧵
Last week @Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit exploited to escape the Sandbox.
Update now and stay tuned for the technical details!
Ref: https://t.co/fSRCbM8WbQ
The second edition of TumpiCon is here!
📅 June 27-28, 2025
📍 Somewhere near Turin, Italy
🔒 Invite-only
No flashy stages. No fluff. Just raw, technical, and unfiltered hacking.
More details? If you know, you know.
Follow the trail: https://t.co/blVUiOEESj
👋🏿 hackers, make sure to check your inbox - we started sending the invites for #TumpiCon2023!
If you did not receive one and you like to join us: DMs are open (pro tip: proposing a talk is an awesome way to raise your chances of receiving an invite 😉).
We are excited to release Cutter v2.0 — our first release with @rizinorg 🚀
We introduce major improvements to Cutter, including support for Projects, Reverse Debugging, better stability, and more.
Learn more in our blog post: https://t.co/G984BsgRna
🎉 Our big 2020 research is finally public 🎉
Discover how @polict_ went from close-to-0 knowledge in fuzzing to crafting 13 0-days in @Telegram!
https://t.co/sXZ5MM8BYw
To close out 2020, we bring you JavaScriptCore Internals Part 2, a guide on Llint and baseline JIT for exploit development.
https://t.co/rJRykXvOSs
We wish all a Happy New Year. May 2021 bring you shells o' plenty. But above all the chance to reunite with friends ✌️
"Corellium, a security research firm sued by Apple, has won a major legal victory against the iPhone maker. A federal judge in Florida threw out Apple’s claims that Corellium violated copyright law with its software, which helps security researchers find bugs and security holes."