@Random_Robbie@LargeCardinal All good here bud. Was hoping to cross paths at SteelCon but it clashed with Oasis. No idea what happened with BSides Liverpool either. You good bud?
Deserialization, reflection, and memory-resident shellcode execution come to mind with PrecodeFixupThunk being the first step of the JIT mechanism (hat-tip to @_xpn_ for weird ways to run unmanaged code in .NET!).
Anyone observed this, or have any more specific suggestions?
@vysecurity If it ain't snake oil on LinkedIn, it's some bullshit CVE with a 10.0 CVSS score that can only be exploited once you've already significantly compromised the target ๐ค
@ethicalhack3r Cheers Ryan! It's tough for sure. Definitely need to get the training miles in - and hopefully not injure yourself or be floored by flu ๐ Half marathon is a nice distance IMO but if you push yourself there you're definitely in danger of being tempted to do a full marathon.
That's another one ticked! Did not go as well as I'd have liked but it was a brutal one today. The heat took a lot of people out. Hope everyone's ok and congrats to the 92k or so marathoners today whether at London or Manchester! #ManchesterMarathon
CVE database is becoming a joke TBH, when things like CVE-2025-24859 are published with a CVSS score of 10.0 - To exploit this vulnerability you first need to obtain a valid session token, then you only maintain access to the corresponding user account... https://t.co/aDJX1f5ZSs
CVE database is becoming a joke TBH, when things like CVE-2025-24859 are published with a CVSS score of 10.0 - To exploit this vulnerability you first need to obtain a valid session token, then you only maintain access to the corresponding user account... https://t.co/aDJX1f5ZSs
@TheHackersNews I make that a 2.3 under CVSSv4.0, maybe even 2.1 - an attacker first needs to compromise an account, then they only maintain access to the account they already compromised. Who's reviewing/approving this stuff?! https://t.co/WxgCOk1gnd ๐ค