Tis the season again :)
Forgive the poor audio and recording, was all from phone and final test run before go live: https://t.co/JExbLAq1a7
Socials:
- https://t.co/BNn6rLVymy
- https://t.co/sy0GlNrLEG
CONFIRMED!! Ken Gannon (@yogehi) of NCC Group (@NCCGroupInfosec) used 5 different bugs, including a path traversal, to get a shell & install an app on the #Samsung Galaxy S24. He earns $50,000 and 5 Master of Pwn points. #Pwn2Own#P2OIreland
No days like 0days!
Recently we've been speaking at conferences about the logic bugs we've been using at the Pwn2Own contests against Samsung and Xiaomi phones for a very long time. Our @offensive_con slides are up now:
https://t.co/QSGgpnIte1
@ha888t 1. It’s a proper shame. Over the years it’s got worse and worse. Used to be a lovely city to visit. Was on my fav list.
2. You’ve been going to different Vegas parties at hacker summer camp in Vegas to me then.
Confirmed! NCC Group EDG (@nccgroupinfosec, @_mccaulay, and @alexjplaskett) successfully used a 2-bug chain against the Alpine Halo9 iLX-F509. Style points for playing DOOM on the device! #Pwn2Own
Correction – Success! Ken (@yogehi) and Ilyes (@040xZx) of NCC Group (@nccgroupinfosec) were able to execute their attack against the Xiaomi 13 Pro. They earn $20,000 and 4 Master of Pwn points. #Pwn2Own
There's just one week left to complete our research survey! If you want the Government to understand how the 1990 Computer Misuse Act affects your cyber security research, then be sure to fill it in 👾
https://t.co/gQTkCQiUn8
#CMA#cybersecurity
1/ I kinda accidentally owned myself with my own shadow workflow attack. I definitely think they are going to become a standard technique. I mean they are pretty much the offensive powershell of the SaaS world!
So how did this happen?
Slides from @alexjplaskett talk at @syspwnx have now been released:
https://t.co/geZXYYaOsp
Covering vulnerability research for Pwn2Own, Soho-smashup and printer vulns.
We did a thing! It's over 10 years since we started working on this but it's still useful today:
https://t.co/ZZKTxlzsTO
Kudos to @pentestmonkey for porting the Perl bits to a modern language.
#aix#solaris#linux#unix#security
Requiring a "skilled person" write a report before mass surveillance is imposed does little
Especially given that the UK gov HAS ALREADY heard from hundreds of "skilled" experts restating longstanding consensus: there's no such thing as a safe backdoor.
https://t.co/TQzyCk5x2z
There has been much discussion about the likely failure of Thames Water in the last day or so. I’ve been looking at the accounts of England’s water companies for the last twenty years. My conclusion is that they are all environmentally insolvent. So, a thread…..