I keep reading the state of triage blogs. I will tell you this, I'm sitting on now two 0click rce vulns for two separate phone vendors.
One more phone vendor and I have RCE on like 99% of the telco market.
Am I the only one that makes hilarious names on Peleton and try to get in the leaderboards so the instructors say it?
"You killed it today Stu Pidas"
"Harry Balsonya did work today"
@evilsocket Oh I totally agree. I have been using Sonnet now. I can't use Opus anymore. It's like I traveled back in time to a dumber, less usable model.
Lol, spent 4 weeks deciding to migrate my Critical to a medium risk because the PII wasnt "sensitive enough". But they patched the vuln in less than 1 hour...
Money must be tight. The $50k bounty was too much to pay. I understand 👍
Shareholders don't want to see that stuff.
@thedawgyg They patched like 30 critical findings last week and judging by the amount of reports I have sitting in triage for a month they probably have so many.
I'm gonna rant for a second:
I found a Zero-Click RCE in the latest Samsung phones in February.
Samsung says it's "Out of Scope" because "AOSP Source."
So I go to Google, they say it’s High, not Critical, because "AOSP Baseline."
My RCE still sitting in the wild, no patch😬
@te3co I have a second one but its the same fix. So im waiting until I see how they fix it and then if they dont fix it the way i think they will. I'll just drop it here 🤣