Big win at #DefCon33! #Qualys Threat Research Unit (TRU) takes home Epic Achievement + Best RCE at the #PwnieAwards for:
- CVE-2024-6387 (regreSSHion) — 1st pre-auth RCE in OpenSSH in 20 yrs
- CVE-2025-26465 — MITM attack on OpenSSH client
#vulnerabilityresearch#TRU
The Qualys Research Team has discovered two vulnerabilities in multipathd, the most important of which can be exploited for authorization bypass. Qualys recommends security teams apply patches for these vulnerabilities as soon as possible. https://t.co/pS8deBBtaU
Hello hackers! Sorry to overwhelm you with @pwncollege news, but we just launched the first new module of the new White Belt material: Talking Web (https://t.co/cKePfnRgn0)! A few more details below 🧵
Check out our blog post to learn results from our experiments with Paranoid (https://t.co/21wnh9dTfk). Our open-source project that detects the usage of weak cryptographic artifacts, such as public keys and digital signatures --> https://t.co/ky56mdGO3u
#OST2 class URLs are versioned. Here's some short URLs suitable for citation that will always point at the newest full classes:
https://t.co/ROHbpbM8uX
https://t.co/vDEqCuvpyA
https://t.co/ciPFUasY1c
https://t.co/l7nHc5L12g
https://t.co/EzBMwClyim
https://t.co/SrxvCg76MA
...
Calling EU bug hunters ..
@nullcon is giving out 10 FREE tickets to "EU based” Bug hunters/researchers to visit nullcon Berlin, here is the link to apply https://t.co/6Rprv0DyA5
Date: 8-9 April 2022
Speakers: https://t.co/BAQYDOqvSB
I've published the article covering my talk at @ZeroNights!
Improving the exploit for CVE-2021-26708 in the Linux kernel to bypass LKRG
https://t.co/iZ8QRGbyhg
Slides:
https://t.co/5HcO2MNSYV
PoC exploit demo video: https://t.co/p6yMkNCeRL
Enjoy!
Exim mail server audit advisory released by @qualys - In total 21 issues reported by the research team, successfully exploited 4 LPEs and 3 RCEs , this is amazing! https://t.co/dKxetAnZg0
Super cool research about DOM parsing internals and namespace confusion bugs. The way @SecurityMB explains HTML standard and browser implementation variations is awesome!
ICYMI @SecurityMB explained a few DOMPurify bypasses yesterday (https://t.co/vT8BL4V7A1). Today we're publishing a first part of two-part series about how he helped secure DOMPurify:
https://t.co/BZ4dH9B0Rv
I've released NAT Slipstreaming, a spooky new technique that allows an attacker to remotely access any TCP/UDP service bound to a victim machine, bypassing the victim’s NAT/firewall, just by the victim visiting a website. https://t.co/UlOnJPftTv Happy Halloween!