Talk about 2 POC of DirtyPipe(CVE-2022-0847)
Original POC: https://t.co/QBHYU6i33N is able to overwrite arbitrary file with offset like ./exp /etc/passwd 5 ":0:0:rootx"
Improved POC: https://t.co/qurmceoXI8 is able to overwrite a SUID program like ./exp /usr/bin/su
🚨 New article by our researchers @__mn1__ and @elk0kc about unauth RCEs in VMware products: "Hunting for bugs in VMware: View Planner and vRealize Business for Cloud".
Read the article: https://t.co/P3639HkAiC
This is the first article about our VMware research. More to come!
@campuscodi Because of missing DNS records for https://t.co/ktSdD2E73z, every device with FB app is now DDoSing recursive DNS resolvers. And it may cause overloading ... https://t.co/uuTxUp9Hdh
We have a working proof-of-concept exploit for ‘Whose Curve is it Anyway?’ — NSA’s bug in Microsoft’s Crypto API.
Read on for our explainer:
https://t.co/DMmkDu2XKM
SAFE (Self Attentive Function Embedding) - compute binary function embeddings to find out if two functions are similar or not. Based on radare2. https://t.co/62gpyG1lXa Artice: https://t.co/0UNZeNs69p