What better way to get into x'mas vibes than @flyingpassword dropping a BFS n-day (CVE-2025-29970) blog post! (Santa would approve :)) Merry X-mas!
https://t.co/Skmuu5rsU1
If u think that Windows research is all we do, think again! In our first IOT blog, @voix44er details the Wolfbox EV charger setup, attack surface, his #Pwn2Own Automotive 2025 bug, exploitation, and best of all, displaying our name on it (in styleee...)!
https://t.co/orDhcbZv6b
Happy Friday! Our intern, @__neverm0r_ , discovered and reported a NPD due to race-condition in afd.sys. Wasn’t assigned a cve doesn’t mean it’s less interesting, right!?
https://t.co/m7HDVQd5pj
Proud to see @_jaelkoh (with @saidelike) talking about undocumented internals of KTM, the bugs and exploits in 'Hunting for Overlooked Cookies in Windows 11 KTM and Baking Exploits for Them'. No ovens required for this recipe!
Confirmed (with a collision)! Rafal Goryl of PixiePoint Security used a 2 bug chain to exploit the WOLFBOX Level 2 EV Charger, but one of the bugs was previously known. He earns himself $18,750 and 3.75 Master of Pwn points. #P2OAuto
Annnddd... the odds ARE in your favor! Congrats @voix44er ! This result is just the cherry on the cake. Regardless of what it may be, what we don't see is the dedication and hard work put into the research.. 💪💪💪
Success! On his second attempt, Rafal Goryl of PixiePoint Security was able to exploit the WOLFBOX EV charger. He heads off the the disclosure room to provide us with all the details. #P2OAuto#Pwn2Own
Sometimes your past has a way of sneaking up/"garbage-collecting" on you.. Well done @b1thvn_, and thanks @TheZDIBugs for tracking these
https://t.co/nl6yONVKb3
https://t.co/WGFjeoxdbk
All shells are spawned equal, regardless of memory-corruption bugs or not!
CVE-2021-34462: Exploiting the Windows AppXSvc Service Logic-Error Vulnerability
https://t.co/QXgA780QPY
RCA for 1 of the 2 CLFS bugs patched in April 2022. While we can't determine the CVE, we did managed to exploit it ;) ... credit: @b1thvn_
https://t.co/OBDKYVKfe6
RCA for 1 of the 2 CLFS bugs patched in April 2022. While we can't determine the CVE, we did managed to exploit it ;) ... credit: @b1thvn_
https://t.co/OBDKYVKfe6