I would answer multiple times with random CVE IDs and fake case numbers, ending with the “My apologies if you receive this email in error or more than once” signature.
HW & IoT SESSION
Another day, another discovery🔥
- Firmware Encryption Reversing by @qkaiser 🔬
- Sighthouse for Seamless Function Detection by Sami Babigeon & @Mad5quirrel 💻
- Deep dive and Design Your First PCB with @tcccorp 🛠️
🎟️ Booking: https://t.co/MXseOECfpK
one was reported today and I expect an advisory within 90 days
the other I reported in 2025 is a shit show because they need to rotate their keys
different platforms, different bugs
It’s really funny watching companies learn things like patching at high velocity isn’t a cybersecurity silver bullet
The state of cybersecurity is so bad in tech today, they’re recreating defense in depth from first principles
What if the 100+ bugs being recently fixed in Chrome and Firefox were not sourced from Big Sleep / Mythos but from AI assisted vulnerability researchers that do not know about disabling crash reporting ?
@catc0n@Junior_Baines Advisory: “A vulnerability affecting some component of one of our product may allow a user under certain conditions to trigger a DoS”
Changelog: “26-05-12 - fixed a security issue”
Reality: unauth RCE via stack overflow, no hardening
Upstream's covering up of security information they're aware of at time of commit is directly related to why your distros have no fixes for the https://t.co/OSvuOIxZ0Z vuln. Completely irresponsible.
@moyix it’s a thin line, but usually conditional checks on country are good “code smell”. Netgear had this 3rd party “gaming speed improvement service” only enabled in China. https://t.co/QrscvfjKI5
Back in Sept ’25, I projected format support requests would decrease based on trend. Then automotive showed up and boy was I wrong.
Anyway, we can handle QNX SAFEFS, QNX IFS embedded in ELF, QNX deflate, UCL compression, and some more obscure format with unblob now.
We also have an F2FS extractor that we did not communicate about. Started seeing Android firmware with F2FS around June 2025.
This format is *cursed*, almost lost it working on it.