@jopraveen18 "silently"
stop blaming without researching first. the guys are just not on this platform anymore.
also:
> no one will have been affected by the bug as only a very small number of projects downloaded 3.4.4 overnight
via
https://t.co/gyUFYjvgoH
@SocketSecurity Malware using "go:generate" would also only run if the pipeline executes a project wide generate like "go generate ./..." (3/3)
afaik, Go does not have any form of code execution during a generic "go build" step.
@SocketSecurity Go's init() does not trigger at build. It will only trigger when the module "loads". To trigger malware using init(), the pipeline needs to either execute the binary after building it, or execute "go test" with tests using the module. (2/3)
🛸 👽 We have published this year's agenda with the talks for the AREA41 security conference 2026 🛸 👽
We are excited - hope you too!
➡️ Check them out at: https://t.co/Y2kauRpy7t
📅 June 18-19. 2026, Zürich
🎫 Ticket sale May 5th @ 13:00 https://t.co/SCfqbXd2L5
gopacket is live! Check it out, it is intended to be a full reimplementation of Impacket in Go (it is in beta please send me bug reports) https://t.co/9XjTickbyA
If you ever need to update headers like cookies from within the repeater tab of Burp but do not want to manually copy the newest cookies, I have you covered.
https://t.co/0vQGyog4SC
Lenovo released all patches for the #Lenovo#Vantage#vulnerabilities, which we've reported earlier this year.
Our blog now includes the full write‑ups for CVE-2025-13154, CVE-2026-1715, CVE-2026-1716, and CVE-2026-1717.
🔗 https://t.co/wK5jsHtFEh
First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested.
https://t.co/eNWThyvTPz
Nobody asked for them, but here are my uBlock rules to slim down Twitter/X, Bluesky, and Mastodon. They disable fancy features and make it so that basically there are only the options to post and to view your "following" feed. No more distractions!
https://t.co/kkUQTKjOEn
The #Insomnihack 2026 talks lineup are LIVE! Top-tier speakers. Real-world security research.
Check out the full programme and register now 👇
https://t.co/uKWXSBA1m0
Seats are limited so don’t miss it!
#Cybersecurity#Infosec#INSO2026#CyberConferences
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own#P2OAuto
We have a collision! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) earned $25,000 USD and 4 Master of Pwn points with the Charging Connector Protocol/Signal Manipulation add‑on against the Grizzl‑E Smart 40A, chaining an authentication bypass (CWE‑306) to remote code execution via CWE‑494. #Pwn2Own #P2OAuto
🚨 New blog post!
Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance.
https://t.co/kKq0rEBqTL
#windows#cve#infosec#pentest