🚨 New Open Source Audit Alert! 🚨
Shielder, with @OSTIFofficial & @CloudNativeFdn, audited @karmada_io:
🔍 6 issues found (1 high, 1 medium, 2 low, 2 info)
✔️ Most fixed, others planned.
🗣️ to @suidpit and @Th3Zer0
Full details in the blog post!
https://t.co/mkRiqw7joX
For the weekend, we gift you with not one, but TWO ways to escalate `sudo iptables` (+ a couple other boring preconditions) into a r00t shell - read how @smaury92 and @suidpit managed to climb your friendly neighborhood 🔥wall!
https://t.co/n5xGrQK9IQ
🍎 With many #macOS security mechanisms at work, one might wonder how malware manages to bypass them. Get ready for a deep dive into macOS security architecture and novel evasion techniques during Pietro Tirenna's (@suidpit) talk at #TheSAS2024.
🚀 Secure your seat: https://t.co/FNtauvMADV
During a recent engagement @Mindlaess_ hacked his way through @vtigercrm which led to discover a privilege escalation and a SQL injection.
Learn more in the dedicated advisories:
- CVE-2024-42994 #sqli https://t.co/dRCKRNwFS0
- CVE-2024-42995 #privesc https://t.co/FyzBVR04xx
Back in December 2023 our researchers @Th3Zer0 @suidpit and @Mindlaess_ performed an audit sponsored by @awscloud and facilitated by @OSTIFofficial on boost.
It resulted in 7 findings and 15 new fuzzers.
The report is now public, check the details here: https://t.co/NK5Pzn6mIu
Exciting news! We've just released a new blog post on mobile app security, where @suidpit and @Th3Zer0 used their intent-fu to discover vulnerabilities (CVE-2024-26131, CVE-2024-26132) in @element_hq, a @matrixdotorg client for Android. #writeup#CVE
https://t.co/TU2Gst1npZ
We recently partnered with @OSTIFofficial to perform a security audit sponsored by @awscloud on @brefphp. The audit resulted in 5 findings promptly addresses by @matthieunapoli.
The report is now public, check the details here: https://t.co/cduPMvQSbb
Excellent writeup showing how to track down vulnerabilities in firmwares starting from CVEs through patch diffing
Credits @suidpit and @Th3Zer0
https://t.co/jj3O4v1PNo
#embedded#infosec#asus
And that's a wrap! Exceptional reports from exceptional #hackers 🥳
More content from @nullcon and #bugbountytips coming up ⏭️.
Cheers to the amazing exploits 🎉 and to many more like these events to come.
#HackWithIntigriti@Nestle
We're announcing our second flagship "Hunting Zero-Days in Embedded Devices" training this year at @cybersaiyanIT, in Rome, 24-27th September!!
4 days of PWNING 💻
https://t.co/PrUEPGcs33
Contact us for limited offer discount codes, only 4 u, as our Valentine's gift ❤️❤️❤️
OMG, our "Cookie Crumbles" paper got into the Top-10 Web Hacking Techniques of 2023 by @PortSwiggerRes! Have a look at the paper if you haven't yet https://t.co/eIJpUBKUy9 and check the other outstanding finalists!
Thank you ❤️
Hip, hip, hooray! It's been 10 years of AppSec Ezine! Big shoutout to all who have been supportive along the journey and to the security community that made this project possible. Cheers 🥂
520th Edition: https://t.co/O9BMJrPCB0
Repo: https://t.co/bmRVaetx0v
#AppSec#Security
Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @Th3Zer0 and @suidpit combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 https://t.co/vURraPb7in