The biggest security gap in your environment might not be some zero-day, it's DNS.
Matt Scheurer is bringing live demos and a wake-up call to BSides312.
May 16th. Chicago. → https://t.co/FicK8iLstz
#BSides312#BSides#Chicago#InfoSec#DNS#THOTCON
If you launch FreeBSD from the @awsmarketplace please be advised that I can now see your "Company name". I never used to be able to see this information, and have no intention of (ab)using it, but this is new.
(And, of course, applies similarly with other Marketplace products.)
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".
Want to guess what those tools were? See image two!
Info via @jsrailton
0day time: Here's a user to root LPE on macOS. I found it accidentally during our research with @theevilbit. This is not the bug that scares me btw, this one makes me laugh