PSA: Y'all are gonna see less tech content from me here going forwards but I'm not leaving either (you'll be able to find me at https://t.co/sV9bHQwhmw if you're so inclined). Till it burns down entirely at least, to borrow from Wikipedia: https://t.co/VmSzN608Pk
(fixed typo :))
I'm not sure I have a bad MSRC story to tell. There were a couple of times they disagreed with me about exploitability/impact, but it seems like I've had a lucky escape. Be sad if the wind has truly turned.
@0xN1NJ10 Your post with reference to keyctl gave me some inspiration to update it. Adding in keyctl based functionality and merging in the useful bits from the @orangecyberdef fork.
Dropping 0day isn’t the worst thing a researcher can do. It’s not ideal, but at least orgs can take steps to mitigate.
Non disclosure is far worse.
What drives researchers toward non disclosure?
Threats from vendors.
Researchers aren’t criminals unless their crime is curiosity.
Whatever will 🐝 will 🐝. Nice close out the season with another decent result. Frustrating that it was another drawer but most wouldn't have expected us to stay up...
My Project
Objective: To equip Security Operations Center (SOC) analysts with practical Linux command-line skills for log analysis, threat hunting, and incident response automation using production-scale log files.
@ireteeh
A Thread👇👇👇