I've been seeing posts all over about the state of CTFs post-LLM. I've seen many attempts to explain why this is just a new evolution of CTFs, but I fundamentally disagree. I believe the original spirit is gone and I've written why in my blog.
https://t.co/tgUZOGkhGV
Fun facts about this Firefox bug: (1) According to Mozilla, it got introduced in 2003, it predates Firefox 1.0! (2) Although it's a UaF, it doesn't rely on any JS callback, the entire PoC is a single function. (3) It was a purely manual find and just a fun bug to PoC.
If you see hypervisors as magic black boxes that are hard to break, join us to this training and learn to apply your reverse, bug hunting and exploit knowledge to build VM escapes !
[Pwn2Own 2024](CVE-2024-2886)[330563095, 330575496] PinArrayBufferContent is insufficient to keep the backing store itself pinned and WebCodecs VideoFrame Race Condition UAF W -> RCE is now public with PoC, exploit and wp.
https://t.co/QWpJITeful
https://t.co/OV9TcH9yIh
@0x10n
We're naming names 🔥 because the harm is not hypothetical.
Today we share "Buying Spying", our new report diving into the commercial surveillance/spyware industry. We dive into the players, the campaigns, the spyware, & the harm it perpetuates.
https://t.co/D8Lx4wRrw6
In this post I'll use CVE-2023-4069, a type confusion bug in the Maglev JIT compiler of Chrome that I reported in July, to gain RCE in the Chrome renderer sandbox: https://t.co/Mas6ALpKiO
En raison de la situation actuelle en Israël, on a quelques tickets pour @hexacon_fr en rab et @Cellebrite serait heureux de vous les offrir. Pour participer, il suffit de répondre à ce message et on sélectionnera des gagnants demain (12 octobre) dans l'après midi.
Last sponsor we want to introduce is a special one: it's @Synacktiv, the company organizing #HEXACON2023.
Leader in offensive security, Synacktiv helps companies assess their networks's security.
There will be a lot of ninjas in the conference, feel free to talk to them! 🤗
Don't miss @codeblue_jp! @_p0ly_ and @vdehors will present how they managed to compromise the Tesla during the latest #Pwn2Own event
https://t.co/r87Zx9UjoV
The program for @GrehackConf is out with 3 Synacktiv talks!
🖥️ Virtualization from an attacker Point-Of-View: @OnlyTheDuck & @MajorTomSec
🚘 Unlocking the Drive: Exploiting Tesla Model 3: @_p0ly_ & @vdehors
🐧 Ubuntu Shiftfs: Unbalanced Unlock Exploitation Attempt: @jbcayrou
After a bit of delay, we're finally releasing advisories for 139 vulnerabilities we found in 23 trustlets used on Huawei mobile devices. Some of them can be exploited to access the Secure World and retrieve sensitive data.
🧵 A thread of our most interesting findings
This year, #HEXACON2023 will introduce the social event with a lightning talks session! 💡
⏳ 5 minutes long
⛔️ No bullshit/commercials
🎠 Fun topics appreciated
🍻 Beers allowed
🫵Open to everyone
Short talks submission will take place during the event