Success! The @mwrlabs wrapped up the #Pwn2Own Tokyo contest with a successful demonstration of a browser exploit on the #Xiaomi Mi6. Now off to the disclosure room for details and verification.
What an event. Massive thanks to the @zdi team for running this year's #P2Otokyo . And big shout out to @fluoroacetate for a seriously impressive set of submissions!
Confirmed! @mwrlabs popped a captive portal with no user interaction, followed by an unsafe redirect and an unsafe application load to get code execution on the #Samsung#Galaxy S9. The exploit chain earns them another $30K and 6 more Master of Pwn points.
Confirmed! The folks from @mwrlabs chained together 5 different logic bugs - including the silent installation of an app via JavaScript - to get code execution over Wi-Fi on the #Xiaomi Mi6. They earned themselves $30K USD and 6 Master of Pwn points.
#Pwn2Own Tokyo is underway! The contest order has been decided via random drawing. Our program starts with @fluoroacetate targeting the #Xiaomi Mi6 with an NFC exploit. See the full schedule and updated results at https://t.co/KOA4HJYUvy. #P2OTokyo
The drawing to determine the order of attempts will be at 9am tomorrow with the first attempt coming at 9:30. Until then, enjoy this preview of the Master of Pwn jackets.
Announcing #Pwn2Own Tokyo 2018. This year, we bring #IoT devices along with phones as targets. Over $500,000 USD available in cash and prizes. Get all the details here: https://t.co/BQOe6uFg1v. See you in Tokyo! #P2OTokyo
#DNSRebinding isn't just for owning your router, it's also for owning your #AWS#cloud deployments, @alxk_mwr pops headless analytics services https://t.co/n25SE8BomZ
📝 New post! I stumbled across a serious browser security bug & I can finally talk about it. The post covers:
➡️ An exciting new logo.
➡️ Range requests.
➡️ "No-cors" requests.
➡️ Sneaking past origin security.
➡️ The importance of standards.
https://t.co/0hyb1dKBB0
A very warm welcome to F-Secure @mwrinfosecurity! F-Secure takes a big step towards cyber security leadership by acquiring MWR InfoSecurity https://t.co/3b4sxzd2gS
Last batch of bugs now patched from Mobile Pwn2own 2017 for the Huawei Mate 9 Pro: https://t.co/0HlNDU7JOR. Tech whitepaper to follow later in the week #pwn2own
At #CYBERUK18 next Tuesday? Our very own Robert Miller and Georgi Geshev talk vulnerabilities and automating the research process to make efficiency savings [14:50 - Exchange Auditorium] | #infosec#vuln https://t.co/sIePDknFBt