🎮 Xbox 360 security in details: the long way to RGH3. Read the exclusive story about the chipless and reliable Xbox 360 modding method by @15432h
https://t.co/QNjNDp3PWX
#Xbox360#Modding#RGH3
🤖 New article by our researcher Nikita Petrov: "From opcode to code: how AI chatbots can help with decompilation".
Read the blog post: https://t.co/vuoZzos3UH
💥 New attack! Our researcher Arseniy Sharoglazov discovered a PHP's Arbitrary Object Instantiation with no user-defined classes. It was turned to RCE!
Read the research: https://t.co/PJZHLRM8xq
💣 If you have access to a Windows machine, try to get NAA credentials via Impacket:
1. https://t.co/HfDmnqOOl7 -rpc-auth-level privacy -namespace '//./root/ccm/policy/Machine/ActualConfig' CONTOSO/user:pass@host
2. SELECT * FROM CCM_NetworkAccessAccount
Credits: @subat0mik
🚒 Invision Community fixed an SSRF vulnerability (CVE-2021-40604) found by Mikhail Klyuchnikov!
Timeline:
✅ 06/23/2021 - The advisory is published
😒 06/24/2021 - Requested CVE via MITRE
😀 06/13/2022 - CVE was assigned
The PoC ⤵️
The "gkey" param is an unfollow token.
📝New research by @a13xp0p0v: "A Kernel Hacker Meets Fuchsia OS"
Fuchsia OS is based on the Zircon microkernel and developed by Google. Alexander assessed it from the attacker's point of view.
Read the article: https://t.co/meuKtNLChu
We recently analysed a number of code execution vulnerabilities in Veeam, @SinSinology outlines our approach to VR and exploit these issues... https://t.co/3NEiteXxaw
Down to 190 characters! #つぶやきGLSL
vec3 p=vec3(t/.1,cos(t+r)),d=r.x/(r.xxy-round(FC.zxy)*2.),a;for(;o.w++<9e2&&snoise3D(a=ceil(p)/28.)+1.>length(a.yz);p+=min(a=fract(-p*sign(d))*abs(d)+1e-4,min(a.y,a.z)).x/d);o.rgb=fwidth(p);
🔥 Veeam fixed an Unauth RCE (CVE-2022-26500, CVE-2022-26501) in Veeam Backup & Replication and a Local Privilege Escalation (CVE-2022-26503) in Veeam Agent for Microsoft Windows found by our researcher @ultrayoba.
Advisory: https://t.co/tRYsKBn3HD
Second article by our researcher @elk0kc about unauth vulnerabilities in VMware products: "Catching bugs in VMware: Carbon Black Cloud Workload and vRealize Operations Manager".
Read the article: https://t.co/srVfc1Q3Vi
🚨 New article by our researchers @__mn1__ and @elk0kc about unauth RCEs in VMware products: "Hunting for bugs in VMware: View Planner and vRealize Business for Cloud".
Read the article: https://t.co/P3639HkAiC
This is the first article about our VMware research. More to come!