Boom! Thomas Bouzerar (@MajorTomSec) and Etienne Helluy-Lafont from Synacktiv (@Synacktiv) close out #Pwn2Own in style with a guest-to-host escape in VMware Workstation. If confirmed, it will put the total contest payout at over $1,000,000! #Pwn2Own
I have recently developed a tool to identify domains and subdomains sharing identical DMARC records, potentially expanding the scope of attack surfaces.
https://t.co/soK4D702xz
🎉 Team SAFE COTTAGE, 1st Runner Up at #DigitalPakistan#CybersecurityHackathon2023! 🥈💰They secure 1 Million Rupees, Intl. Training Coupons, and Sponsorships. Thanks to all contributors and the Chief Guest Dr. Umar Saif, Federal Minister IT & Telecom. 🏆🌍 #Hackathon2023
Check out the new Updated and Improved "Bug Bounty Blueprint: A Beginner's Guide." 🎯 Let me know your thoughts! 🙌 #BugBounty#bugbountytips
https://t.co/noESxloseR
Stealth trick for Red Teaming - why worry about being caught by an MDR (i.e., Artic Wolf, FireEye, etc.) when you can kill their visibility? 🧐
ipconfig /displaydns - Find API Endpoint
echo 127.0.0.1 https://t.co/g9gwpLI2WI >> c:\windows\system32\drivers\etc\hosts
I was able to access thousands of companies’ passwords on #Azure and run code on their VMs.
This includes access to Microsoft’s own credentials… 💣
Here’s HOW I did it.
This is the story of #SynLapse. (1/11)
The most valuable skill in a remote world:
Writing effectively.
But colleges do a terrible job of teaching us how to write for the internet.
My writing has reached over 5 million people online.
Here are 6 quick tips to upgrade your writing skills in the next 5 minutes:
This is probably the most complex exploit I've done so far. A UAF in Android kernel freed by kfree_rcu (introduces a delay) in a tight race + kCFI + Samsung RKP. Yet its still possible to gain arbitrary kernel RW, disable SE and root from untrusted app. https://t.co/u8iD42ZC7B