Thank you #DEFCONSafeMode for the opportunity to present my talk "Bypassing Biometric Systems with 3D Printing", the live Q&A that was really fun and included the "shoot the noob" ceremony and your awesome staff that made me feel really comfortable. #Defcon#defcon28
For the past 48hrs I've been unwinding a massive wallet draining operation 😳😭
I don't know how big it is but since Dec 2022 it's drained 5000+ ETH and ??? in tokens / NFTs / coins across 11+ chains.
Its rekt my friends & OGs who are reasonably secure.
No one knows how.
#Safemoon was just hacked for $8.9M.
After two minutes looking at the newest Safemoon contract, I was able to identify the extremely obvious exploit.
The attacker took advantage of the public burn() function, this function let any user burn tokens from ANY other address (code attached).
The attacker used this function to remove SFM tokens from the Safemoon-WBNB Liquidity Pool, artificially raising the price of SFM.
The attacker was then able to sell SFM into this LP at a grossly overpriced rate within the same transaction, wiping out the remaining WBNB in the liquidity pool.
This is an extremely elementary exploit that many contracts in the space have been falling victim to.
Please do not let any user burn tokens from any address, it is a bad idea.
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
We've just published a quick write up on CVE-2023-23397, which allows a remote adversary to leak NetNTLMv2 hashes: https://t.co/xDxGwJfY2e by @domchell
This is the MOST ALPHA research paper about smart contract security EVER. 🧵
THEORY: They examined 516 smart contract security bugs & exploits.
FACTS: They applied the THEORY in @code4rena contests & bug bounties and received a total prize of $102k 🤯
https://t.co/5cz4tIOegO
506 days since Taliban BANNED girls from going to school.
There is no other country in the world that bans female education. These brave girls in Afghanistan are chanting —
“We want education. We want education for girls. We want an educated Afghanistan
This market cycle was absolutely unforgettable.
From hilarious bloopers, to enraged influencers, to unbelievable memes, 2022 had it all.
Come with us as we take a trip down memory lane…
El régimen iraní acaba de condenar a muerte a Amir Nasr-Azadani, futbolista de la selección de Irán, por pronunciarse a favor de las protestas por los derechos de las mujeres. Será ejecutado en la horca. El mundo del deporte debe levantar la voz y evitarlo. Sin palabras.
Demonstrating CVE-2022-37958 RCE Vuln. Reachable via any Windows application protocol that authenticates. Yes, that means RDP, SMB and many more. Please patch this one, it's serious!
https://t.co/ikOrTvQIJs
ChatGPT has crossed 1M+ users in just 5 days.
To compare, it took Netflix 41 months, FB - 10 months, and Instagram - 2.5 months.
But many haven’t yet realized its full potential.
Here are the 10 mindblowing things you can do using it right now:
This is MASSIVE. The Windows Subsystem for Linux in the Microsoft Store is now generally available on Windows 10 and 11! Windows 10 users can now run Linux GUI apps natively! https://t.co/U1uZBPl4mj