May 10-11-12, 2024
May 10-11-12, 2024
I was having too much fun at offensive con to read anything. I wholeheartedly endorse Offensive Con. Had a great time, even if some ppl I met were only born 6 years after I started doing security. Grumble. Kids these days.
Holy shit, CVE-2024-4367
β H4x0r.DZπ©πΏ (@h4x0r_dz) May 9, 2024
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF https://t.co/8iGYjkcE3Z#infosec
Man who kept his boat besides his house was ordered from the city to put up a fence to hide the boat from view. So he built the fence and hired someone to paint it. pic.twitter.com/wrkQh6RjXn
β Doug Aoki (@Nantanreikan) May 9, 2024
Possibly a first: Prosecutors have IDed the latest Jan. 6 suspect by looking at images on his wife's Poshmark account: https://t.co/Un8Pk8COHE pic.twitter.com/XbOBfsIFOH
β Kyle Cheney (@kyledcheney) May 10, 2024
I'm preparing a long blog post atm. This will take some time to be written and also depends on Microsoft providing a patch. It'll follow the same style as https://t.co/WCRYaKo56R so hopefully a good candidate for .NET code audits for beginners. Fingers crossed.
β frycos (@frycos) May 11, 2024
(Gaslighting my reader) as I have argued consistently throughout this essay,
β John Attridge (@John_Attridge) May 12, 2024
Player 2 has entered the ring.
β thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) May 12, 2024
A new Chinese pwn2own style competition is now public. The list of targets is interesting, lots of edge devices and even Kaspersky. https://t.co/FQJU1dZo9R
So hereβs me giving my book Philosophy of Cybersecurity to the renowned cybersecurity thought leader (and haxor) @thegrugq. Thank you for a professional exchange of views! pic.twitter.com/OxKg6x3AhZ
β Lukasz Olejnik (@lukOlejnik) May 12, 2024
Recently modified code and sanitizer instrumentation seem to be among the most effective heuristics for target selection in directed #fuzzing according to this recent SoK by Weissberg et al. LLMs show much promise for target selection, too.
β Marcel BΓΆhmeπ¨βπ¬ (@mboehme_) May 12, 2024
π https://t.co/Lr7jjNDXKj pic.twitter.com/yw1T3jJIkq