-

Twitter avatar for @Paul_Reviews
Paul Moore @Paul_Reviews
.@EufyOfficial - Couple of Q's

Why is my "local storage" #doorbellDual storing every face, without encryption, to your servers?

Why can I stream my camera without #authentication?!

But crucially, is this really the AES key for my video footage? Please tell me it's not.

Image

-

-

So a new thing happened. A paper we submitted got rejected by a journal after automated plagiarism detection. It turned out two students in India had plagiarised our preprint and then published online reports. So we've been accused of copying them. Fun.

-

-

-

-

The "#Vulnerabilities 1001: C-Family Software Implementation Vulnerabilities" free course by #OpenSecurityTraining2 is awesome and very recommended to all developers and beginner code auditors.

https://ost2.fyi/Vulns1001

Also, make sure to check out all the other high-quality, free #OST2 training courses.


-

-

-

Twitter avatar for @borrello_pietro
Pietro Borrello @borrello_pietro
@jevinskie Thank you! 🙂 Still wip but I'm exploring different routes for benefits of microcode control Up to now I implemented: - fast software breakpoints for fuzzing - conditional hw breakpoints for perf profiling - constant time hw division - and yes x86 PAC 😁

Suggestions are welcome!

-

Twitter avatar for @b_nishanov
Bakhti Nishanov @b_nishanov
A confectionery producer in Kazakhstan dropped a new ad for their chocolate bar called “Kazakhstan”. In it, what looks like a Russian draft dodger walks over to Kazakhstan and is handed a chocolate bar. He asks what it is and is told, “It’s the taste of freedom.” Absolute fire.
Twitter avatar for @vvabramov
Vyacheslav Abramov @vvabramov
@b_nishanov Russian advertising agency made this ad without any requests from the client.

-

Twitter avatar for @rthhh17
rthhh @rthhh17
The video record of my Black Hat USA 2022 talk is up! @BlackHatEvents "DirectX: The New Hyper-V Attack Surface"

-

Twitter avatar for @payloadartist
payloadartist @payloadartist

-

Twitter avatar for @NCCGroupInfosec
NCC Group Research & Technology @NCCGroupInfosec
Video from our @BlackHatEvents talk by Iain Smart ( @smarticu5 ) & Viktor Gazdag ( @wucpi ) on "RCE-as-a-Service: Lessons Learned from 5 Years of Real-World CI/CD Pipeline Compromise" is available now

-

Don't miss what's next. Subscribe to the grugq's newsletter: