Advertisement · 728 × 90

Posts by

Post image

Binary Ninja 5.3 (Jotunheim) adds new architecture APIs for full function level lifting. We are already using them for upcoming TMS320C6x work, and plugin authors should be able to put them to good use too.

1 day ago 1 1 1 0
Project Zero

The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844

It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!

1 day ago 8 3 0 0

[RSS] Slowburn: Looking through AMD Platform Configuration Blobs infrastructure


swarm.ptsecurity.com ->


Original->

1 day ago 0 1 0 0
Preview
23 Chrome Exploit PoCs on an Open AWS Server: Inside an Active CVE-2026-4440 Exploit Development Toolkit An open directory on an AWS EC2 instance exposes 23 files comprising a complete Chrome/Android exploit development toolkit targeting CVE-2026-4440 and multiple WebGL/ANGLE vulnerabilities — renderer R...

Exploit code for a recently patched Chrome vulnerability has leaked online via a misconfigured server.

Security firm Breakglass believes the code is the work of a "professional exploit developer," and most intended for "sale or government use."

intel.breakglass.tech/post/cve-202...

2 days ago 8 4 0 0
Preview
Protecting Cookies with Device Bound Session Credentials Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April ...

security.googleblog.com/2026/04/prot...

4 days ago 8 2 1 0
Preview
Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP Confidential computing allows cloud tenants to offload sensitive computations and data to remote resources without needing to trust the cloud service provider. Hardware-based trusted execution environ...

"With Fabricked, we present a novel software-based attack that manipulates memory routing to compromise AMD SEV-SNP"

fabricked-attack.github.io

5 days ago 2 2 1 0
Preview
Zero Day Initiative — The April 2026 Security Update Review It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularl...

It's a huge release from #Microsoft and a larger one from #Adobe. @dustinchilds.bsky.social has some new tables to help tell the story and he breaks down a monstrous Patch Tuesday release. www.zerodayinitiative.com/blog/2026/4/...

1 week ago 1 1 1 0
Preview
Bringing Rust to the Pixel Baseband Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...

The Pixel 10 smartphones released last year are the first phones to use Rust for its modem firmware in an attempt to narrow the phone's baseband attack surface

security.googleblog.com/2026/04/brin...

1 week ago 24 7 0 0
From left to right: Executive Director of Finance John Terrill and Executive Director and Chairman Mark Trumpbour onstage at SummerCon

From left to right: Executive Director of Finance John Terrill and Executive Director and Chairman Mark Trumpbour onstage at SummerCon

The Summercon 2026 CFP is open.

We’re looking for original work. Things you’ve actually done. Things that worked, or didn’t.

Don't overthink it, the first step is submitting.

summercon.short.gy/CFP-2026

1 week ago 3 2 0 0

Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS


heyitsas.im ->

More LLM bugs: CVE-2026-34980 and CVE-2026-34990


Original->

1 week ago 0 1 0 0
Advertisement

[RSS] Standardizing Rewards in Google VRP: Introducing Information Tiers and Action Criticality


bughunters.google.com ->


Original->

1 week ago 0 1 0 0
Preview
Anthropic Teams Up With Its Rivals to Keep AI From Hacking Everything The AI lab's Project Glasswing will bring together Apple, Google, and more than 45 other organizations. They'll use the new Claude Mythos Preview model to test advancing AI cybersecurity capabilities.

The AI lab's Project Glasswing will bring together Apple, Google, and more than 45 other organizations. They'll use the new Claude Mythos Preview model to test advancing AI cybersecurity capabilities. www.wired.com/story/anthro...

2 weeks ago 55 9 3 4

I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. github.com/tyranid/info...

2 weeks ago 6 4 0 0

xz security advisory (CVE-2026-34743):


tukaani.org ->

Who has the guts to update? :)


Original->

2 weeks ago 1 2 0 0

New Fortinet zero-day on Easter eve... precious timing

fortiguard.fortinet.com/psirt/FG-IR-...

2 weeks ago 8 4 0 1
Preview
Remote code execution in CentOS Web Panel - CVE-2025-70951

There's a new unauth remote code execution bug in the CentOS Control Web Panel web hosting toolkit, tracked as CVE-2025-70951, that will need patching in the coming days

fenrisk.com/rce-centos-w...

2 weeks ago 6 4 0 0
Post image

AI found critical vulnerabilities in Microsoft software, autonomously.

XBOW identified 3 critical RCEs, including one of the most severe issues in March’s Patch Tuesday and two in Bing with potential SYSTEM-level impact.

No source code. Real environments. Real CVEs.
https://bit.ly/4bNBgWT

2 weeks ago 1 3 0 1
Post image

We have adjusted the scoring on the advisory to reflect server-side mitigations that the vendor described during the disclosure process.

3 weeks ago 3 1 0 0
Post image

Catch Christopher Domas’ keynote from RE//verse 2026! fail: jmp fail (everything I got wrong in RE and security research) gets into the dead ends, bad ideas, and wasted hours behind real progress in RE and security work. Watch now: youtu.be/iOq8O_phwbA?...

1 month ago 1 2 0 0

Ubiquiti patches 10/10 bug: community.ui.com/releases/Sec...

1 month ago 9 5 0 0
Advertisement

RE//verse 2026 videos are online


www.youtube.com ->


Original->

1 month ago 2 3 0 0
Preview
Findings Gadgets Like it’s 2026 — Atredis Partners Java deserialization vulnerabilities have been of interest to me for nearly a decade. In 2016, my team published a blog post titled "What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your…

We decided to revisit an old research problem with some new LLM powered tooling. Check out our latest blog post to see how we approached this research, and the new Java deserialization gadget chains it discovered in just two days! www.atredis.com/blog/2026/3/12/findings-gadgets-like-its-2026

1 month ago 2 5 0 0

Check out the analysis by @cryptocat.me for CVE-2026-20127 in Cisco SD WAN. That other PoC posted last week exploits a totally different bug that doesn't match the reported IOCs (some kind of file upload due to path traversal in vManage maybe). We asses with high confidence this is CVE-2026-20127 🔥

1 month ago 2 1 0 0
Preview
Zero Day Initiative — The March 2026 Security Update Review I am back in the friendly confines of the Mid-South headquarters of TrendAI ZDI (a.k.a. my home office), and am all set for the third patch Tuesday of 2026. Take a break from your regularly scheduled ...

Happy Patch Tuesday! The latest security patches from #Adobe and #Microsoft are here. Thankfully, no bugs are listed as being under attack, but there's still some interesting ones in the mix. Join @dustinchilds.bsky.social as he breaks down the March release www.zerodayinitiative.com/blog/2026/3/...

1 month ago 2 3 0 0
Post image

As per its stated policy, Kaspersky did not attribute Operation Triangulation.

Instead the company winked that it knew who made the tools when it chose the name and logo of the hacking campaign.

techcrunch.com/2026/03/09/a...

1 month ago 25 4 2 0
On the Effectiveness of Mutational Grammar Fuzzing Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar t...

Ivan Fratric shares some tips and tricks for grammar fuzzing

projectzero.google/2026/03/muta...

1 month ago 7 4 0 0
Preview
MuddyWater Exposed: Inside an Iranian APT operation MuddyWater espionage campaign exposed

The Ctrl-Alt-Intel team has dumped the content of misconfigured command and control servers linked to the MuddyWater Iranian APT, aka Static Kitten, Mango Sandstorm, Earth Vetala, Seedworm, and TA450

ctrlaltintel.com/threat%20res...

1 month ago 9 6 0 0
Phrack Prophile on FX Click to read the article on phrack

phrack.org/issues/68/2#...
Another legend has crossed over. Thank you @fxv2.bsky.social for being your kind, brilliant self, whose contributions are too many to name, not just in hacking, but in being a superconnector who I now know is responsible for so many friendships & marriages. You are missed.

1 month ago 35 10 3 1
Preview
proof-of-concept/cve-2025-36632 at main · atredispartners/proof-of-concept Proof of concepts and other snippets. Contribute to atredispartners/proof-of-concept development by creating an account on GitHub.

On a recent engagement, we exploited a previously disclosed privilege escalation bug in Tenable's Nessus Agent. No public PoC was available, so we made one; check it out here github.com/atredispartn...

1 month ago 3 4 0 0
Advertisement
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...

In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API.

Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process.

projectzero.google/2026/02/gphf...

1 month ago 5 4 0 0