Security but not as in "national security". Playing CTFs with @redrocket_ctf (and @Sauercl0ud). Pwn2Own Vancouver 2020..=2024\{2023}. @[email protected] Outside of computed boundsJoined January 2020
If you're a security researcher and in Germany, consider signing cysec-reform.jetzt . Decriminalizing research might not be the top political priority right now, but it's still important!
@ecsc2024@MITAmalta@MITAmalta, this is not how you build up a cybersecurity community in your country. It was great to see a lot of ECSC players show their support people like @_mixy1 who faced both disqualification and legal action. As the vulnerability research community, we should do the same.
This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n
Exploit for Pwn2Own CVE-2024-29943, an Integer Range Inconsistency caused OOB access! Analysis will be updated later. Shoutout to
@_manfp for finding this bug. And shoutout to @maxpl0it for his integer range inconsistent PoC.
github.com/bjrjk/CVE-2024…
think i found a bug. which means it’s time to take a break and enjoy the possibility before looking more closely and finding out there’s a check in an upstream code path I missed
@chrisrohlf@mncoppola Keeping open a bug to support a government operation is isomorphic to opening a backdoor to support a government.
I'm pretty sure you wouldn't want Google to keep a bug open for the benefit of China, Chris.
alecmuffett.com/article/109963
theguardian.com/world/2022/feb…
Is this the "counterterrorism operation" by a U.S.-allied Western government that's being referenced? If saying the country and "terrorist" group involved paints a flattering picture of these exploit tools, why aren't they saying which ones are involved?
This years Google CTF Qualification is over. Congratulations to @kalmarunionenDM, kijitora and Zer0RocketWrecks! The top 8 teams qualified for Hackceler8 2024 in Málaga. More details at goo.gle/ctf.
¡Vamos!
Happy to have my write-up on @thezdi's blog again - after so many fights with some kind of range analysis, a bug that just directly gives every type confusion you want felt quite fun
Happy to have my write-up on @thezdi's blog again - after so many fights with some kind of range analysis, a bug that just directly gives every type confusion you want felt quite fun
44K Followers 3K FollowingChoose disfavour where obedience does not bring honour.
I do math. And was once asked by R. Morris Sr. : "For whom?"
@[email protected]
0 Followers 61 FollowingDudley Daniel Raj alias as dannyDUD, Red Teamer, Bug hunter, obsessed with breaking things in as a hardware as well as software
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
26K Followers 2 FollowingOffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.
44K Followers 3K FollowingChoose disfavour where obedience does not bring honour.
I do math. And was once asked by R. Morris Sr. : "For whom?"
@[email protected]
7K Followers 783 FollowingSecurity engineer at https://t.co/027VXUlgOx. Focusing on the Linux kernel. Maintaining @linkersec. Trainings at https://t.co/D5MrxmYimS.
5K Followers 47 FollowingWe secure software with deep-dive audits, cutting-edge research, and in-depth trainings.
Secure your solana program with Riverguard @ https://t.co/VmxVHzx2U2 🏞️💂
38K Followers 1 Following‼️‼️NOT THE CALIFORNIA DMV‼️‼️ Real personalized license plate applications that the California DMV received from 2015-2017. Posts hourly.
12K Followers 3 FollowingRandom stuff from the big yellow book. By @mammoth
DM for submissions - include a little story if you want.
No affiliation with McMaster-Carr Supply Company
12K Followers 24 FollowingAn annual awards ceremony celebrating and making fun of the achievements and failures of security researchers and the wider security community.
336K Followers 189 FollowingSharing our neurodivergent experiences helps us realize that we are not alone. Most memes are on ADHD, some are on Autism and others are just me being silly.
2K Followers 326 Followingjournalist for surveillance, data protection, internet regulation I trainer for digital security I PhD candidate @unihh I pgp: 9C4ED204