🚨 NEW PAPER on the 0day Supply Chain 🚨:
I gathered open source data & interviewed Gov employees, VR and China researchers to figure out what the zero day marketplace looks like in the U.S. and how it compares to China.
Key findings below ⬇️ 0/🧵
atlanticcouncil.org/in-depth-resea…
It’s interesting to see how quickly my Black Hat 2023 keynote predictions about AI started to become a reality.
The security impacts of these AI agents (e.g. taking non-deterministic actions) are going to dramatically change our threat models. Interesting times ahead.
It’s interesting to see how quickly my Black Hat 2023 keynote predictions about AI started to become a reality.
The security impacts of these AI agents (e.g. taking non-deterministic actions) are going to dramatically change our threat models. Interesting times ahead.
Join @vector35’s Kyle Martin and @Margin_Research’s Ian Palleiko in Orlando Feb 24-27, 2025 to learn how to apply advanced program analysis techniques to the problem of vulnerability research. re-verse.io/pavr-24
🚨The Junkyard Call For Bugs is Open! 🚨We want you to bring your most impactful, creative, or most meme-y bugs in end-of-life (EOL) products, and demonstrate them live on stage! Winners get 💰prize money 💰
districtcon.org/junkyard
In Part 3 of our blog series _You Can't Spell WebRTC without RCE_, we conclude our Signal-iOS research with commentary by @__comedian and @m40282845 on exploit limitations and IOCs! margin.re/2024/08/you-ca…
HackingForSoju's captain, @Calaquendi44 , just got a Pwnie Award, accepted on her behalf by her sister (and also HFS member), @secretgardenctf
We are proud of both of you.
HackingForSoju's captain, @Calaquendi44 , just got a Pwnie Award, accepted on her behalf by her sister (and also HFS member), @secretgardenctf
We are proud of both of you.
An honor to accept the Pwnie Lifetime Achievement award on behalf of Margin Research’s founder and my sister Sophia @Calaquendi44 this morning @defcon@PwnieAwards.
"In 28 minutes, XBOW matched 40 hours of work by the most experienced pentester, who has 20 years of experience, with both solving 85%."
Very cool results from the @Xbow team—and another great example of using generative models to accelerate work. How many automated pentesters…
"In 28 minutes, XBOW matched 40 hours of work by the most experienced pentester, who has 20 years of experience, with both solving 85%."
Very cool results from the @Xbow team—and another great example of using generative models to accelerate work. How many automated pentesters…
You Can't Spell WebRTC without RCE - Part 2 blog post, which turns the vulnerabilities we injected in Part 1 into remote code execution on iOS 16.4! Follow along with @__comedian to learn more about the iOS shared cache, Corellium, and ROP in ARM64! margin.re/2024/07/you-ca…
🚨We are very pleased to announce the nominees for the 2024 Pwnie Awards! Be sure to tag your friends and catch us at Def Con! 🚨
🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇
docs.google.com/document/d/13J…
Interested in messaging app research on iOS? Follow along with @__comedian in our blog series "You Can't Spell WebRTC without RCE!" Part 1 dives into Signal’s WebRTC calling library and injects bugs to facilitate deeper research: margin.re/2024/07/you-ca…
The award-winning Qualys Threat Research Unit (TRU) has discovered a critical vulnerability in OpenSSH, designated CVE-2024-6387 and aptly named "regreSSHion." This Remote Code Execution bug grants full root access, posing a significant exploitation risk. blog.qualys.com/vulnerabilitie…
This bug is not really a regression because @mdowd, who we all know is from the future, clearly knew about it before traveling back in time to 2006 to exploit it the first time (in our timeline). It's only a regression in this timeline.
qualys.com/2024/07/01/cve…
138 Followers 7K FollowingBorn: May 15, 1961 (age 63 years), Honolulu, Hawaii, United States
Education: United States Military Academy (1983)
Awards: Defense Distinguished Service Medal
420 Followers 287 FollowingLife has taught us that love does not consist in gazing at each other but in looking outward together in the same direction.
Interests: diving.and traveling.
1.2M Followers 508 Followingim greg I like football and stocks and my birthday im from kentuckey. I'm a investor. I like to golf at the golf course. subscribe for just 10¢ a day ⤴️
1.9M Followers 27K FollowingYes, I can see some risk that your threat to jail Internet company executives for not censorsing aggressively enough could backfire.
2.9M Followers 76 FollowingThe official positive side of 𝕏. I’m Sander from the Netherlands. All copyrights belong to their respective owners! DM for credits/removal/submission!
144K Followers 456 FollowingWe are the National Cyber Security Centre – part of the UK’s intelligence & cyber agency @GCHQ. We help to make the UK the safest place to live and work online.
70K Followers 80 FollowingThis is Cyber National Mission Force’s alert mechanism to contribute to our shared global cybersecurity (Following, retweets and links do not equal endorsement)
52K Followers 634 FollowingThe Australian Signals Directorate provides intelligence, cyber security and offensive operations in support of the Australian Government and the ADF.
3.9M Followers 2K FollowingOfficial FBI X account. Submit tips at https://t.co/tGqFRcJykB. Public info may be used for authorized purposes: https://t.co/x6bfDUEYeJ.
308K Followers 99 FollowingOfficial communications from CISA on X will always originate from this account. No other accounts are authorized to convey info from CISA or senior CISA staff.