⚠️ A few hours ago, a malicious crate was discovered on crates.io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted.
For details and how to see if you are impacted, see: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Microsoft killed my exploit 😢
This Friday on @offby1security I'll talk to @steph3nsims about what why, how and if this is the end for this class of exploit techniques
One day I'll sit around the camp fire and be like "You know grandpa Bas used to this stuff by hand before the em-dashes took over" ... Things like https://github.blog/security/vulnerability-research/now-you-c-me-now-you-dont-part-two-exploiting-the-in-between/ were always less about the bugs themselves and more about how to approach attack surfaces and exploit development as an adventure in creative debugging and ultimately just fun puzzling. Of course, that very same kind of iterative text based feedback loop is perfect for the current fancy text completion revolution. It's just a bit of a shame that the landscape seems to be shifting from "that was so much fun to figure out!" towards "oh wow it was able to figure it out".
I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host. https://trustsig.eu/blog/wasm2c-tableflip-unchecked-calloc/
No perfect 10s this time, but that's a lot of AIX vulns from the other day:
Just published “Vulnerability Analysis of CVE 2025 22226 Information Disclosure Due to OOB Read in VMwares HGFS” by Alex Zaviyalov the first vulnerability in an ITW VMWare guest to host escape chain 👇
https://www.nccgroup.com/media/1mzfvyzl/nccgroup_cve-2025-22226.pdf
We have achieved kernel code execution via the IDT under Windows 11 with VBS/HVCI/kCET enabled.
Read the technical write-up here: https://exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11
#Windows11 #KernelExploit #IDT #VBS #HVCI #kCET #DataOnly #RedTeam #ExploitResearch #WindowsSecurity #infosec #pentest
If I gambled on both NFTs and the metaverse to the tune of millions and millions of dollars and even renamed my company accordingly I would be so canceled I’d be farming potatoes, but people are still quoting Zuck AI predictions on my daily news feed.
Doing a presentation tomorrow on our utter dependence on US technology and specifically how we 100% picked US tools/support for cybersecurity as well. We are SO fucking fucked. #sentinel