Posts
3124
Following
708
Followers
1551
"I'm interested in all kinds of astronomy."
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality SAMPLE out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-1955

CVE-2024-0121
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality LD instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2012

CVE-2024-0117
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality out-of-bounds read vulnerability due to excessive loop iteration

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2013

CVE-2024-0118
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality STORE_STRUCTURED instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2014

CVE-2024-0120
0
1
0
repeated

Talos Vulnerability Reports

New vulnerability report from Talos:

NVIDIA D3D10 Driver Shader Functionality MOV instruction out-of-bounds read vulnerability

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2015

CVE-2024-0119
0
1
0
repeated

Trend Zero Day Initiative

Unfortunately, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) could not get his exploit of the TrueNAS Mini X working within the time allotted.

0
1
0
repeated

Trend Zero Day Initiative

Sadly, the Neodyme (@neodyme) team could not get their exploit of the Lexmark CX331adwe printer working within the time allotted.

0
1
0
repeated

Trend Zero Day Initiative

We have another collision. The DEVCORE Research Team (@d3vc0r3) successfully exploited the Lorex 2K camera, but they used a bug previously seen in the contest. They still earn $3,750 and 1.5 Master of Pwn points.

0
1
0
repeated

I thought I understood the extent to which the broad availability of mobile location data has exacerbated countless privacy and security challenges. That is, until I was invited along with four other publications to be a virtual observer in a 2-weeek test run of Babel Street, a service that lets users draw a digital polygon around nearly any location on a map of the world, and view a time-lapse history of the mobile devices seen coming in and out of the area.

The issue isn't that there's some dodgy company offering this as a poorly-vetted service: It's that *anyone* willing to spend a little money can now build this capability themselves.

I'll be updating this story with links to reporting from other publications also invited, including 404 Media, Haaretz, NOTUS, and The New York Times. All of these stories will make clear that mobile location data is set to massively complicate several hot-button issues, from the tracking of suspected illegal immigrants or women seeking abortions, to harassing public servants who are already in the crosshairs over baseless conspiracy theories and increasingly hostile political rhetoric against government employees.

https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/

16
23
1
repeated

Yes- I’m looking at you!

0
1
0
repeated
@lukito My dentist uses a patient mgmt software with a very similar UI (probably .NET by the looks of it)
0
0
1
I think to be true to myself next time I should only boost failing entries (that had the same work and thought put into them as winning ones) from #Pwn2Own.

#failnight
0
0
1
repeated

Trend Zero Day Initiative

As a reminder - you can find all of the results from Day Two of Ireland at https://www.zerodayinitiative.com/blog/2024/10/23/pwn2own-ireland-2024-day-two-results

0
1
0
repeated
repeated

Trend Zero Day Initiative

Confirmed! PHP Hooligans / Midnight Blue (@midnightbluelab) used a command injection bug to get code execution on the Synology BeeStation BST150-4T. They earn $40,000 and 4 Master of Pwn points.

0
1
0
repeated
re: #music #grindcore
Show content
@swapgs I saw them first touring with Napalm Death, mind blowing performance too! https://www.youtube.com/watch?v=jXaUUvOEQ7E
0
0
1
#music #grindcore
Show content
2
1
2
@thezdi Napalm Death is prime xdev music \m/
1
0
2
Show older