Boom! Rafal Goryl of PixiePoint Security needed two attempts but was able to get his exploit of the Phillips Hue Bridge working. He heads off to the disclosure room to provide all the details. #Pwn2Own
You can find all of the results from Day Two of #Pwn2Own Ireland at https://www.zerodayinitiative.com/blog/2025/10/22/pwn2own-ireland-2025-day-two-results - We'll be updating this blog throughout the day as results become available. #P2OIreland
The new version of the Sanitizer API is now enabled by default in @firefoxnightly!
https://developer.mozilla.org/en-US/docs/Web/API/Sanitizer
https://wicg.github.io/sanitizer-api/
Please give it a try and provide us with feedback.
Recapping Day One of #Pwn2Own Ireland 2025. Join @dustin_childs (and Maude) as he covers the highlights of the first day of the competition. We awarded $522,500 for 34 unique 0-day bugs, and more is to come. https://youtu.be/tiM_StSFvow
The schedule for r2con2025 is out!
It's online, plenty of awesome talks.
I recently had the opportunity to talk about Evilginx on the Click Here podcast from The Record.
I reflected on the moral considerations surrounding the double-edged nature of developing offensive security tools.
Enjoy the Frankenstein reference 😅
https://therecord.media/evilginx-kuba-gretzky-interview-click-here-podcast
ProTip: A recommendation to enjoy more this year’s #r2con2025 as long as it's 100% online: Gather some friends with drinks and popcorn and watch the stream live together!
All the presentations are recorded, so the speakers will be available in the chat and really appreciate your live feedback in the Telegram/Discord and YouTube channels!
Impressed with the level of compatibility of the new memory-safe C/C++ compiler Fil-C (filcc, fil++; https://fil-c.org/) based on clang. Many libraries and applications that I've tried work under Fil-C without changes, and the exceptions haven't been hard to get working.
Our 2025-2026 internship season has started.
Check out the list of openings and apply for fun and knowledge!
https://blog.quarkslab.com/internship-offers-for-the-2025-2026-season.html
All results from Day One of #Pwn2Own Ireland 2025 can be found at https://www.zerodayinitiative.com/blog/2025/10/21/pwn2own-ireland-2025-day-one-results - This will be updated throughout the day with results. #P2OIreland
While our colleagues hack live at #Pwn2Own in Cork, take a look at our newly published last year's writeup on our blog: We compromised a QNAP router to take over a networked Canon printer.
▶️ Read the findings and how we got there: https://neodyme.io/en/blog/pwn2own-2024_qhora/
Just received an email from YouTube that they'll soon enable autodubbing on the OctoPrint channel for new and soon also old videos. Hell no, every time I run into this AI shit when watching YouTube I just want to scream, it's THAT bad.
Thankfully, there's a way to opt-out, and I just did that. And if you upload stuff to YouTube, for the love of all that is holy, PLEASE disable that too!
Uncheck Channel Settings > Upload defaults > Advanced Settings > Automatic dubbing
It feels like the major tech companies have followed a Journey of discovering The Hardest Way Possible why quality assurance is so important, gradually ramped up quality assurance, dramatically improved the quality of their software, until the senior engineers who pushed for this retire, and then a guy who thinks he knows everything because he's read both "What They Teach You At Harvard Business School" and "What They Don't Teach You At Harvard Business School" says to himself "why are we paying for all this quality assurance? the quality is clearly fine, we don't need it!"
https://www.theregister.com/2025/10/16/windows_11_update_localhost/
CVE-2025-8078: ZYXEL Remote Code Execution via CLI Command Injection https://rainpwn.blog/blog/cve-2025-8078/
@peter
Just a friendly reminder: the fact that the fediverse survived unaffected is _only_ because it's being run by private individuals, _at their own expense_, physically distributed all over the world.
Running, maintaining and moderating a service like this costs time and/or money.
So please donate to your instance if you can. I know I do. It's not much, but I do what I can.
This is a collective effort.