"You don't need pentesters anymore." - Every hype cycle, ever.
While the AI debate continues in Vegas, we'll be busy finding the bugs it missed and proving which "findings" were never vulnerabilities in the first place.
Happy Black Hat & DEF CON!
#BlackHat #DEFCON #AppSec #AI #CyberSecurity #HackerSummerCamp #doyensec #security
Another security position at Mozilla. Help manage our (web) bug bounty program on HackerOne as a Senior Security Engineer https://job-boards.greenhouse.io/mozilla/jobs/8088831 (job posting says Germany, but other countries are eligible, use the job search)
Check @aleeamini 's post. He has done a remarkable job of analyzing samples from last year's wipe of Iranian banks. I briefly wrote and talked about the operation before, but now that the cat is out of the bag, I guess everyone gets to enjoy the craftsmanship behind it. The blog post covers only the post-exploitation phase and local side of works, jumping from local access to unrestricted firmware and memory. The initial access remains uncovered here, but I strongly believe at least one of the RCEs dell fixed last year was used for gaining initial access to storage devices.
The structure and style of tooling and operation is also very similar and hallmarks of the infamous Predatory Sparrows. Details about this overlap will remain TLP gated though. You might remember a glimpse of that from the wiping attack against Iranian gas stations and fuel distribution system, which also attempted soft-bricking POS devices installed on pumps, combined with partial wipe of mid-level management and relay servers.
One of the most interesting aspects of these wipers used in Iran, which I believe are first of its kind publicly documented as well, are combining software based wipes with physical disruption of operation of device switches. This is mostly an effort to further block attempts to interrupt the wipe operation by physically switching off or restarting the storage device on-site. That alone buys some extra wipe time, before datacenter operators literally pull the plug on machines.
https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/
RE: https://infosec.exchange/@david_chisnall/117007707710681727
“All encryption is end-to-end, if you’re not picky about the ends.” -- Chris Fenner
yay, my 13th (14th?) chrome cve!!
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
The screensharingd bug that was killed on latest updates, is a pre-auth, contrary to what the company that disclosed it to Apple is writing. This is an amazing bug that allows to pwn any unpatched Mac that has Screen Sharing enabled. If you have it enabled go patch now. If you have old versions for which a 5T company doesn't bother to release patches, good luck!
Releasing a PoC that just allows to download any file from vulnerable machine.
I find this compelling, but my economic clue is subprime (pun intended). I would love to read critique on their arguments.
https://www.groundbrkr.com/p/the-second-derivative-why-no-one
As promised, DarkSword Kernel Exploit writeup is now live at https://therealclarity.github.io/blog/clearsword/
This goes over the root cause, what happens on the Kernel side and how the kernel exploit is implemented.
Hope it helps anyone looking to understand it! :)
Vegas in August = Hacker Summer Camp.
We'll be at Black Hat, B-Sides LV, and DEF CON 34.
Highlights: a demo of our upcoming Malware Analysis Add-On, a hands-on DLL sideloading workshop (40 seats, register now), a live look at Teams' new Git-native workflow, and recruiting. (Yes, we're hiring!)
👉 Find the full rundown and where to catch us: https://hex-rays.com/blog/hex-rays-hacker-summer-camp-2026