Unfortunately, the Viettel Cyber Security (@vcslab) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.
CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog
Hot off the press!
#cisa #kev #cve #zeroday #vulnerability #eitw #activeexploitation
An idea I recently heard on a parenting podcast really resonated with me. Tech has created a generation of people used to instant gratification.
Hungry? Open an app. Want to listen to music? Open an app. Bored? Open an app.
However a lot of needs in life canât be gratified instantly and we now have many people, both adults and kids, who simply donât know how to handle that. We now have entire subcultures whose main dysfunction is they canât just get what they want without work and theyâre mad.
After I refused a bribe to remove a @web3isgreat post about alleged crypto pyramid scheme co-founder Roman Ziemian, Iâve now received a fraudulent copyright claim aimed at forcing me to take it down
The Irish Data Protection Commission fines LinkedIn âŹ310M over using personal data for behavioral analysis and targeted ads under GDPR, after a 2018 complaint (Ian Curran/The Irish Times)
https://www.irishtimes.com/business/2024/10/24/microsoft-owned-linkedin-fined-310m-by-irish-data-protection-commission/
http://www.techmeme.com/241024/p13#a241024p13
Our first collision of Day Three: the group from STEALIEN Inc. successfully popped the Lorex camera, but the bug they used had already been demonstrated in the contest. They still earn $3,750 and 1.5 Master of Pwn points. #Pwn2Own #P2OIreland
Unfortunately, Sina Kheirkhah (@SinSinology) and Enrique Castillo (@hyprdude) of Summoning Team (@SummoningTeam) could not get their exploit of the Ubiquiti AI Bullet working within the time allotted.
We're ready for Day Three of #Pwn2Own Ireland! Weâve already awarded $874,875, & we have 15 attempts left to go. Will we hit the $1,000,000 mark or will all remaining attempts end up in bug collisions? Follow along with the results here and on our blog: https://www.zerodayinitiative.com/blog/2024/10/24/pwn2own-ireland-2024-day-three-results
One of our final attempts of Day 2 ends in a collision. The InfoSect (@infosectcbr) group successfully got a shell on the Lorex camera, but they used a bug previously seen in the contest. They still earn $3,750 and 1.5 Master of Pwn points. #Pwn2Own #P2OIrelandv
â Fortinet has issued an advisory for FortiManager confirming CVE-2024-47575 is being actively exploited in the wild. This extremely critical vulnerability has a CVSS score of 9.8.
â ď¸ This vulnerability can enable RCE upon connecting to a FortiManager instance with a valid Fortinet device certificate and could lead to total compromise of the vulnerable system.
âąď¸ Shoutout to @rk for the quick work on this Rapid Response!
đ Launch runZero now to pinpoint assets that could be affected -- no rescanning or credentials required:
https://www.runzero.com/blog/how-to-find-fortimanager-instances-on-your-network/
TIL: H. P. Lovecraft, on the 'proper' pronunciation of 'Cthulhu':
The name of the hellish entity was invented by beings whose vocal organs were not like man's, hence it has no relation to the human speech equipment. The syllables were determined by a physiological equipment wholly unlike ours, hence could never be uttered perfectly by human throats ... The actual sound -- as nearly as any human organs could imitate it or human letters record it -- may be taken as something like KhlĂťl'-hloo, with the first syllable pronounced gutturally and very thickly. The u is about like that in full; and the first syllable is not unlike klul in sound, hence the h represents the guttural thickness.
(Not your usual pronunciation note -- the equivalent of "you kinda can't get there from here, but if you have to try, here's now")