CVE Crowd's search feature is now public!
This means you can now search for vendors, products, package names or CVE numbers and find related posts on the Fediverse and Bluesky - all without signing up anymore.
Previously, I used sign up as an obstacle for bots. But since #ALTCHA proved good enough to keep those away, it now also secures search.
I hope this is useful to y'all!
#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking #CVE #CveCrowd
...If anybody's looking for a person who basically does everything from compiler {backend,frontend} development, GPU driver development, to hardware/firmware security research, let me know. #getfedihired
US only.
RE: https://mastodon.social/@campuscodi/117128474535423979
Ah, I get it now. They are doing the same thing to CISA that they did to 18F and login.gov - kill off perfectly functional (in fact, superior, non-partisan, cost-effective) public tech infrastructure so it can be privatized by attrition. The classic "starve it, then declare it ineffective" tactic. 😠
I want a Firefox extension that knows how to replace every single "N months ago" label with the actual exact timestamp (using patterns for how the data is hidden in tooltips, click-to-expand, etc.).
That shit is SO unhelpful. Like if I'm looking back at git history, I don't care that a change was made roughly 3 months ago. I care whether it was made before or after an email I'm looking at that said something relevant to the change.
⚠️ A few hours ago, a malicious crate was discovered on crates.io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted.
For details and how to see if you are impacted, see: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Microsoft killed my exploit 😢
This Friday on @offby1security I'll talk to @steph3nsims about what why, how and if this is the end for this class of exploit techniques
I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host. https://trustsig.eu/blog/wasm2c-tableflip-unchecked-calloc/
Just published “Vulnerability Analysis of CVE 2025 22226 Information Disclosure Due to OOB Read in VMwares HGFS” by Alex Zaviyalov the first vulnerability in an ITW VMWare guest to host escape chain 👇
https://www.nccgroup.com/media/1mzfvyzl/nccgroup_cve-2025-22226.pdf
We have achieved kernel code execution via the IDT under Windows 11 with VBS/HVCI/kCET enabled.
Read the technical write-up here: https://exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11
#Windows11 #KernelExploit #IDT #VBS #HVCI #kCET #DataOnly #RedTeam #ExploitResearch #WindowsSecurity #infosec #pentest
If I gambled on both NFTs and the metaverse to the tune of millions and millions of dollars and even renamed my company accordingly I would be so canceled I’d be farming potatoes, but people are still quoting Zuck AI predictions on my daily news feed.
Doing a presentation tomorrow on our utter dependence on US technology and specifically how we 100% picked US tools/support for cybersecurity as well. We are SO fucking fucked. #sentinel
Can someone explain to me why AI companies are not being investigated for hacking other companies?
In the country I am living in, authorities HAVE TO investigate when they get to know about a crime - even without a criminal complaint (because generally people who were e.g. murdered cannot complain any more...).
Is the US justice system already so broken that this doesn't work any more?