@k0lj4.bsky.social

At #Pwn2Own Ireland 2024, we successfully targeted the SOHO Smashup category. 🖨️ Starting with a QNAP QHora-322 NAS, we pivoted to the Canon imageCLASS MF656Cdw - and ended up with shellcode execution. Read the full vulnerability deep dive here 👉 neodyme.io/en/blog/pwn2...

Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw

This blogpost starts a series about various exploits at Pwn2Own 2024 Ireland (Cork). This and the upcoming posts will detail our research methodology and journey in exploiting different devices. We st...

neodyme.io

🔎 Digging deeper into COM hijacking! In Part 3, we explore two new vulnerabilities: 🗑️ Webroot Endpoint Protect (CVE-2023-7241) – SYSTEM via arbitrary file deletion 📥 Checkpoint Harmony (CVE-2024-24912) – SYSTEM via a file download primitive Read more: neodyme.io/en/blog/com_...

The Key to COMpromise - Downloading a SYSTEM shell, Part 3

In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r...

neodyme.io

🪝Introducing HyperHook! 🪝 A harnessing framework for snapshot-based #fuzzing using Nyx. ⚒️ HyperHook simplifies guest-to-host communication & automates repetitive tasks, making snapshot-fuzzing easier & more efficient! 🔗 Read more: neodyme.io/en/blog/hype...

Introducing HyperHook: A harnessing framework for Nyx

In this post, we introduce HyperHook, a harnessing framework for snapshot-based fuzzing for user-space applications using Nyx. HyperHook simplifies guest-to-host communication and automates repetitive...

neodyme.io

🔎Part 2 of our COM hijacking series is live! This time, we discuss a vulnerability in AVG Internet Security, where we bypass an allow-list, disable self-protection, and exploit an update mechanism to escalate privileges to SYSTEM 🚀💻 neodyme.io/en/blog/com_...

The Key to COMpromise - Abusing a TOCTOU race to gain SYSTEM, Part 2

In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r...

neodyme.io

Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog series! 🎊 Check out our first blog post on our journey to 💥 exploit five reputable security products to gain privileges via COM hijacking: neodyme.io/blog/com_hij...

The Key to COMpromise - Pwning AVs and EDRs by Hijacking COM Interfaces, Part 1

In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r...

neodyme.io

ND people are @ #38C3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YELL) and a not yet mitigated Bitlocker Flaw! (Saturday, 7:15 PM HUFF)

Bild

💥When security software itself becomes a target! 💥 Learn how we've uncovered critical vulnerabilities in Wazuh, turning a powerful security tool into an unexpected attack vector. 👉 Read more about the findings: neodyme.io/en/blog/wazu...

From Guardian to Gateway: The Hidden Risks of EDR Vulnerabilities

Explore the hidden risks within security software as we dive into vulnerabilities of Wazuh, a popular EDR solution. This post reveals how even trusted tools can become targets, highlighting the import...

neodyme.io

Just published a blog post about some critical vulnerabilities I discovered in Wazuh last year! The post covers details on how I found these vulnerabilities and highlights why security tools like EDRs can themselves become valuable targets for attackers. #infosec neodyme.io/en/blog/wazu...

From Guardian to Gateway: The Hidden Risks of EDR Vulnerabilities

Explore the hidden risks within security software as we dive into vulnerabilities of Wazuh, a popular EDR solution. This post reveals how even trusted tools can become targets, highlighting the import...

neodyme.io