The next battleground is in sight, and things are going to move fast. Half-baked tech pitched as transformational will be quickly adopted and thrown in front of children without any validation, but the demos will be amazing!
Karsten
@gr4yf0x.bsky.social
VR. Can cook a decent Cacio e Pepe. Physicist in a former life.
We just published @firefox.com updates to fix the exploits used at the Pwn2Own contest yesterday and today. Both contestants achieved RCE in our content process but did not escape the sandbox. blog.mozilla.org/security/202...
Firefox Security Response to pwn2own 2025 – Mozilla Security Blog
At Mozilla, we consider security to be a paramount aspect of the web. This is why not only does Firefox have a long running bug bounty program but also mature ...
blog.mozilla.org
It’s only Tuesday but the first night of Lobbycon has already started! 🍻
the takeover has begun.. trainings start tomorrow morning!
RUMOURS are TRUE 🤷♀️ PHRACK will be releasing a SPECIAL #71.5 👉HARDCOVER👈 at www.offensivecon.org BERLIN ("The 𞅀-Day Edition"). Main #72 release THIS SUMMER at MULTIPLE conferences (main release at WHY2025). ❤️
To prevent deer from being hit by cars Finland has tried using reflective paint. (https://www.smithsonianmag.com/smart-news/avoid-deer-strikes-finland-painting-deer-antlers-reflective-paint-180949792/) File this under "solutions to modern problems that summon the old gods."
The BlackHoodie training at OffensiveCon has a whole of 2 seats left, and we will have a special give-away with this edition :) blackhoodie.re/Offensivecon...
Blackhoodie OffensiveCon 2025
Hackers around the globe, listen, BlackHoodie will be at OffensiveCon this year :) For the very first time we’re offering a 1-day free training, for women, by women, at the most prestigious offensive ...
blackhoodie.re
Don't forget, the CFP for the 40th anniversary issue of Phrack is open until June 15th 2025. You can be someone's favorite article in the future!! bsky.app/profile/phra...
We heard you needed some more time, so we wanted to let you cook. We decided to push the Phrack 72 CFP deadline back until June 15th. Stay tuned for upcoming Phrack events. Print this flyer out and give it to someone IRL!!
Save the date - @blackhoodie.bsky.social is partnering with @offensivecon.bsky.social this year to bring a BlackHoodie training to Berlin! Students will learn how to place compiler backdoors in innocent code. Mark your calendars for May 15th! Registration opens tomorrow, space is very limited ☺️
Happy to share my slides from BOOTSTRAP25. Unfortunately the bug discussed is still not patched in Linux 6.14.0 despite it being reported explicitly. Slides are in markdown but there's a PDF in "releases" too github.com/jduck/bs25-s...
GitHub - jduck/bs25-slides: Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25
Slides from "Musing from Decades of Linux Kernel Security Research" at BOOTSTRAP25 - jduck/bs25-slides
github.com
Must be @argp.bsky.social and karl's article on the FreeBSD kernel allocator. The first one I worked really through, introduced me to kernel exploitation, and finally helped me with my first real exploit for FreeBSD-SA-19:02.fd. phrack.org/issues/66/8#...
.:: Phrack Magazine ::.
Phrack staff website.
phrack.org
What is your favorite Phrack article? What did it teach you?
Good analysis by the syzkaller developer, how some of thr latest ITW vulns could have been found.
Looks like we have a confirmation that Cellebrite uses memory corruptions in Linux kernel USB drivers to unlock Android phones. First 2 bugs seem easily discoverable by syzkaller/syzbot with a bit of extra descriptions. 3rd one is likely as well ⤵️
Pumpkin (@u1f383 on X) does cool work. Here is another cool read about an interesting race condition involving signal handling u1f383.github.io/linux/2025/0...
Linux Kernel Some Vsock Vulnerabilities Analysis
After CVE-2024-50264, the Theori team reported five more issues in the Linux kernel vsock subsystem, and syzbot recently discovered two additional issues. I believe these provide valuable insights int...
u1f383.github.io
Linux kernel exploitation slides from Pumpkin. He exploited a stack out-of-bounds write bug in the traffic control subsystem. u1f383.github.io/slides/talks...
Really great read by @h0mbre (on X) about his journey to exploit a Linux n-day on kCTF. Not only the exploit but the process to understand the bug including own failures, e.g. deal with CONFIG_DEBUG_LIST, is full of insights. h0mbre.github.io/Patch_Gappin...
Patch-Gapping the Google Container-Optimized OS for $0
Background I’m trying to really focus this year on developing technically in a few ways. Part of that is reviewing kCTF entries. This helps me get a sense of what subsystems are producing the most bug...
h0mbre.github.io
Hackers rejoice! We are releasing the Phrack 71 PDF for you today! Don't forget this year is Phrack's 40th anniversary release! Send in your contribution and be part of this historical issue! The CFP is still open, you can find it and the PDF link at phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
phrack.org
To all our Bluesky friends, feel free to follow us here as we will be posting regular updates as the conference gets closer. See you in May!
As of today I'm not longer with CrowdStrike. Looking forward to new challenges in VR :)
Can recommend Satoshi's training as well, rarely had a training that was such hands-on.
Happy to hear that!
[RSS] Linux Kernel: TOCTOU in Exec System github.com -> Original->
Creative vuln research by Eloi (@elvanderb on X) on XNU logic bugs t.co/Z3ktOkj6Gi
https://www.synacktiv.com/sites/default/files/2024-11/finding_and_exploiting_an_old_xnu_logic_bug.pdf
t.co
Cool idea. Artists under the Taylor Swift level usually get their money through album sales and merch, maybe concerts only.
I really like the idea of Bandcamp Gift Cards! Get your friends and family hooked on supporting independent artists/small labels! https://bandcamp.com/gift_cards Original->
I really like the idea of Bandcamp Gift Cards! Get your friends and family hooked on supporting independent artists/small labels! https://bandcamp.com/gift_cards Original->
Interesting paper by Erin Avllazagaj to automatically find Linux kernel objects being potentially useful for privilege escalation, tool is called SCAVY. www.usenix.org/system/files...
usenix.org
Slides for my @ekoparty talk "Advanced Fuzzing With LibAFL" - > docs.google.com/presentation...
Advanced Fuzzing With LibAFL @ Ekoparty 2024
Advanced Fuzzing With LibAFL Dominik Maier Ekoparty 2024-11-15 1
docs.google.com