And here is the detailed report on our PSA from last week: "Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free" modzero.com/en/blog/plea...
Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free
modzero.com
And here is the detailed report on our PSA from last week: "Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free" modzero.com/en/blog/plea...
Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free
modzero.com
🎶 PSA: Multiple Denial of Service vulnerabilities in TeamSpeak. Find our colleague Michael Imfelds advisory here modzero.com/en/advisorie...
[MZ-26-01] TeamSpeak
modzero.com
We're Hiring! We are currently looking for a Penetration Tester and a Senior Red Teamer. Check out our open positions and reach out if you think you’d be a great fit. Here: modzero.com/en/jobs/
Jobs
modzero.com
Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und praktischen Lösungen will sich Nikonole einer zusammenbrechenden Welt entgegenstellen.
Hacken & Kunst: „Kunst allein reicht nicht aus“
Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und ...
netzpolitik.org
X basically industrialized the creation of fake porn of women who don't consent. Others did it first, but Grok made it normalized and centralized: publicly visible, instantly creatable by anyone, regardless of who's being targeted and dehumanized. Only question now is will X suffer any consequences
Sollen wir Büchertische zum Thema Fitness und Fasten machen oder gleich die Oster-Backbücher rausstellen?
No Leak, No Problem - Remember our PSA about updating your INSTAR cameras? Here’s the reason in detail, worked out and noted by our teammate Michael Imfeld: modzero.com/en/blog/no-l...
No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE
modzero.com
Does anyone here have a working way to contact archive.org? It's about a security issue...
catch a glimpse of us holding our annual “state of the zero” meetup - to wrap our heads around all of IT and us. we also took a boat trip, ate too many sweets, touched some grass, saved the world, had a barbecue and a drink or two…💓 #modzero #infosec #itsecurity #captainitswednesday
PSA update your INSTAR cameras. Our teammate Michael Imfeld identified a critical RCE (CVE-2025-8760) on 2k+ and 4K devices. Find the advisory here: modzero.com/en/advisorie...
[MZ-25-03] INSTAR 2K+ and 4K Series
modzero.com
Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...
When Backups Open Backdoors: Accessing Sensitive Cloud Data via
modzero.com
ROPing our way to “Yay, RCE” - and a lesson in the importance of a good nights sleep! Follow our Colleague Michaels journey of developing an ARM ROP chain to exploit a buffer overflow in uc-http modzero.com/en/blog/ropi...
ROPing our way to RCE
modzero.com
🔔 Unser #kandidierendencheck ist online: 18 Thesen beantworten - und ihr erfahrt, welche Kandidierenden in eurem Wahlkreis so denken wie ihr. 👇 www.kandidierendencheck.de/bundestag
kandidierendencheck Bundestagswahl 2025 | Wahlhilfe für deine Erststimme
Vergleichen Sie Ihre Meinung mit der Ihrer Kandidierenden über 18 Themen zur Wahl! Jetzt mitmachen!
kandidierendencheck.de
Seit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das Abstimmungsverhalten. netzpolitik.org/2025/real-o-...
Real-O-Mat: Taten zählen mehr als Worte
Seit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das ...
netzpolitik.org
was just listening to #DeLaSoul's classic #RingRingRing on the radio and thought about the time we broke a phone. or: how some coupled minor pinches can become a proper headache colleagues @yonk42.bsky.social and @parzel.bsky.social talked about it at #37c3 www.youtube.com/watch?v=K9mm...
37C3 - Finding Vulnerabilities in Internet-Connected Devices
YouTube video by media.ccc.de
youtube.com
Wenn Sie sich die Unwörter der letzten 11 Jahre anschauen, was fällt Ihnen auf? • 2024 Biodeutsch • 2023 Remigration
We broke something: in a recent pentest on a hardened target, we were able to achieve unauthenticated Remote Code Execution (RCE) via Server-Side Template Injection (SSTI) in a Spring Boot application We wrote it down for you to try at home: modzero.com/en/blog/spri...
Exploiting SSTI in a Modern Spring Boot Application (3.3.4)
modzero.com
Der @ths.ch und ich haben uns beim #38C3 mal wieder mit Wahlsoftware beschäftigt. media.ccc.de/v/38c3-der-t...
Der Thüring-Test für Wahlsoftware
Wähle Dein Risiko! Vor der Bundestagswahl 2017 veröffentlichten wir unsere Analyse über haarsträubende Sicherheitslücken in einer weit v...
media.ccc.de
Wieder ein mega Programm! Der CCC hat zu seinem Chaos Communication Congress #38C3 den ersten Fahrplan veröffentlicht: Version Alpha-0.1 fahrplan.events.ccc.de/congress/202...
I can highly recommend Shazzer from @garethheyes.co.uk, such a great tool for XSS research!
Digging for XSS Gold: Unearthing Browser Quirks with Shazzer
YouTube video by PortSwigger
youtube.com
Hello Bluesky 👋 We are an IT security company. Our team consists of like-minded hackers located in Germany and Switzerland. Our core areas of expertise are comprehensive technical security analyses, penetration tests and red teaming services. Want to learn more about us? Check: modzero.com/en/
In-depth IT Security
modzero.com