governa, to firefox
@governa@fosstodon.org avatar
spacerog, to IBM
@spacerog@mastodon.social avatar

I don’t usually post work stuff but doesnt have a Mastodon presence so once in a while I have to post the important stuff.

Congratulations to @chompie1337 who scored a win in the Windows 11 LPE category! Her exploit circumvents the latest Virtualization Based Security mitigations. She becomes the first solo female competitor to score a full win at , the world’s most prestigious hacking competition.

(Only links I have are to Xitter and I won’t post those)

it4sec, to random
@it4sec@mastodon.social avatar

The , which began in 2007, initially focused on identifying vulnerabilities in web browsers and operating system.
The first Pwn2Own Automotive event occurred in 2024 in Tokyo.
I'm looking forward to seeing how it will shape Automotive Cyber Security in the next few years.

securityaffairs, to tesla Italian
thezdi, to random

The first ever Automotive is in the books! We awarded $1,323,750 throughout the event and discovered 49 unique zero-days. A special congratulations to Synacktiv, the Masters of Pwn! Stay with us here and at the ZDI blog as we prepare for Pwn2Own Vancouver in March.

YourAnonRiots, to Cybersecurity Japanese

📢 Tesla, Sony, Alpine Players and others Hacked on Day One at Automotive 2024.

https://hackread.com/pwn2own-automotive-tesla-sony-alpine-players-hack/

governa, to tesla
@governa@fosstodon.org avatar
jos1264, to random
@jos1264@social.skynetcloud.site avatar
governa, to tesla
@governa@fosstodon.org avatar
thezdi, to random

That’s a wrap for Day 1 of Automotive! We awarded $722,500 in prizes for 24 unique exploits. Tune back in tomorrow here or at the ZDI blog for more updates! Here are the current standings:

thezdi, to tesla

Announcing Vancouver 2024! We're heading back to @CanSecWest with a new Cloud-Native/Container category. We've also added @SlackHQ to the Enterprise Comms Category, and returns as a partner. Read all the details and rules at https://www.zerodayinitiative.com/blog/2024/1/16/pwn2own-vancouver-2024-bring-cloud-nativecontainer-security-to-pwn2own

Fr333k, to random

Would love to be in Tokyo for Automotive. Maybe another time, I hope people will toot …

video/mp4

thezdi, to random

Let's take a look behind the scenes of Automotive to see how the setup is going...
https://youtube.com/shorts/3ikKHDnAUeI

thezdi, to Ubiquiti

Our blog series looking at targets for Automotive continues. Today, we cover the attack surface of the Connect EV Station. Read all the details (including hi-res pics of the PCBs) at https://www.zerodayinitiative.com/blog/2023/12/5/attack-surface-of-the-ubiquiti-connect-ev-station

raptor, (edited ) to random
thezdi, to random

Miss anything from Toronto 2023? @MaliciousInput and @dustin_childs cover all of the highlights of the event, which awarded $1,038,250 for 58 unique 0-days. They also provide a look ahead to the events of 2024. Watch the video at: https://youtu.be/bQ7jfLpMEl0

0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🇺🇸 🎰 Hackers that breached Las Vegas casinos rely on violent threats, research shows
➝ 🔓 🇺🇸 University of Michigan employee, student data stolen in
➝ 🔓 discloses security incident linked to breach
➝ 🇺🇸 Cyber attacks hit NY state operation, two Hudson Valley hospitals
➝ 🇺🇸 🗳️ D.C. Board of Elections: Hackers may have breached entire voter roll
➝ 🔓 🇮🇪 Thousands of drivers have sensitive data exposed to hackers in major IT
➝ 🇷🇺 📨 Pro-Russia hackers target inboxes with in webmail app used by millions
➝ 🇫🇷 🇷🇺 says Russian state hackers breached numerous critical networks
➝ 🇳🇬 Nigerian Police dismantle recruitment, mentoring hub
➝ 🇵🇸 💸 donation scams emerge amid Israel-Hamas war
➝ 🇪🇸 👮🏻‍♂️ arrests 34 who stole data of 4 million people
➝ 🇨🇦 🇨🇳 : Lawmakers Targeted by China-Linked ‘’ Disinformation
➝ 🇺🇸 🇷🇺 Ex-NSA Employee Pleads Guilty to Leaking Classified Data to
➝ 🦠 🇰🇵 N. Korean Group Targets Software Vendor Using Known Flaws
➝ 🦠 🇮🇷 Iranian Group Launches New Wave of IMAPLoader Attacks
➝ 🦠 🪰 malware framework infects 1 million , hosts
➝ 🦠 📱 Zero-Day Attacks: Experts Uncover Deeper Insights into Operation Triangulation
➝ 🔓 📱 Galaxy S23 hacked two more times at Toronto
➝ 🔓 Critical Flaws Uncovered in , , and Platforms
➝ 🔓 🩺 Critical Flaw in NextGen's Mirth Connect Could Expose Data
➝ 🔓 Warns of Critical Remote Code Execution Vulnerability in BIG-IP
➝ 🔓 🍏 Hackers can force iOS and browsers to divulge and much more
➝ 🩹 warns admins to patch CVE-2023-4966 bug immediately
➝ 🔓 ✌🏻 Finds Second Zero-Day as Number of Hacked Devices Apparently Drops
➝ 🔓 Critical RCE flaws found in access audit solution

📚 This week's recommended reading is: "Click Here to Kill Everybody: Security and Survival in a Hyper-connected World" by Bruce Schneier

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-432023

thezdi, to random

That’s a wrap for Day 2 of Toronto 2023 – we’ve awarded a total of $801,250 so far this week! We’ll be back tomorrow with another full day of attempts. See the full schedule and today’s results at www.zerodayinitiative.com/blog

Leaderboard as of today:

thezdi, to random

The schedule for Toronto is now live! We've got an exciting four days of exploits ahead of us. Check it out at https://www.zerodayinitiative.com/blog/2023/10/23/pwn2own-toronto-2023-the-schedule

thezdi, to random

We're just one day away from Toronto 2023 and the return of the SOHO Smashup! Contestants must exploit a Wi-Fi router then pivot to another device. Success earns them $100K. See the drawing for order at https://youtube.com/live/Tm8-syB79FQ. Results will be posted throughout the week.

raptor, to random
0x58, to Cybersecurity

📨 Latest issue of my curated and list of resources for week /2023 is out! It includes the following and much more:

➝ 🔓 🏌🏻‍♂️Golf gear giant data breach exposes info of 1.1 million
➝ 🔓👕 Forever 21 data breach affects half a million people
➝ 🔓 🤦🏻‍♂️ customers hit by hackers, because of default passwords
➝ 🇺🇸 ⚖️ Lawsuit Accuses University of Minnesota of Not Doing Enough to Prevent
➝ 🎬 🔓 discloses data breach following security incident
➝ 🏥 🔓 Organizations Hit by Cyberattacks Last Year Reported Big Impact, Costs
➝ 🇺🇸 🌎 joins a growing chorus of organizations criticizing a cybercrime treaty
➝ 🇺🇸 🦠 U.S. Hacks , Quietly Removes Botnet Infections
➝ 🇷🇺 🇺🇦 targets with new Android , intel agencies say
➝ 🇷🇺 🕵🏻‍♂️ Unmasking , One of the World’s Top Cybercrime Gangs
➝ 🇨🇳 👀 ‘Earth Estries’ Group Targets Government, Tech Sectors
➝ 🇨🇳 Chinese Hacking Group Exploits Barracuda Zero-Day to Target Government, Military, and Telecom
➝ 💸 🇪🇺 Pay our ransom instead of a fine, gang tells its targets
➝ 🇺🇸 🇨🇳 : Pro-Chinese influence operation was the largest in history
➝ 🇪🇸 📸 Spain warns of Locker ransomware phishing attacks
➝ 🇵🇱 🚂 Two Men Arrested Following Railway Hacking
➝ 🇰🇵 🐍 hackers deploy fake PyPI packages in attacks
➝ 💸 fraud-as-a-service expands, now targets banks and 251 brands
➝ 💬 🎠 Trojanized and apps on Google Play delivered spyware
➝ 🦠 📄 MalDoc in PDFs: Hiding malicious Word docs in PDF files
➝ 🇧🇷 👀 A Brazilian phone was hacked and victims’ devices ‘deleted’ from server
➝ 👨🏻‍💻 🔐 Enterprise Server Gets New Security Capabilities
➝ 🚗 💰 Over $1 Million Offered at New Hacking Contest
➝ 🩹 Patches High-Severity Flaws in Enterprise, IT Service Intelligence
➝ ⛏️ 🔓 Recent Flaws Chained in Attacks Following Exploit Publication

📚 This week's recommended reading is: "Spam Nation: The Inside Story of Organized Cybercrime―from Global Epidemic to Your Front Door" by @briankrebs

Subscribe to the newsletter to have it piping hot in your inbox every week-end ⬇️

https://infosec-mashup.santolaria.net/p/infosec-mashup-week-352023

raptor, (edited ) to ubuntu
thezdi, to random

Revealing the targets for Automotive. We've got 4 categories: Tesla, Infotainment systems, EV Chargers, and Operating Systems. Over $1 Million USD in cash and prizes available. We'll see you in Tokyo! https://www.zerodayinitiative.com/blog/2023/8/28/revealing-the-targets-and-rules-for-the-first-pwn2own-automotive

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines