We derestricted crbug.com/382005099 today which might just be my favorite bug of the last few years: bad interaction between WebAudio changing the CPU's handling of floats and V8 not expecting that. See crbug.com/382005099#co... for a PoC exploit. Also affected other browsers
29.10.2025 14:27 โ ๐ 17 ๐ 6 ๐ฌ 0 ๐ 0
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch
The U.S. Department of Justice accused Peter Williams, former general manager of L3Harrisโ hacking division Trenchant, of stealing trade secrets and selling them to a buyer in Russia.
NEW: The U.S. govt accused Peter Williams, ex general manager of hacking tool maker L3Harris Trenchant, of stealing trade secrets and selling them to buyer in Russia.
As we reported earlier, Trenchant investigated a leak of internal tools this year. It's unclear if that investigation is related.
23.10.2025 15:47 โ ๐ 25 ๐ 21 ๐ฌ 1 ๐ 5
Exclusive: Apple alerts exploit developer that his iPhone was targeted with government spyware
A developer at Trenchant, a leading Western spyware and zero-day maker, was suspected of leaking company tools and fired. Weeks later, Apple notified him that his personal iPhone was targeted with spy...
SCOOP: A man who worked on developing hacking and surveillance tools for defense contractor L3Harris Trenchant was notified by Apple that his iPhone was targeted with mercenary spyware.
The developer believes he was targeted after he was wrongly accused of leaking zero-days developed by Trenchant.
21.10.2025 14:54 โ ๐ 27 ๐ 24 ๐ฌ 2 ๐ 3
Project Zero
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.
project-zero.issues.chromium.org/issues/42807...
16.10.2025 19:50 โ ๐ 10 ๐ 1 ๐ฌ 1 ๐ 0
We now have a (draft) @metasploit-r7.bsky.social exploit module in the pull queue for the recent Microsoft SharePoint Server unauthenticated RCE zero-day (CVE-2025-53770), based on the in-the-wild exploit published a few days ago. Check it out here: github.com/rapid7/metas...
23.07.2025 13:18 โ ๐ 11 ๐ 8 ๐ฌ 1 ๐ 0
Google fixes bug that could reveal users' private phone numbers | TechCrunch
The bug allowed a researcher to uncover recovery phone numbers of nearly any Google account.
New: A security researcher found a bug that revealed the private recovery phone number of almost any Google account.
TechCrunch verified the bug w/ the researcher, who quickly brute-forced the phone number of a test Google account we had set up.
09.06.2025 14:06 โ ๐ 64 ๐ 23 ๐ฌ 1 ๐ 5
"Windows App to replace Remote Desktop app for Windows"
There's a lot of confusion about what this means, so let me clarify:
This only affects the Remote Desktop App on the *Microsoft Store*, which you most likely don't use
Most system administrators use mstsc, the Windows built-in RDP client
12.03.2025 13:07 โ ๐ 5 ๐ 1 ๐ฌ 1 ๐ 0
We will never knowโ we will never have the faintest ideaโ how much money is getting made in insider trading windfalls from people in Trump's and Musk's circles who have an hour of notice about the daily swings in tariff policy or the occasional announced *expectations* of such swings.
06.03.2025 19:06 โ ๐ 1943 ๐ 644 ๐ฌ 42 ๐ 45
Ghidra 11.3 is OUT!
โจPyGhidra is the new feature to be excited about.โจโจItโs a Python library providing direct access to the Ghidra API. โจโจ
I expect this to massively increase Reverse Engineering tool development, as it significantly reduces the barrier to entry for Ghidra interaction.
06.02.2025 18:34 โ ๐ 36 ๐ 16 ๐ฌ 1 ๐ 1
Musk Cronies Dive Into Treasury Dept Payments Code Base
Overnight, Wired reported that, contrary to published reports that DOGE operatives at...
A 25-year-old DOGE worker named Marko Elez who has admin privileges on Treasury dept systems that control about 95% of payments made by the gov, including Social Security checks, tax refunds and contract payments "has already made extensive changes to the code base for these critical payment system"
04.02.2025 19:12 โ ๐ 567 ๐ 345 ๐ฌ 33 ๐ 64
03.02.2025 01:52 โ ๐ 22 ๐ 3 ๐ฌ 1 ๐ 0
To all our Bluesky friends, feel free to follow us here as we will be posting regular updates as the conference gets closer. See you in May!
21.01.2025 15:32 โ ๐ 8 ๐ 3 ๐ฌ 0 ๐ 0
Project Zero
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium.org/issues/36869...
10.01.2025 00:08 โ ๐ 38 ๐ 16 ๐ฌ 1 ๐ 2
Around 2008 I was in Ottawa and some MoD person mentioned that only a few years ago they stopped wargaming against a US invasion, and I joked "just wait until they run out of water for their golf courses in Arizona"...
09.01.2025 11:08 โ ๐ 23 ๐ 5 ๐ฌ 2 ๐ 0
Someone is using a fake PoC for the LDAPNightmare exploit to infect researchers and threat actors with an infostealer
www.trendmicro.com/en_us/resear...
09.01.2025 10:05 โ ๐ 29 ๐ 11 ๐ฌ 1 ๐ 2
Surfer Gabriel Media leaping from his surfboard at the top of the wave so the he appears to be floating in the air above the water, completely upright, with one arm extended above his head, holding out one finger, his surfboard trailing behind and also floating in the air
Brazil's Gabriel Medina with the best touchdown celebration I've ever seen (Photo: Jerome Brouillet/Getty)
29.07.2024 20:08 โ ๐ 334 ๐ 97 ๐ฌ 8 ๐ 17
in the 90โs, computers would scream every time you went online. thatโs called foreshadowing
07.09.2023 21:40 โ ๐ 8402 ๐ 3063 ๐ฌ 56 ๐ 57
The windows networking stack has been the source of various vulnerabilities over the years, a few of which could lead to remote code execution. This talk wil...
Recon2023 Erik Egsgard HuntForRedOctober
Video of the talk I gave at Recon on hunting for bugs in the Windows TCP/IP stack is now up!
youtu.be/jzA5aLrK4OY
07.09.2023 21:32 โ ๐ 10 ๐ 1 ๐ฌ 0 ๐ 0
DSU Cyber Operations graduate | software vulnerability research | Minnesota Twins | he/him
Offensive security conference in the heart of Paris. 10-11th October 2025
https://www.hexacon.fr/
Degenerate Artist / Sysadmin / Cybersecurity / System Integration
The worldโs premier hacker conference. Serving the global hacker community since 1993.
Defcon.org
Forum.defcon.org
Defcon.social
Since 1984, 2600 Magazine has published the hacker perspective and documented the development of the hacking community. In addition to the magazine, we have a weekly radio show ("Off The Hook") and a biennial conference (Hackers On Planet Earth - HOPE).
DFIR by day, DFIR by night.
Former vet tech.
Violinist, Salty, Tired, Meme Enthusiast.
Hacker - Helper - Human
JaysonEStreet.com
Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX.
vulnu.com <- sign up for my weekly cybersecurity newsletter
security architect / co-founder @digitaldefenseinstitute.com / co-founder Recon InfoSec
โฅโฅโฅ == @eric.zip, nerdery, rainbows, sweatpants
she/her | mama of 3 | ๐ค๐๐ฟ๐๐
unicorns.lol
https://short-stack.net
whitneychampion.com/portfolio
SecOps Witch ๐ฎ
Lego zealot & Blizzard tragic ๐ฎ
Slave to 7yo terror ๐ถ
Australian based ๐ฆ
Provider of sarcasm & profanity ๐คฌ
she/her โ๏ธ
Views ALL MINE ๐
https://linktr.ee/girlgerms
She/Her. Cybersecurity Educator & Engineer. Writer. Keynote Speaker. LinkedIn Learning Author (150K+ learners). Neurospicy (ADHD). Sharing insights to inspire growth and connection. Black and proud.
Stephandsec.com
Itโs me. Sherrod DeGrippo
Father. Grandpa. Geek. Hacker. Former journalist. Security researcher. CMO @BSidesLV.org Member: Curated Intel
Principal Eng, Detection & Response Lead | @dnanexus.bsky.social | Founder, Sonar Security | Red Siege, VMware Tanzu, NASA GSFC, Apple, 18F | art, lego, board games, comics, cute animals |๐ง๐ปโโ๏ธโต๏ธ
Past: Host of "Tribe of Hackers"; Assoc. Producer "Darknet Diaries."
Current: Cybersecurity researcher and executive. Also, father of the fastest climber who has ever lived. Seriously.
Warning: I talk about my son ALOT
โUt scandis, alios subleva.โ
Adviser, lawyer, and sometimes cybersecurity circus ringmaster - my monkeys fly.
Breaker of software, responder of incidents, IANS Faculty, VP R&D Hunter Strategy.
CSO of TPO.groupโฆ๏ธSenior Fellow for Global Cyber Policy at the Council on Foreign Relationsโฆ๏ธ EFF Board of Directorsโฆ๏ธshe/her โฆ๏ธ bestselling author but only that one time
Tech Dysangelist
cDc/hack.xxx/veilid
Support Veilid! Badge: ๐
www.veilid.com
Merch at: @hack.xxx
he/him/hey buddy