Vulnerability Research
532 subscribers
A channel dedicated to post stuff about computer vulnerability research, exploit development and reverse engineering.
Download Telegram
The new Microsoft Visual Studio optimizer seems provisioned.
Automated Exploit Detection in Binaries by Luis Miras still works in 2016.
There are targets inside Iran being the sole victim of the Vijeo Citect HMI from the Schneider Electrics.
A Cyber-Espionage malware has been spotted in GeoIP of Pakistan. It's a very complex threat, leading to Cisco IOS remote pwnage.
An iOS application named i-FunBox found to be exploitable.
VTGuard on Internet Explorer itself is based on VPTRs and VTs, funny cap with _funcap.
Working with the Samsung Smart View reveals funny stuff.
An old school stack-based overflow has been found on Proxifier software.
DLL Hijacking 0day on MS Office Word has been spotted in the wild.
👍1
Exploitation of WhatsApp messenger has been spotted in the wild.
A new technique (of address access probing) in Egg-Hunting has been found in a Chinese exploit kit.
Have you ever disassembled NtQueryIntervalProfile routine?
A new exploit on Cisco IOS has been spotted in the wild, with the price of $3M.
A new 0day in QNAP devices (all-models, all-types) is being largely used by Russian threat actors.
👍4🖕2
A new 0day in Microsoft Windows Active Directory has been spotted in the wild. An underground community is selling it for $3M.
Apple's PAC (Pointer Authentication Codes) exploit mitigation technology is proofed to be bypassed by a Chinese actor, regardless of the FORCEDENTRY incident.
👍4
Two RCE 0days on Mikrotik firmware have been spotted in the wild. They are actively (but staying below the radar) being used by a Chinese threat actor, linking to the government.
A chinese campaign with 0day exploitation on Fortinet and Citrix has been spotted in the wild.