Steph (@defane) 's Twitter Profile
Steph

@defane

ID: 36366781

calendar_today29-04-2009 14:16:25

11 Tweet

260 Takipçi

761 Takip Edilen

Mickey Jin (@patch1t) 's Twitter Profile Photo

As promised, I just dropped a dozen new sandbox escape vulnerabilities at #POC2024 If you missed the talk, here is the blog post: jhftss.github.io/A-New-Era-of-m… Slides: github.com/jhftss/jhftss.… Enjoy and find your own bugs 😎

kmkz (@kmkz_security) 's Twitter Profile Photo

After the MS process...and the reward 🙄 our #Microsoft AutoUpdate #EoP vuln. is not a #0day anymore Good job of our teammate Steph 🇷🇪🇫🇷 Note: it is not "just" an #LPE affecting MS products so think about this when using #O365 on your #MacBook msrc.microsoft.com/update-guide/v… #patchtuesday

After the MS process...and the reward 🙄 our #Microsoft AutoUpdate #EoP vuln. is not a #0day anymore
Good job of our teammate <a href="/defane/">Steph 🇷🇪🇫🇷</a>
Note: it is not "just" an #LPE affecting MS products so think about this when using #O365 on your #MacBook 
msrc.microsoft.com/update-guide/v…
#patchtuesday
SEC Consult (@sec_consult) 's Twitter Profile Photo

🚨 Critical vulns in dormakaba exos 9300! We’re sharing 20 CVEs in dormakaba’s physical access control system: doors can be opened without authentication with network access. Kudos to dormakaba for excellent handling & patches. 👉 r.sec-consult.com/dormakaba #ResponsibleDisclosure

🚨 Critical vulns in dormakaba exos 9300! We’re sharing 20 CVEs in dormakaba’s physical access control system: doors can be opened without authentication with network access. Kudos to <a href="/dormakaba/">dormakaba</a> for excellent handling &amp; patches. 
👉 r.sec-consult.com/dormakaba #ResponsibleDisclosure
kmkz (@kmkz_security) 's Twitter Profile Photo

2 y ago we tried to submit a research projet on this components to a defense CFP because this has a huge attack surface since it is used almost anywhere ! ->rejected : not innovative (yep, not AI content - literally this) ... but SEC Consult did not try: they did 👌🏻👏👏