Slava Moskvin | Path Cybersec (@slava_moskvin_) 's Twitter Profile
Slava Moskvin | Path Cybersec

@slava_moskvin_

Security researcher

ID: 800829554

linkhttps://slavamoskvin.com/ calendar_today03-09-2012 17:21:31

203 Tweet

828 Takipรงi

264 Takip Edilen

xvonfers (@xvonfers) 's Twitter Profile Photo

(ZDI-CAN-26505)[ksmbd] Attacker send malformed smb2 negotiate request -> smbd return error response -> attacker can send smb2 session setup even thought conn->preauth_info is not allocated(NPD) github.com/torvalds/linuxโ€ฆ Reported by Viacheslav Moskvin(Slava Moskvin | Path Cybersec)

Slava Moskvin | Path Cybersec (@slava_moskvin_) 's Twitter Profile Photo

Slides and fuzzer code from the Fuzzing Linux kernel modules stream are now live: github.com/sl4v/hfsplus-kโ€ฆ Thanks again to Stephen Sims for hosting!

Slava Moskvin | Path Cybersec (@slava_moskvin_) 's Twitter Profile Photo

My network fuzzer net-shredder found a remote NULL pointer dereference in the Linux kernel's SMB server (ksmbd) slavamoskvin.com/zdi-25-310-remโ€ฆ

Slava Moskvin | Path Cybersec (@slava_moskvin_) 's Twitter Profile Photo

Proof that AI can now find 0-days even w/o agents or advanced tooling. Also pretty cool: o3 managed to find the known vulnerability only 8 out of 100 times, and the 0-day just 1 out of 100. I hadnโ€™t realized it might take that many tries to get a useful result from AI.

POC_Crew ๐Ÿ‘จโ€๐Ÿ‘ฉโ€๐Ÿ‘ฆโ€๐Ÿ‘ฆ (@poc_crew) 's Twitter Profile Photo

๐Ÿ› ๏ธ [POC2025] TRAINING MacOS/iOS Kernel User Fuzzing Training by Meysam Firouzi (.) ๐Ÿ“… Nov 10-12 (3 days) ๐Ÿ“ Four Seasons Hotel Seoul, South Korea ๐Ÿ”— More info powerofcommunity.net/#training #POC2025

๐Ÿ› ๏ธ [POC2025] TRAINING

MacOS/iOS Kernel User Fuzzing Training
by Meysam Firouzi (<a href="/R00tkitSMM/">.</a>)

๐Ÿ“… Nov 10-12 (3 days)
๐Ÿ“ Four Seasons Hotel Seoul, South Korea

๐Ÿ”— More info powerofcommunity.net/#training
#POC2025