Manu

16 posts

Manu banner
Manu

Manu

@rtfmkiesel

häcker

Switzerland Beigetreten Mayıs 2021
121 Folgt102 Follower
Manu
Manu@rtfmkiesel·
There are probably more vulns to be found, especially in the parts that I did not look at. Passing the torch to all the other researcherz.
English
0
0
0
53
Manu
Manu@rtfmkiesel·
First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested. mkiesel.ch/posts/lenovo-v…
English
1
1
3
131
Manu
Manu@rtfmkiesel·
Nobody asked for them, but here are my uBlock rules to slim down Twitter/X, Bluesky, and Mastodon. They disable fancy features and make it so that basically there are only the options to post and to view your "following" feed. No more distractions! gist.github.com/rtfmkiesel/1b7…
English
0
0
0
70
Manu retweetet
TrendAI Zero Day Initiative
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
0
5
17
3K
Manu retweetet
TrendAI Zero Day Initiative
We have a collision! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) earned $25,000 USD and 4 Master of Pwn points with the Charging Connector Protocol/Signal Manipulation add‑on against the Grizzl‑E Smart 40A, chaining an authentication bypass (CWE‑306) to remote code execution via CWE‑494. #Pwn2Own #P2OAuto
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
0
6
16
2.9K
Manu retweetet
cy//ective
cy//ective@cyllective·
The final stage would not have been possible without John Ostrowski from @compasssecurity thanks for the Swiss infosec collaboration! 🫕🤝
English
0
1
1
43
Manu
Manu@rtfmkiesel·
🇨🇭With El Tony's new Mate Zero and Coop's New Prix Garantie Mate, matelab is now at 60 mate-based beverages 🧉 matelab.ch
English
0
0
2
41
Manu
Manu@rtfmkiesel·
@_nnxxrr_ yea that explains it, know the feeling here's an sql injection with AV local -.-
Manu tweet media
English
0
0
2
161
NXR🇮🇩
NXR🇮🇩@_nnxxrr_·
@rtfmkiesel hackerone analyst -> and accepted by elastic internal staff
English
1
0
2
668
Manu
Manu@rtfmkiesel·
Who @elastic rated #CVE-2026-0532? Were you drunk? > This requires an attacker to have authenticated access with privileges sufficient... Yet in the CVSS string privileges required == None This drops it from a 8.6 to a 6.8 if you consider "modify connectors" high privileges.
English
1
0
1
86
Manu
Manu@rtfmkiesel·
@IntCyberDigest Have you all drunk too much booze over the holiday? The patch/CVE came out ±5 days before the PoC. If your DB is publicly reachable and does not even have an IP filter (lol), you should have patched it by then. Fix your vuln feeds before blaming the PoC author.
English
0
0
3
203
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ Meet the guy almost everyone hates for releasing a PoC for a MongoDB unauthenticated memory leak exploit dubbed Mongobleed the day after Christmas. This is allegedly the vulnerability used to breach Ubisoft, which led to the R6 chaos.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
83
140
3.1K
514.5K