Rezk0n

408 posts

Rezk0n

Rezk0n

@Rezk0n

Bug trafficking, *OSX and Android research. (I want to do all the things but time..)

Katılım Mayıs 2014
1.3K Takip Edilen231 Takipçiler
Rezk0n retweetledi
Lau
Lau@notselwyn·
Hi everybody! I did a talk today about pagetable exploitation techniques on x64 Linux. I uploaded the slides to Github I loved meeting everybody :) github.com/Notselwyn/blog…
English
1
26
86
6.2K
Adam Chester 🏴‍☠️
I'm sorry @AnthropicAI, did you just try and tell me to enable data sharing (which I disabled) and then told me that you can keep my data for 5 years??!
Adam Chester 🏴‍☠️ tweet media
English
10
5
66
7.9K
Rezk0n retweetledi
attackify
attackify@attackify·
NPM package NX compromised! The nx package versions 20.11.0 and 21.7.0 appears to be compromised with code published that would attempt malicious actions including modifying the installers .bashrc/.zshrc. github.com/nrwl/nx/issues…
English
3
4
8
1.3K
Luke Parker
Luke Parker@LukeParkerDev·
just found what looks like a massive virus. thousands of github repos called 's1ngularity-repository' created in the last couple hours. containing public data of your github private tokens and a clear attempt at trying to get access to all private/financial data on the system
Luke Parker tweet media
English
6
7
33
6.8K
Rezk0n retweetledi
chompie
chompie@chompie1337·
This is what I mean when I say working with MSRC is degrading. They want everything: write up, stack traces, PoC, exploit source, analysis, life advice, approval on anything you will ever publish. In return they will patch your bug whenever they feel like it and not tell you
TrendAI Zero Day Initiative@thezdi

Uncoordinated Vulnerability Disclosure: After more than a decade of CVD, has it benefited vendors or researchers more? Have the number of bugs increased to where vendors simply cannot cope with CVD? @dustin_childs has some thoughts - & lots of questions. zerodayinitiative.com/blog/2024/7/15…

English
18
71
445
95.9K
Rezk0n retweetledi
attackify
attackify@attackify·
🚀 Bridging MITRE ATT&CK with ATTACKIFY for Advanced Threat Actor Emulation! Exciting news! We've just released a new CLI tool in beta to compliment ATTACKIFY that will help you instantly run emulations based on any @MITREattack Threat Actor Group Profiles. 🎯 Map ATT&CK TTPs to ATTACKIFY Modules 🛡️ Automate Threat Actor Emulations 🔗 Run Custom APT Campaigns Instantly 🔐 Improve Security Controls as data is published! Learn more from our blog: attackify.com/blog/bridging_… #Cybersecurity #ThreatEmulation #ThreatIntel
GIF
English
0
2
13
695
Rezk0n retweetledi
attackify
attackify@attackify·
🚀 New Module Alert! 🚀 We're excited to introduce our latest ATTACKIFY module targeting CVE-2024-26229, a vulnerability in the Windows CSC Service. 🔍 Key Features: - Test & Validate Security Controls: Focus on local privilege escalation detection & prevention. - Real-World Simulation: Attempts to safely exploit the vulnerability & runs whoami.exe to verify SYSTEM privileges. Enhance your security posture with ATTACKIFY today! Test your security controls against many of our privilege escalation modules and more💪 attackify.com #CyberSecurity
attackify tweet media
English
0
3
8
318
Rezk0n retweetledi
attackify
attackify@attackify·
🚨 Attention Australian Businesses and Educational Institutes! 🚨 We're offering FREE Professional ATTACKIFY accounts for the rest of 2024 if you register for a FREE account in June. We want to help protect against the current surge in cyber attacks seen in Australia lately. Don't miss out on this opportunity to improve your overall security posture now! - Audit Endpoints - Test, Validate & Improve Security Controls - Perform Security Maturity Assessments - Perform External Asset Discover and Vulnerability Scanning attackify.com (Must be a registered business within Australia) #CyberSecurity #Australia #ATTACKIFY #JuneFreeOffer
English
0
2
3
143
Jiska
Jiska@naehrdine·
@CodeColorist The lectures are in-person, so if you're located near Berlin, feel free to join :) Anyone can register. It's a bit of paperwork, but I can help you with that. Details are here: uni-potsdam.de/en/studium/wha…
English
1
0
1
302
Jiska
Jiska@naehrdine·
Join us for an exciting guest lecture! @i41nbeer will present his talk "r00t cause analysis: the process of analyzing in-the-wild zero day iOS exploits" 📱💥 📅 Friday, April 19, 14:30 📍 Potsdam, @HPI_DE, HS3
English
2
5
51
4.3K
Rezk0n retweetledi
Theori
Theori@theori_io·
Do you use a virtual machine to browse dangerous links safely? If you use the Chrome browser inside that virtual machine, is it secure enough? As you might have guessed, the answer is not so much. We chained six unique CVEs from 2023 listed below. • Chrome Renderer RCE : CVE-2023-3079 • Chrome Sandbox Escape : CVE-2023-21674 • LPE in guest OS : CVE-2023-29360 • VMware Info Leak : CVE-2023-34044 • VMware Escape : CVE-2023-20869 • LPE in host OS : CVE-2023-36802
English
22
260
927
139.5K
Rezk0n retweetledi
Pwnie Awards
Pwnie Awards@PwnieAwards·
How the hell are we gonna send the epic fail Pwnie to China
English
4
10
72
12.3K
United Energy
United Energy@UnitedEnergyAU·
POWER OUTAGE UPDATE (1/4) #UnitedEnergy is responding to 600 faults & working to restore power to 120,000 customers after severe winds & lightning strikes caused significant damage to poles, wires & electrical infrastructure across the south-east suburbs & Mornington Peninsula.
English
3
1
7
3.1K
Rezk0n retweetledi
Joseph Ravichandran
Joseph Ravichandran@0xjprx·
The world's first(?) kernel exploit for Vision Pro- on launch day!
Joseph Ravichandran tweet mediaJoseph Ravichandran tweet media
English
81
765
6.6K
1.8M
Rezk0n
Rezk0n@Rezk0n·
@TinySecEx This looks sick, will this be public or nah?
English
0
0
0
234
TinySec
TinySec@TinySecEx·
Although it is only an early version, but it already helps me alot.😂
TinySec tweet media
English
7
0
18
4.7K
Rezk0n retweetledi
attackify
attackify@attackify·
🚀 Exciting New Module in #ATTACKIFY  - OceanLotus 🚀 A new module inspired by the awesome research from @coolestcatiknow & @PwnieFan and the @MITREengenuity team on OceanLotus APT emulation! 🛡️ Dive deep into advanced threat simulations & hone your defenses by experiencing first hand tactics of OceanLotus. Use ATTACKIFY to quickly emulate key OceanLotus TTPs around the OSX.OceanLotus backdoor and malicious activity! attackify.com #adversaryemulation #APT #infosecurity #purpleteam
GIF
English
0
5
11
600
Yassine Aboukir 🐐
Yassine Aboukir 🐐@Yassineaboukir·
@stokfredrik much love brotha and may the wind always blow in your favor whatever you do next 🤟🏽
English
1
0
18
3.4K
Rezk0n retweetledi
attackify
attackify@attackify·
🔐 Introducing the Bootloader.io Scanner Module for ATTACKIFY! Following the success of our LOLDrivers Scanner Module, we're excited to unveil the Bootloader.io Scanner. Dive deep into detecting malicious bootloaders using data from the awesome project hosted at bootloaders.io For an in-depth look & bonus scripts for manual scans and tinkering, check our blog: 📖 attackify.com/blog/loldriver… 🚀 ATTACKIFY: Simulate Malware, Emulate Adversaries, Conduct Security Scans & more - all for FREE! Join us today: 🔗 attackify.com #purpleteam #Bootloaders #infosec #BlueTeam #redteam #CyberSecurity #Bootloaders #LOLDrivers
attackify tweet media
English
1
15
29
4.6K
Rezk0n retweetledi
attackify
attackify@attackify·
🔐 New Module: LOLDrivers Scan! While ATTACKIFY excels in automated adversary simulations, we're also about enhancing endpoint security. Our newest module leverages the awesome work from the #LOLDrivers project, allowing seamless malicious and vulnerable drivers scans on your endpoints. 🚀 Explore ATTACKIFY - Emulate Adversary Behavior, Simulate Malware, Run Various Security Scans, and more in just a few clicks - all for FREE! Sign up at: 🔗 attackify.com #purpleteam #LOLDrivers #infosec #BlueTeam #redteam #CyberSecurity
attackify tweet media
English
1
7
21
3.1K