Tal Lossos

31 posts

Tal Lossos

Tal Lossos

@TalLossos

Security Researcher

Katılım Haziran 2022
60 Takip Edilen142 Takipçiler
Tal Lossos
Tal Lossos@TalLossos·
@antoniozekic I doubt it as well. Reported a remote DoS a few months ago and got a reply that it isn't a "security implication"
English
0
0
1
158
A. Z.
A. Z.@antoniozekic·
I haven't noticed and other issue having system termination as impact in Apple's iOS 18 security advisory. Additionally, it appears that Apple is moving in the direction of classifying reported issues as Denial of Service when only Proof of Concept was provided, unlike previous descriptions that mentioned kernel code execution or kernel memory disclosure.
A. Z. tweet media
English
2
2
14
3K
Tal Lossos
Tal Lossos@TalLossos·
@Guluisacat Same here! Two marked as “addressed”, but one of them is still exploitable with the exact same PoC :)
English
0
0
0
49
Tal Lossos
Tal Lossos@TalLossos·
@karmaz95 And there is the case when they agree that the reported issue is a vulnerability, they fix it but don't grant a CVE 🙃
English
0
0
1
46
Tal Lossos
Tal Lossos@TalLossos·
@karmaz95 This happened to me as well. I reported a TCC bypass to Apple and they replied that it is an "expected behavior" for some reason...
English
1
0
1
43
Karol Mazurek
Karol Mazurek@karmaz95·
I published two reports I submitted to #Apple earlier this year that were closed as expected behavior, but I can't entirely agree with the decision. From now on, I will also upload PoCs to my YouTube channel (links inside): karol-mazurek.medium.com/apple-gatekeep… Feel free to subscribe & enjoy!
English
6
9
44
5.2K
Tal Lossos
Tal Lossos@TalLossos·
Quite a few people asked me if we’ve found more vulnerabilities in the NVMe Linux kernel driver. So, here is my answer! Check out the blog post of my colleague Alon on his journey of fuzzing the driver with some lovely findings!
Alon Zahavi@Alon_Z4

Be sure to check out my recent blog about my latest research “Your NVMe had Been Syz’ed”. In there I show how to add new subsystems to syzkaller, and how to use it to find new vulnerabilities. cyberark.com/resources/thre…

English
0
0
3
273
Tal Lossos retweetledi
Shak Reiner 🍍
Shak Reiner 🍍@ShakReiner·
Finally got around to publishing this post on a 𝙘𝙧𝙞𝙩𝙞𝙘𝙖𝙡 𝙫𝙪𝙡𝙣𝙚𝙧𝙖𝙗𝙞𝙡𝙞𝙩𝙮 𝙞𝙣 𝙖 #𝗖𝗼𝘀𝗺𝗼𝘀𝗦𝗗𝗞 𝙘𝙝𝙖𝙞𝙣! Dive in if you're interested in the security of the #IBC protocol and the Cosmos in general 🪐✨ cyberark.com/resources/thre…
English
0
13
15
1.7K
Tal Lossos retweetledi
LaurieWired
LaurieWired@lauriewired·
Did you know that NVMe over TCP exists? I sure didn't, but it's a super interesting attack vector. @TalLossos just put out an excellent blogpost of using CppCheck to find a null pointer deference in the Linux kernel’s NVMe driver. Check it out! cyberark.com/resources/thre…
English
0
9
56
5.5K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Containers have completely ruined the feeling of seeing `uid=0(root)` 😢
English
13
15
361
36.9K