Malcolm Stagg
164 posts

Malcolm Stagg
@malcolmst
Ethical hacker @synackredteam. Working on software/electronics, AI and robotics projects @sodium_24. Former @DARPA challenge competitor. Opinions are my own.
Keller, TX Katılım Haziran 2009
248 Takip Edilen500 Takipçiler

@Jo3Ram AFAIK you’ll probably need to see someone with a badge for a hint, unless they added something online since then
English

@malcolmst Is the phrase obtainable online or do I need to go in-person?
English

@Microsoft @MicrosoftHelps Is there any way I can have correct formatting without being forced to change my privacy settings @Microsoft?
English

@Microsoft @MicrosoftHelps the only difference between these two screenshots is turning the privacy setting on or off. This shouldn’t cause the formatting to be completely different.


English

Apparently if you have the Office 365 privacy setting “Turn on all connected experiences” turned off, the Apsos font no longer renders correctly. It silently uses Apsos Display which is totally different spacing. Is this expected @Microsoft? Why force me to have this turned on?
English

I have a video demo showing exploitation against an enterprise extension
youtu.be/A07CNGXsJ4g?si…

YouTube
English

Appreciate @synack @README_Security publishing my writeup about CVE-2024-0333:
readme.synack.com/exploits-expla…
English
Malcolm Stagg retweetledi

(CVE-2024-0333)[1513379][Extensions][Updater ][crx_file]CRX3 File Signature Verification Bypass via Embedded ZIP64 Payload is now open with a PoCs.
issues.chromium.org/issues/41485950


xvonfers@xvonfers
[1513379][crx_file]CVE-2024-0333: Insufficient data validation in Extensions Error early for CRXs with ZIP markers in header. chromium-review.googlesource.com/c/chromium/src… @malcolmst
English

Interesting Google Chrome vulnerability I reported before Christmas was fixed today (CVE-2024-0333). I’ll post more details later after people have a chance to update.
chromereleases.googleblog.com/2024/01/stable…
English

@DARPA @defcon @AnthropicAI @Google @GoogleDeepMind @Microsoft @OpenAI @openssf Will the talk be recorded?
English

Attending @defcon this year? Check out our panel with #AIxCC program manager and collaborators @AnthropicAI, @Google, @GoogleDeepMind, @Microsoft, @OpenAI, & @openssf at 2:30 p.m. PT on Track 2! More about the competition at: aicyberchallenge.com #defcon31

English

The new @DARPA challenge from @perribus looks very exciting! Seriously considering coming out of DARPA challenge “retirement” to work on this one.
Perri Adams@perribus
I’m excited to announce the AI Cyber Challenge, a major, two-year @DARPA competition challenging the best and the brightest in cybersecurity and AI to secure the systems on which all American rely. aicyberchallenge.com
English
Malcolm Stagg retweetledi

As we prepare for the holidays, we’re counting down our most popular stories of 2022, starting with “How I hacked my way to the top of DARPA’s hardware bug bounty” by @malcolmst (with art by Si Weon Kim) from January: readme.security/how-i-hacked-m…
English

@Dinosn So now you can just use Notepad to brute-force passwords? That seems convenient 😀
English

Windows 11 now warns when typing your password in Notepad, websites bleepingcomputer.com/news/microsoft…
English

@phyr3wall @rustyrazorblade Thanks! Now I can finally get my computer back from vim.
English

vim tip I learned about 13 years ago from @rustyrazorblade . "Shift ZZ" will save the file and quit vim. I haven't touched ":wq" since 2009
English

Last day at #defcon30 … taking some “me” time to kick the tires on the IoT #CTF … #cybersecurity #hackersummercamp :)
English

@mcipekci @synack @SynackRedTeam @bamhm182 @0xteknogeek Congrats @mcipekci! It was great working on it with you!
English

Thank you @synack @SynackRedTeam for the opportunity to working with @malcolmst @bamhm182 and @0xteknogeek on the PLUOT project, it was really interesting project and thank you so much for the great memorial gift for it!

English



