Ricerca Security

38 posts

Ricerca Security banner
Ricerca Security

Ricerca Security

@RicercaSec

Offensive Security Professionals | VAPT, R&D, Consulting, Training | Recognized by government agencies, Fortune 500s | Japanese: @RicercaSec_JP

Japan 加入时间 Mart 2020
0 关注2.8K 粉丝
Ricerca Security
Ricerca Security@RicercaSec·
We are thrilled to announce that our researcher Akira Moroo (@retrage) and CEO Ren Kimura (@RKX1209) will be speaking at HITCON CMT 2024 in Taiwan! Title: Lessons Learned from a 4-Year Journey on Developing a Generic Fuzzing Framework hitcon.org/2024/CMT/agend…
English
0
6
14
4.3K
Ricerca Security
Ricerca Security@RicercaSec·
In the final part of our Fuzzing Farm series, we provide technical analysis and a PoC for CVE-2022-24834, an RCE vulnerability in Redis we found. While we reported it in 2022, the bug detail was disclosed last week. If you use Redis, patch it immediately. ricercasecurity.blogspot.com/2023/07/fuzzin…
English
0
51
179
21.7K
Ricerca Security
Ricerca Security@RicercaSec·
This is part 3 of our Fuzzing Farm series. Our team is also working on 1-day and 0-day exploits. In this article, we explain the process of developing a Proof of Concept (PoC) for undisclosed bugs, using a CVE of Google Chrome as an example. ricercasecurity.blogspot.com/2023/07/fuzzin…
English
0
48
184
19K
Ricerca Security
Ricerca Security@RicercaSec·
This is part 2 of our Fuzzing Farm series. Our team is not only working to develop and utilize fuzzers, but also to evaluate and improve them. In this article, we discuss some pitfalls and insights when evaluating fuzzers. ricercasecurity.blogspot.com/2023/07/fuzzin…
English
0
17
34
8.1K
Ricerca Security
Ricerca Security@RicercaSec·
Our Fuzzing Farm team is developing and utilizing fuzzers. We will be sharing their work over the next 4 blog posts, starting this week. The first post covers how to find bugs and identify their root cause through fuzzing. ricercasecurity.blogspot.com/2023/07/fuzzin…
English
0
16
59
7.3K
Ricerca Security
Ricerca Security@RicercaSec·
We will be publishing an English version of the technical series "Fuzzing Farm," which was well-received in Japanese. The series will be released from this week to next week. The final day will feature a technical article explaining the exploitation of CVE-2022-24834. Stay tuned!
English
0
5
18
4.1K
Ricerca Security
Ricerca Security@RicercaSec·
We have reported an RCE vulnerability in Redis, which is assigned as CVE-2022-24834. The patch was released yesterday and we recommend applying it promptly. We will be publishing the writeup and PoC next week. Stay tuned! redis.com/blog/security-…
English
1
22
72
10.5K
Ricerca Security
Ricerca Security@RicercaSec·
The qualifying round for DEF CON CTF, the world's largest hacking competition, took place last month. For the second year in a row, the team with our company staffs qualified for the finals, placing 11th out of 535 teams worldwide (1st in Japan).
Ricerca Security tweet media
English
0
0
22
3.2K
Ricerca Security
Ricerca Security@RicercaSec·
🏁Ricerca CTF 2023 has just ended🏁 #RicercaCTF 2023 is over! Thank you for your playing
Ricerca Security tweet media
English
0
0
5
6K
Ricerca Security
Ricerca Security@RicercaSec·
🚩Ricerca CTF 2023 registration is open🚩 We’ve just opened the registration for #RicercaCTF 2023 which starts tomorrow, Apr 22 (Sat) 01:00 UTC. Visit 2023.ctf.ricsec.co.jp to play the CTF. Challenges with a wide range of difficulty from rev, pwn, crypto, web, etc.
English
1
12
25
15.7K
Ricerca Security
Ricerca Security@RicercaSec·
🚩Ricerca CTF 2023 website is now available🚩 The website of #RicercaCTF is now open. We are also proud to announce the authors. The event will take place next weekend: Sat, April 22, 2023. Registration will be open soon. Visit 2023.ctf.ricsec.co.jp for more information.
English
1
1
4
1.8K
Ricerca Security
Ricerca Security@RicercaSec·
🦾 Our cybersecurity training is released 🦾 Participants can learn vulnerability analysis and exploit techniques, targeting everything from simple programs to kernel drivers. Customized training is also available. Visit ricsec.co.jp/en/news/traini… for more information.
English
0
0
7
2.2K
Ricerca Security
Ricerca Security@RicercaSec·
Our paper "RCABench: Open Benchmarking Platform for Root Cause Analysis" has been accepted at the NDSS BAR 2023 workshop!
Ricerca Security tweet media
English
3
18
61
45.6K
Ricerca Security
Ricerca Security@RicercaSec·
#RicercaCTF 2023 will be held on Saturday, April 22, 2023. The event will last 12 hours from 10:00 to 22:00 JST. We will announce details in April on CTFtime and Ricerca Security's official Twitter account. ricsec.co.jp/news/ricercact…
English
0
0
4
1.6K
Ricerca Security
Ricerca Security@RicercaSec·
The denial-of-service (DoS) vulnerability in tdpServer of TP-Link RE300 V1 (CVE-2022-41783) that was reported by our security engineer has been disclosed. Please visit jvn.jp/en/jp/JVN29657… for more information.
English
0
1
2
0