Arbitrary code execution in objdump -g
We have a thing for finding bugs in bug finding tools. IDA Pro, Ghidra, Binja Sidekick, or radare2. You name it we hacked it. Our friends were saying we should try objdump. So here we go.
Blog post: blog.calif.io/p/oobdump-relo…
AI-generated PoC and writeup: github.com/califio/public…
🚨 Latest from today's Shai Hulud campaign -
The JFrog Security Research team has identified more malicious packages in this campaign which are being published with a hidden payload - hosted directly on GitHub instead of npm! 🧵
25 Followers 227 FollowingEnjoying topics like #appsec, #cryptography, #ctf, #crêpes and more.
Admitting to the occasional 'breaking-stuff-for-fun-and-profit' thing.
Stay #ZBAT.
5K Followers 9 Following@Openwall oss-security mailing list thread summaries, currently maintained by @solardiz. Originally setup and maintained as an automated feed by @eugeneteo.
908 Followers 1 FollowingBuilding AI that finds & fixes web security bugs — autonomously. SOTA in white-box bug hunting. Try Takumi: https://t.co/zruO7dgEcc
18K Followers 18 FollowingSecurity reviews and research that keep winners winning. We apply unmatched hacking talent to secure critical software for the most innovative teams.
2K Followers 7 FollowingZenith assembles auditors with proven track records to secure your project. We find the critical bugs now—freeing you to launch this week—not next month.
89K Followers 16 FollowingTrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
4K Followers 10 FollowingHacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
541K Followers 2K FollowingPolyagentmorous ClawFather. Came back from retirement to mess with AI and help a lobster take over the world.
@OpenClaw🦞 + @OpenAI
28K Followers 1 FollowingOffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.