Avatar
CrowdCyber
36f403b6512d7e69bb7b89442ce43ffa63cdf6ead2641d7935b239e2ec3557ad
Revolutionizing and Democratizing Cybersecurity

One of the world's largest crypto payment processors CoinsPaid loses $37M in hack https://x.com/bitcoinnewscom/status/1690809194146897920

SandBlaster: Reversing the Apple sandbox from Cellubrite Labs https://github.com/cellebrite-labs/sandblaster

CoFuzz: Coordinated hybrid fuzzing framework with advanced coordination mode https://github.com/Tricker-z/CoFuzz

VS Code’s Token Security: Keeping Your Secrets… Not So Secretly https://cycode.com/blog/exposing-vscode-secrets/

Chimera - Automated DLL Sideloading Tool With EDR Evasion Capabilities https://www.kitploit.com/2023/08/chimera-automated-dll-sideloading-tool.html?m=1

Maker of Chrome extension with 300,000+ users tells of constant pressure to sell out https://www.theregister.com/2023/08/11/chrome_extension_developer_pressure/

TunnelCrack is a combination of two widespread security vulnerabilities in VPNs https://tunnelcrack.mathyvanhoef.com/

DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced https://github.com/ShorSec/DavRelayUp

Abusing nvidia driver (nvoclock.sys) for physical/virtual memory and control register manipulation. https://github.com/zer0condition/NVDrv

General Device Manager 2.5.2.2 - Buffer Overflow (SEH) Exploit https://0day.today/exploit/description/38921

Censorship Industrial Complex: Using GPT-4 for content moderation https://openai.com/blog/using-gpt-4-for-content-moderation

Offensive Tool Development - The Shellcode Compiler Was Right There All Along... (Part 1) https://sh3llsp4wn.github.io/Shellcode-With-The-Default-Linux-Toolchain/

Ford SYNC 3 infotainment vulnerable to drive-by Wi-Fi hijacking https://www.theregister.com/2023/08/14/ford_sync_vulnerability/