Anonymous GitHub account mass-dropping undisclosed 0-days
github.com
github.com
The first requires being able to overwrite binaries in the Swift tool directory. Yes, if you overwrite binaries executed by ghidra, you can trigger code execution. This is not a surprise.
The second, idk, I'm not familiar with TraceRMI (but it's probably worth noting that "RMI" stands for Remote Method Invocation).
The third is not a vulnerability in the slightest, they just demonstrate that native 7zip parsing code is reachable. Maybe there is a bug in the 7zip parser, but without that it's meaningless.
Maybe I'm projecting my own biases ;-)
I do wonder though: if you can tell the AI to search for vulns, can't you also tell it to contact the right maintainer for each one found?
So, knowing that bad actors have an unending river of cheaply acquired zero days, the best response is to publish them so that maintainers also have access to them. Existing methods of slow disclosure cannot keep up with the AI firehose.
It’s ugly, but it will force needed change. A thorough AI red team effort is the lowest bar of releasing software responsibly in this day and age.
All this is doing is making the AI firehose worse.
I’m onboard with this being suboptimal. But as someone who has filed >10 significant disclosures in the last month resulting from reviewing my codebase and had exactly zero responses, I can relate to the decision.
> but it's probably worth noting that "RMI" stands for Remote Method Invocation
This reminds me of someone submitting a (clearly vibecoded) vulnerability report claiming to have found a way to execute arbitrary SQL. The project in question? An SQL server... https://github.com/tursodatabase/turso/pull/4322
After a bit of research, the Firefox one seems plausible to me. But, I haven't actually tried the POC. The explanation about the private-data and untrusted-input flags is plausible but I'm not an expert on Firefox's internals, maybe that's not actually how it works.
This just sucks, all around. Are we going to need every open source project gawking at the same repo full of stuff that has nothing to do with them, on the off chance that someone discloses a vuln that does have to do with them? Is this some kind of performative complaint about high friction in responsible disclosure? Well great job dickhead, you've just made a system that's even worse. Nobody benefits from this. Yuck yuck yuck.
Disclosures always enable more secure software to theoretically exist,
even if nobody follows through creating it.
They often do.
The biggest mitigation is that gitea documentation discourages you from using action runners from untrusted users. Not flawless security, but it's something...
This recommendation seems incompatible with third-party collaboration, at least on its face!
Does it? Or does it need to be in the same directory you invoked ghidra?
There'd be a certain irony being able to reverse shell anyone doing an nmap scan. If i had infinite tokens i'd throw claude on writing an exploit and dig through the history who made it possible because - if we take a moment to wildly speculate and assume it can ACE - this is the kind of bug an intelligence agency would love to have: Add a few ipv6 packets that then edit the trace being observed if the observer uses nmap / get access to any researcher pc who uses nmap.
Media codecs pretty much, single-handedly even, drove about a new era of defenses and mitigations in Android: https://blog.isosceles.com/the-legacy-of-stagefright / https://archive.vn/x3d0Y
"Why don't we unpack malware in the kernel" - "And so the search for intelligent life continues..."
Every TV / movie hacker has known about this.
code execution js code execution, if reached through some bug or executing code that was not intended to be executed its bad, even if the mechanism is kind of obvious and trivial, it still can lead to unexpected code to be launched.
the repo also notes low quality of some POC like ones you noted.
its correct to be a bit wary and i wouldnt call it some crazy 0day dropping account or anything, but bugs/vulns are bugs an vulns and simply because you are not impressed by their complexity, it does not reduce them entirely. just makes em lil less scary.
the ghidra one, it reminds of things like unquoted service paths in windows services. its a silly thing and clearly its bad but it still happens and gets companies pwned :'). a lot of companies use ghidra actively and if you imagine what kind, you'd hope they will not allow the overwriting of those swift binaries ;p. some pentester bound to have a laugh.
Ah, MS07-052[1] ("code execution leads to code execution") strikes again. These sorts of "if you allow arbitrary code to be executed, code will be executed" "vulnerability" reports seem evergreen
[1]: https://devblogs.microsoft.com/oldnewthing/20070807-00/?p=25...
By mass sharing these kinds of gaps and utilising mythos tier LLM's ability to find and combine multiple disparate bits of information together, are we increasing it's capabilities and versatility?
The nghttp2 nghttpx one is more interesting, and could potentially be used for phishing, but it's very hard to line up properly because the request queue is non-deterministic so basically impossible to target a specific victim (assuming proxy traffic).
The VLC one is just a straight-up crash/bug. And VLC crashes all the time when using weird codecs, so that's nothing new.
Am I missing something here?
...when was the last documented case of an in-the-wild hack targeting VNC?
Everyone goes to the extremes when it comes to these theories and throws out all aspects of pragmatism.
What are you doing on your computer where it is really a threat to you? I'm curious as to your specific use case :)
If not, why not?
Video is a great vector for distributing malware, especially sought-after grey area content like porn, conflict videos, celebrity leaks, pirated films, etc. Not enough people pay attention to the impact of video as a vector for compromise. All downloaded video should be sandboxed!
I don’t know if there is data on exploits due to downloaded media but it would be an easy way to exploit specific target populations (find a video of interest to them and “leak” it somewhere).
So maybe tweaking your usage (ex. no spaces around them) or using a technically incorrect en-dash might offer the desired effect while subtly signaling that your message isn't AI-generated.
I still use them — mostly for pauses — but I'd like to think my voice sounds distinct enough from an AI that people can tell.
However I've only ever used regular dashes. How do you type an em-dash? Is it OS specific? I've taken to using Emacs insert-char with a list of frequently used ones in my scratch buffer. My memory for Unicode is unreliable.
On iOS you type it by pressing dash and holding until alternative options come up, same way you type e.g. accented characters.
On Linux X11 at least, you can enable the Compose key and then press `<Compose>---` which results in — and `<Compose>--.` which gives you –
Which is super useful for hard space - non line-breaking space - so that one letter words don't appear at the end of lines.
Also just learned about compose key apparently, and I noticed that I can program this split keyboard I'm using to turn that into a chord, anywhere!
Then an LLM told me that I can 3D print my own custom keyboard with 32 programmable layers. Everything is an infinite rabbit hole these days, how wild.
(disclaimer: I feel like this obsession with dashes is special to native English speakers, which I'm obviously not)
edit: another comment gave a mac shortcut – — - <--- one of these might be it
Just --- only works when you have the text replacement thing on (the same thing that turns (C) into ©).
The en dash is also used in things like scores (3–2 Turkey), votes (the bill passed 58–42), or connecting words where the second part is longer than one word (the Australia–New Zealand alliance.) You can remember the latter as, "a hyphen isn't big and strong enough to hold on to more than one word.
If you're on a mac, pressing Option+- is the en dash and Option+Shift+- is the em dash.
So em dashes are for pauses or highlighting things I guess? The en dash you explained in your reaction. Is there any other use for the hyphen except for making lists?
Option-shift-hyphen types an em-dash, option-hyphen an en-dash. You can also hold the hyphen key (on a Mac or iPhone) and it will allow you to select either. Em dashes are used—like—this—as something spiritually akin to a parenthetical. En-dashes are used within ranges: Feb 14–17.
It's an attention to detail thing that you'd definitely want to get right in a physical textbook or the like.
I'll go a step further: I think I'd rather actively filter out people whose AI detection is that naïve.
Internet slang like "lol" came from trying to text on those shitty number pads on old cellphones. I expect similar slang will come about in the future from humans trying to prove they're not a dirty clanker. Sacrificing the em-dash is just the beginning of this. Soon, we're all going to be typing without rhythm.
Just so academia can claim some level of detectability
Why go the extra way to have a slightly elongated dash when a normal one would just as well do the job?
I might be conpletely off here but I've never seen a situation where using a normal dash where a long one should be causes any sort of syntactic trouble.
https://www.merriam-webster.com/grammar/em-dash-en-dash-how-...
Just because you don't care to use the proper dash doesn't mean everyone else doesn't. People have different levels of caring about different details. For the sticklers, there's even a special code point for ellipsis, … rather than .... (Four being correct, as one is to end the sentence.) Personally I'll just skip — entirely unless I'm in a trolling mood, though “sometimes” the right quotes are worth using. Special characters are easy to type on a phone soft keyboard, taking a long press on the relevant key, or if you're using any other advanced input system, so they shouldn't really be considered to be the mark of LLM input.
The real trouble is that people doing engage with the substance of the post anymore, and just shallowly dismiss a post as being vibe written, as if that makes any points raised invalid. Anti-intellectualism's always been cool among a certain crowd. Shame to see it spread but ah well, the propaganda's working.
But people at work who are copying responses from LLMs into emails to others also suck, and I want to distance myself from them as much as possible. I'm kinda hoping we will eventually have a wave of "what the fuck are we paying you for if you're just copying stuff from an LLM to Slack" firings.
Just focus on not producing slop.
I think that there could be even more then a fingerprint in those messages.
It’s this video: https://youtu.be/5CKuiuc5cJM?is=9VQ1FCxY_X3eNm-b
Warning: They anthropomorphize a lot in this video, but I get it… the words exist, why not use them.
Basically we optimize the models to produce output with certain characteristics but that doesn't mean that what we see is the whole truth or even that the relationships in the underlying system are structured in the way that we might expect.
Sure, that’s why there have never been any authors that became famous despite being poor and deliberately writing with that affect.
Good writing style does connote good education, and in environments where being upper-class bolsters social standing, some people flaunt it to signify class, as they would with any other wealth signifier, like expansive shoes.
I am a union tradesman— the third generation to work in manufacturing in this area. Affecting an upper-class identity diminishes social standing in my environment. Having a lot of money, definitely doesn’t. My dirty work boots probably cost as much as many of the trendiest shoes on the market, and the guys at work know that and admire them… but my wearing them doesn’t signify class. Similarly, you can use good writing style in a way that shows you went to a good school and paid attention without wearing it like a Harvard Business School fleece.
Sometimes you’re trying to communicate education or class. Often that’s not the main goal.
Similar story for Chaucer, and so many others. I don't think good writing, things we appreciate so much it lasts generations, has much to do with signalling education or class.
So all your writings are private, then?
Do you have a motivation to communicate or publish? You're posting here on HN, so I think so.
Why do you do think you do it?
https://en.wikipedia.org/wiki/Soft_hyphen
It's a perverted expression of hidden passive aggression.
And if it ever catches on with LLMs ⸻⸻ we just make it longer
I had to look up why this exists, and apparently it was added in Unicode 6.1 (2012) because some style guide required it, and using consecutive U+2014 em dashes isn't sufficient because that might not render as one continuous line.
Google docs will convert “—-“ to an emdash but simple text inputs wont.
So when you see one in that context you have to consider the explanation. They copy pasted an em dash specifically, they drafted in Google docs, they know the unicode keyboard shortcut, etc. None of these are safe assumptions. And if it’s markdown you know it wasnt drafted in Google docs.
> A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
Which is roughly the definition of zero day. Whether the contents of the repo reflect the above claim is something else entirely.
Reminds me of Jamie Wolf's joke about bestiality laws. Who are those for? What stops most people from bestiality is… not wanting to have sex with animals! For people who do want to, what, they won't because of… the law??
Who will this comment stop??
“””here are the best estimates of how many animals are killed every day on a per-species basis.
Chickens: 206 million/day
Farmed Fish: Between 211 million and 339 million
Wild Fish: Between 3 billion and 6 billion
Ducks: 9 million
Pigs: 4 million
Geese: 2 million
Sheep: 1.7 million
Rabbits: 1.5 million
Turkeys: 1.4 million
Goats: 1.4 million
Cows: 846,000
Pigeons & other birds: 134,000
Buffalo: 77,000
Horses: 13,000
Other animals: 13,000
In total, this means that every 24 hours, between 3.4 and 6.5 billion animals are killed for food”””
- https://sentientmedia.org/how-many-animals-are-killed-for-fo...
Others consider law a way of encoding the group’s existing rules and norms.
In that view, making something illegal or mandatory is not a prerequisite for punishment: it’s the actual main point.
The threat of punishment is meant for those not deterred from an act by the simple fact it is illegal (and the threat only works if enforced).
Others put it the other way around, and see law as social engineering, a way to shape the group, either through the encoding itself of the desired behaviours in law, or through deterrence. Or both. If what one is after is either power or legitimacy, they need compliance more than punishment (can’t rule once you’ve chopped everyone’s heads off, or once the mob has put yours on a spike).
It’s also sometimes used as coordination (which side of the road we drive on).
And there’s also law as dispute resolution (if your neighbour’s hen lays an egg in your garden, who does it belong to? Yes, it’s ridiculous. Yes, some places have one or more laws for that). Which, incidentally, both requires and provides legitimacy. Funny, that.
And probably many other kinds / points of view, with many different purposes, intents, and mechanisms.
Anyway, all that to say law is vast, fascinating, and utterly tedious. And apologies for the tangent.
You're thinking of criminal law. And it's not just some group's rules and norms - there already exists familial or social group punishment for that. Criminal law is prosecuted by the State. It's the code of conduct of the society you exist in.
If you want a thought experiment for what life would be like without organised society, read Leviathan
Hence why we accept State governance and law (to a greater or lesser extent, obviously people protest specific laws and injustices and what's on the statute books changes on a regular basis), because the alternative to law is "nature", aka bigger-army diplomacy. Anarchy doesn't free people, it only gives freedom to those with existing power to disempower others. Those with superior power will simply rob, rape, kill or enslave everyone else.
States exist to secure their territory from those sort of external threats, and incubate an economy inside their borders, which aspires to bring wealth and happiness. The criminal law is put in place by those with the monopoly on legitimate violence, often encoding the views of the population, to keep their society running.
What I meant is more about why and how laws come to be, which depends on what we think they’re for. Hobbes’ point of view is one. Locke and Rousseau had different opinions.
For example, one can view criminal law as a punishing tool, like gp, whose only purpose is to punish the act once discovered. You criminalise duels to punish duelists because murder is bad and no murder or attempted murder should go unpunished, and associate a great punishment because murder is a very bad thing.
But you can also criminalize duels to prevent or reduce the incidence of duels, and associate a great punishment to it to deter your stupid hot-heated young nobles from going around each other. Still criminal law, but this time both as social engineering and deterrence.
It’s been a long time since I read Hobbes. Should definitely go back to it.
The point of beastiality laws are to give society some recourse to punish people who abuse animals.
There was a very famous case back in Washington state back in the early 2000s where a group of men were sexually abusing horses. It was uncovered because one of them died, and the other could only be charged with trespassing because it wasn't illegal at the time to sexually abuse animals.
What an odd thing to say about the sexual abuse of an animal.
I don’t think the semantics are very important here, I think it was clear I'm talking about sexual abuse specifically without this odd clarification.
What I said, verbatim, about that case.
What part of that is incorrect or warrants clarification, exactly?
I appreciate your definition of abuse here but it's confusing in a discussion about legality.
No, it wasn't. The laws are quite explicit about what "abuse" means, and if you take a gander at most laws (including Washington state's circa 2000 or so) in the context of animals it usually explicitly refers to physical harm (for example, mutilation) or improper living conditions. Charging them under Washington's existing abuse laws would've required the animal to be physically injured, which it wasn't. It's quite literally why they had to pass a new law.
I don't know why I have to explain this, but:
1) Sexual abuse can occur without physical harm or injury.
2) Beastiality is sexual abuse.
Edit: Removed video link because the second half was gross and unrelated. May try finding another clip, but the first half was of Cenk Uygur from The Young Turks about a decade ago saying he'd legalize cases where the person pleasured the animal.
You didn't imply until now that I was wrong about animal abuse already being illegal. In that case, a bestiality law doesn't fix the actual problem, right? It's a band-aid partial fix.
1) Beastiality isn't sexual abuse
2) Beastiality laws are pointless because it was already illegal under existing abuse laws (it wasn't, as we've repeatedly discussed)
3) Sexual abuse requires physical harm
all of which are pretty gross (1,3) and/or pointless (2). I don't really feel the need to argue any of this any further, so I'll leave you to it.
And that's not a pointless argument. If we're still allowing the whole category of non-physical abuse to animals, except for bestiality, that's a terrible job of lawmaking.
And just on a tangent here now that I'm reading the law they added, does it really make sense to have a blanket exemption for "accepted animal husbandry practices"? Some of those procedures are just as exploitative and unnecessary. It makes me think this law isn't putting animal welfare first.
For some reason with people it goes the other way around.
Regarding the comment, it isn't going to stop anyone. Most people will not do cybercrime because they're honest. Of the remaining, the risk of being sentenced to jail time will instead stop some people, even if not all of them.
I guess “bad” is excessive. I regularly observe traffic laws with less rigor the your average police officer would prefer.
To a first order, laws basically just codify how the government (the overwhelmingly dominant applicator of violence in any given society these days) will apply violence so that the peasants can reason about it in advance and avoid it.
You don't need any of that for the basic "if I do violence upon others without a damn good reason violence will be done upon me" workflow though.
Sure the worst atrocities are known to be bad from Religion (10 commandments, which is a law in itself) but many aren't. Speeding, drunk driving, harassment aren't concept that are obviously wrong (as in obvious to people with no guardrails).
So laws aren't useless. The fact that most people respect them actually means they have a purpose.
The people who want to see the people doing bestiality punished
The main issues are that it's potentially really harmful towards the animals, depending on act, and a vector for zoonotic disease transfer.
If you're going to do it, do it right, and accept that you're probably going to end up with some system transfer you didn't necessarily anticipate.
I very briefly considered doing something like this: if I just post the results on the internet, people can crowdsource filing issues and working on fixes. It's certainly not the nicest way of doing this, but on balance I'd like these issues to be fixed eventually.
I ended up not doing that and am instead filing a couple issues a day because it's not that much of a burden. This was an experiment that was much more successful than I expected, so I didn't budget to spend this time, but it's also not a huge deal to slowly do it.
I’ve seen so many claims of people who used LLMs to generate hundreds of issues that turned out to be full of hallucinations or non-bugs being described as bugs that any claim like this needs some real evidence. Saying you found 500 safety bugs in Rust but that you’re casually only filing a couple of them makes this hard to believe.
It's easy to find the 37 issues they have already filed: https://github.com/search?q=soundness+gemini++author%3AManis...
Of course don't just spam untested PRs as that will land you in PR jail very quickly.
These AI models are making *everything* sound like an exploit. Not sure if this is good for the ecosystem. It makes me question everything that comes in more carefully. Is this a real exploit, or someone farming for karma to claim "I opened 39 CWEs in the last week. Hire my 'security' company to audit your code."
Seems like we're already in the middle of this phase, but rather than dying down, the 'reports' have just gotten more noisy and obtuse, making it more difficult to establish the actual degree of threat / attack vector.
As a bonus if you find any actual zero-days in your mass-generated ones you don't report it and get a new one to play with.
Assuming, of course, said state agency is operating under sufficiently strategic governance and management…
I really think this characterization is misleading. It's not "getting smart", only more tailored toward a specific usage, better curated dataset, better harness, better prompts, better labeling of results, documentation of failures and success, etc.
The outcome is (hopefully) overall better but this anthropomorphized wording makes it sound like AI itself is somehow changing or evolving. No, both academia doing fundamental research, industry making it available commercially, and finally security researchers making the entire tooling and process packaged as a service are actively shaping it to make it better. There is no "it".
Or are you just defining "fast" as something only horses can do, and considering that a useful insight about cars?
edit: downvotes but no rebuttals. feel free to show me where the agency, reasoning from first principles, world model etc exists. or you can ask an llm and they'll tell you they don't have those.
There's nothing intelligent about a math processor, even if it's automated.
Do you consider the protagonist of "Memento" to lack intelligence, then?
> Children at school are capable of "discovering" math solutions/methods that are known to others but hasn't been taught to them.
LLMs have already done that one: A chatbot’s result for the 80-year-old “unit distance” conjecture is the first AI proof that would likely be published in math’s top journal if humans had done it alone
https://www.scientificamerican.com/article/ai-just-solved-an...
> Creativity in new areas without training.
To my knowledge, not something that has ever been done by humans, but again, it depends entirely on how you actually define the goal posts.
> There's nothing intelligent about a math processor, even if it's automated.
There's nothing intelligent about a bag of cells, but here we are.
Every software update introduces and reintroduces them
These people whinging about slop don't realize everything that doesn't come from a credible source gets ignored.
Credible people are using AI and once these issues are fixed, it will die down.
The threat of AI zero days will persist though, but they will be much more expensive and subtle to find.
> In regard to AI usage, my fuzzing workflow was automated by AI with a strict harness. I used GPT-5.5-3-Codex-Spark for ALL the fuzzing, as barely any "thought" is necessary when provided with an efficient harness. Contrary to the growing narrative that I'm just some random child burning tokens, I DO actually have a degree in the subject and have published multiple papers on fuzzing methodology. I spent years researching and developing new tools and ideas for how to fuzz. You do NOT need a SOTA model to help you identify these issues, I promise!
It’s possible/likely that whomever is running this experiment is keeping the non slop bugs to themselves. It’s probably what I’d do.
Yes, maliciously used features should sometimes drive change (eg. in how to reduce or reduce impact of social engineering attacks), but as a claim it has no value.
Also, I've known some thoroughly unimpressive people who have affiliated themselves with DARPA. I wouldn't use it as an appeal to authority.
For example, if you allow weak passwords, then you have a trivial vulnerability to people guessing other people's passwords. But nothing about the login system is working differently from how anyone intended. It's just that the intentions themselves were naïve.
Like yes there is a heap OOB issue in an incredibly old file format, but without already having arguably compromised access to a machine, exploiting it for RCE seems impossible?
I'm happy to be shown what I'm missing but this seems like a memory corruption bug, not RCE, and if it was feasible w/o the custom buffer then why not provide that as the example? In the real world, a ffmpeg invocation would use the default buffer handler that will use padding/alignment/etc that makes the heap even less predictable, and incredibly unlikely to have a function pointer exactly following the frame buffer that will deterministically be invoked by a process placing it there?
It seems very far fetched.
I've seen plenty of systems along the lines of what you're describing where unauthenticated clients can submit jobs. Sometimes the developers even claim that's intentional. Either way, it's a vulnerability, because it compromises the underlying hosts.
Theres a bunch of very specific scenario DoS bugs, buffer over/ underflows, that will get caught by ASLR and whatnot
When I report serious ones, mostly the devs will respond with something like, yeah, thats how we designed it in a dangerous way, so that the layer above or below can solve the issues, and other footgun stuff.
This is one of the reasons that responsible disclosure exists. Their tune will likely change after sufficient bad publicity.
If the Apache Solr devs can be convinced to add authentication to their product instead of hand-waving about reverse proxies or other add-ons, anyone can.
Do NOT, under any circumstances, use any material in this repository
maliciously. This is good-faith, open-disclosure vulnerability
research intended to get more people interested in exploring
this area of cybersecurity.
Reminds of the message in the The Anarchist Cookbook before one the recipes that essentially said: "This is really dangerous, don't ever do it, here is how you do it."I've been a skiddy, he would have believed this. Thankfully, I've grown a bit, and can see this for the transparent, "I'm angry and want to hurt others so I will feel a little less alone", it actually is.
I'm sorry you're so angry dude (me too), but as someone who's joined the blue side, we'd appreciate it if you gave us some kind of heads up, the bad guys generally have a lot more time to scroll for new payloads than I do. Not all of us deserve the kindness of a heads up, but every single one of our users deserve it. Don't punish them because you're mad at someone else.
You can flex on the idiots you're trying to flex on, without hurting people. Even an email to security@[that_project_domain] saying "hey, I've published these" would move you from the group of people I see making the world worse, into the group making it better. (You don't have to, obviously, but making the whole world worse wont make you less angry.)
Sure you than can do it anonymous and so on but point is : its not like every actor that gets notified will react thankful to it. Some even just ignore it.
I'm equally annoyed and over the alarmist takes. But I don't think it's fair to group mine into it. I'm annoyed at seeing discard respect for others into the same void everyone is happy to toss quality.
Do these tiny things matter? No, not to the default-panic-level everyone adopts when they see 0day, or CVE... but duh, I'm now just repeating exactly what you already said. That no, for the record is mostly because I don't use any of these, not just because they're boring exploits. While I always look, I default assume anything CVE is boring/pointless. But I still read them.
But then, I'm not trying to convince the owner of the repo. I'm trying to discourage the theme among researchers that "no one cares", because I have seen researchers disclose bugs publicly, that we'd be eager to pay out on, because they disagreed with the decision on their last report.
I've fixed bugs being actively exploited against our users, that was found/fixed only after a whitehat report for something adjacent (we pay on those btw, and you should too). I don't wanna live in the world where it's easier for the bad guys, the only way we get there is once "everyone knows", you gotta report the all bugs that you can turn into an exploit. I don't want "the whitehat researcher culture" to move towards, who cares' dump the PoC on github, screw anyone that could be hurt by the bad guys, they deserve to be punished for the incompetence of others. SWE's are shit at security, security researchers are shit at SWE, the only way we get the good outcome, is if they're willing (and encouraged) to work together.
So I'm still not gonna name them, it wouldn't be hard to figure out who they were, with a likely-trivial amount of effort if feel the need to know... but if you'd rather, I'd encourage you to imagine I work at the worst company you can name or imagine, so you can use that to discard anything I've said. Because I'd rather be judged on my argument, not who hired me that one time.
I meant it when I said it intentionally. I still run BB programs the same way, and expect others to behave similarly. Funny enough I was just talking to that friend this week, about the BB program. Nothing has changed so given my friends still follow the same pattern at that company... We is more accurate. Sorry it bothers you, but not everyone is you.
but the ridiculous contradictions in what you’re saying are difficult to ignore.
You went from implicitly speaking for a bug bounty team,
to not speaking for one (but sort of your colleagues?),
to now unabashedly speaking for TWO bug bounty teams
…without even naming an industry?
Account take over of a user account. I'm pretty sure I could sell access to the DMs of a few popular people for 100x what we paid out for that report.
But also, I'm pretty confident that this researcher delivered this exploit because I'd said that there was no way he could use it maliciously, not because he wanted to be paid. Then, once I made that critical error in judgement by questioning (rejecting) his assertion in his report. He, like most hackers, being insulted by the idea, was then required to restore his name and reputation. There are the people who only go after targets that they can confidently make money off targeting... some of us care more about reputation than money, and will die on any hill when our reputation/work is questioned/doubted.
> Security "teams" are a bunch of fucking busybodies with nothing to do. Pay for a competent admin team and the security dept is completely redundant and useless.
Lmao, tell me you don't really understand what goes into getting functional systems/corp security without telling me. I don't even disagree with the point you were trying to make. You're absolutely correct! If you have a competent admin team, you don't need a dedicated security team. Unfortunately, as I live in the real world, where most people are incompetent, it does help to have a dedicated security team. Especially considering if you were an admin who is competent, you could make 2x as a security engineer, which normally keeps all the competent people out of admin, and thus requiring a dedicated security team.
I don't know why you're mad, or why you're arguing it at me. I'm pretty sure I already agree with most of your points... the only one I might disagree with, and only then because you're arguing at me for some reason, and that makes me think you probably disagree, with the important point which is, we're all on the planet together, you're not required to help me do my day job, but as an industry, both security engineers and security researchers, we need to remember that we're actually on the same side, and we need to aggressively resist returning to the us vs them mentality that we're just barely starting to escape from. Case in point, it appears to me that you think complaining about how security people are useless and CVEs don't matter, as a much more important point, than complaining about obviously irresponsible disclosure.
Please name the "victims" here.
I'm genuinely curious, have you ever had actual, direct threats to your safety before, as a person? As in, murder, torture, false imprisonment, or other __likely and credible__ threats of grave bodily harm?
> but as someone who's joined the blue side
Are you somebody who separates "cybersecurity" from say: military intelligence poisoning one of your employees, sending them to a hospital which is already compromised, before sending back their new asset into your very "secure" company?
I don't know what methods where used to find these exploits but I am starting to think security through obscurity might not be a bad thing in this day and age, where someone can just let bots loose on your codebase.
something like nginx could arguably be more secure if it was closed source
(I am a proponent of and contributor to open source)
Maybe if it's some server-side software that you only use yourself...
> OSS only needs someone to have a strong LLM to check for bugs.
The same applies to propietary, closed-source code. It being closed-source means that the source isn't generally available, but the executable is. Hence, someone with a strong model can still reverse it and find vulns.
A different way to frame this would be that those bugs would never be surfaced or exploited if the software were proprietary.
I'd love to hear why you think obscurity is bad, if you now think maybe it's good in the LLM age?
I'd also be interested if you could describe exactly what or how you think security through obscurity works, or doesn't?
I've been thinking a lot about how to better teach this concept, so I'm looking to understand exactly how everyone thinks/understands how it currently works, or should work, or what it should do. I don't care about the "correct" answer, (I have ddg too :P) I'm interested in general expectations from SWE's that I might teach at work, instead of opinions of security eng speaking about theory.
> starting to think security through obscurity might not be a bad thing
In the case of FOSS software, it is generally recognized that the small advantage of keeping the source secret is far outweighted by the contributions and vuln reports you get if you publish the source.
It was reported by @rz1027 (me) as in Gitea's coordinated 1.26.3 security release, credited in the release notes. The exploitarium's actual Gitea PoC is a different bug (act_runner container-options escape).
Refs: [https://blog.gitea.com/release-of-1.26.3-and-1.26.4/] [https://github.com/go-gitea/gitea/security/advisories/GHSA-f... ] [https://hivesecurity.gitlab.io/blog/gitea-forgejo-nine-cves-...].
Edit:
To be clear still interesting finds. I think with some chaining some of them might be more severe. Like the ovpn one and windows potentially registering vpn app as default open or some protocol opener for a url location like openvpn:// in an I frame and some clever social engineering. Just a random thought
Floci, libssh2, c-ares, FFmpeg, and the PHP one are all LEGIT./
The Ghidra one for example, not so much. I cant help but wonder if this was halfway completed research folder and they just published it as is
The problem ultimately came from not being able to prevent stale pointers. The attack works by figuring out the size of the stale pointer, then spraying memory with data of the same size, and finally achieving RCE (Remote Code Execution). How do people even come up with ideas like this?
Used to be a zero day got you unauthorized access to a computer system with no warning.
Now it might not even get a maintainer to do a patch when they're bored.
Many French people with crypto money experienced that the hard way recently.
In short, it's a very active and growing activity. Many data leaks helped people to identify wealthy targets. Some just brag about having crypto.
https://www.lemonde.fr/societe/article/2026/04/24/enlevement...
https://www.franceinfo.fr/faits-divers/cryptomonnaies-la-vag...
https://www.lemonde.fr/societe/article/2025/08/19/l-ascensio... (paywall)
https://www.slate.fr/societe/enlevements-lies-cryptomonnaies...
Some random recent ones we know about:
https://france3-regions.franceinfo.fr/grand-est/haut-rhin/mu...
https://www.leparisien.fr/faits-divers/renseignes-par-des-ha...
Banks give you an advantage with transaction security and deposit insurance, but that's dealing with money and not cash.
Ideally, nothing nefarious should happen if both of them were listed and queryable publicly.
Why GitHub, people don’t know any better?
Didn’t bother submitting since who actually uses tizen?
Then I did some searching and found multiple examples of both definitions in use, making things murky.
So I turned to Merriam-Webster’s dictionary: “ of, relating to, or being a vulnerability (as in a computer or computer system) that is discovered and exploited (as by cybercriminals) before it is known to or addressed by the maker or vendor”
And of course they use an “or” to make it ambiguous as to whether the days start counting when the vulnerability becomes known, or when the vendor has addressed it.
No, the full name was always "zero-day exploit". The number 0 refers to the days between the vulnerability being known by the vendor and the public availability of the exploit. So the vendor has zero days to create a security patch before the release of the exploit.
The term "zero-day vulnerability" is a derived term to refer to a vulnerability affected by a zero-day exploit. Similarly, a "zero-day attack" is a derived term to refer to an attack carried out using a zero-day exploit.