Android Red Team @google
Fuzzing @aflplusplus.bsky.social
CTF @enoflag
(opinions my own)
Time to take them apart 🧵
Time to take them apart 🧵
- generating two HTML trees (libFuzzer)
- parsing w/html5ever
- diffing w/hotmeal+cinereus
- sending via roam to Chrome
- applying sending back detailed traces of patch application
found two legitimate adoption agency bugs so far! (the others were my fault).
- generating two HTML trees (libFuzzer)
- parsing w/html5ever
- diffing w/hotmeal+cinereus
- sending via roam to Chrome
- applying sending back detailed traces of patch application
found two legitimate adoption agency bugs so far! (the others were my fault).
Find more details here🔗https://buff.ly/psTxdyG
Find more details here🔗https://buff.ly/psTxdyG
The hacker also published users’ data on the website okstupid.lol.
The three sites are still down, a week after the live hack.
Thinking log contains the answer, but at least it decides it cannot answer it..
Thinking log contains the answer, but at least it decides it cannot answer it..
projectzero.google/2026/01/pixe...
To mark the occasion, we released some older posts that never quite made it out of drafts.
Enjoy!
To mark the occasion, we released some older posts that never quite made it out of drafts.
Enjoy!
To mark the occasion, we released some older posts that never quite made it out of drafts.
Enjoy!
he's nervous, but assures it's production ready
he's nervous, but assures it's production ready
Dissent Doe at DataBreaches.net, and yours truly at this.weekinsecurity.com, are running this survey to explore the state of legal demands and criminal threats in cybersecurity.
Dissent Doe at DataBreaches.net, and yours truly at this.weekinsecurity.com, are running this survey to explore the state of legal demands and criminal threats in cybersecurity.
(Failed to send this message on the first try)
(Failed to send this message on the first try)
Organized by: @yannicnoller.bsky.social, @rohan.padhye.org, @ruijiemeng.bsky.social, and Laszlo (@lszekeres.bsky.social) Szekeres.
──────
✨ After 5 years, we will be again co-located with NDSS!
🔗 fuzzing-workshop.github.io
📅 11. Dec (Submission)
//cc @mboehme.bsky.social (MPI-SP), @ruijiemeng.bsky.social (CISPA), @rohan.padhye.org (CMU), László Szekeres (Google)
Organized by: @yannicnoller.bsky.social, @rohan.padhye.org, @ruijiemeng.bsky.social, and Laszlo (@lszekeres.bsky.social) Szekeres.