The Dustin Childs
banner
dustinchilds.bsky.social
The Dustin Childs
@dustinchilds.bsky.social
Just a simple information security gnome trying to make his way through the universe. Part-time patch wrangler. Tweets are just my opinion and such. Got questions about patches or bug bounties? My DMs are open. Signal: DustinChilds.17
Silent patches make Zed sad :-[
November 11, 2025 at 6:37 PM
Wow - a small(ish) Patch Tuesday! Just 64 new CVEs from #Microsoft and 29 from #Adobe. One Msft CVE under active attack. I'll have my full thoughts out shortly.
November 11, 2025 at 6:05 PM
Reposted by The Dustin Childs
I attended Pwn2Own in Cork ☘️ last week. I shared a review of the event on this week's episode of my podcast.

You can find that at 14:41 in the video linked here ⬇️
www.youtube.com/watch?v=aaLA...

Thanks to @dustinchilds.bsky.social & @thezdi.bsky.social for allowing me to attend. ❤️
October 30, 2025 at 8:40 PM
But I thought Microsoft said it wasn't worth fixing? "Microsoft classified this as low severity and this will not be patched in the immediate future." arcticwolf.com/resources/bl...
UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities - Arctic Wolf
Arctic Wolf Labs has identified an active cyber espionage campaign by Chinese-affiliated threat actor UNC6384 targeting European diplomatic entities in Hungary, Belgium, and additional European nation...
arcticwolf.com
October 30, 2025 at 7:42 PM
Not to brag or anything, but I did predict this. I didn't predict the patch would be bypassed. *sigh* Patch kwality continues to be an issue. Go update your WSUS - again. msrc.microsoft.com/update-guide...
October 24, 2025 at 2:32 PM
For the record, Maude and I are just friends. Any other rumors you may have heard are just tabloid trash. ;-]
October 24, 2025 at 2:29 PM
October 23, 2025 at 5:59 PM
Reposted by The Dustin Childs
For all results of Day Three of #Pwn2Own Ireland 2025, check out the blog at www.zerodayinitiative.com/blog/2025/10... We'll be updating this with live results throughout the day.
Zero Day Initiative — Pwn2Own Ireland 2025: Day Three and Master of Pwn
Welcome to the third and final day of Pwn2Own Ireland 2025. So far, we’ve awarded $792,750 for 56 unique 0-day bugs, and we still have 17 attempts to go! We’ll be updating this blog with live results ...
www.zerodayinitiative.com
October 23, 2025 at 9:58 AM
I asked 30 seconds or 30 minutes. They told me 30 seconds. They lied.
October 22, 2025 at 4:29 PM
Good dog
October 22, 2025 at 11:29 AM
Reposted by The Dustin Childs
On Day One of #Pwn2Own Ireland, we awarded $522,500 for 34 unique 0-days. Day Two is shaping up to be even better. Get ready - pwnage is coming....
youtube.com/shorts/49s0O...
Kicking Off Pwn2Own Ireland 2025 Day Two #shorts
YouTube video by Trend Zero Day Initiative
youtube.com
October 22, 2025 at 7:52 AM
Ya love to see it. I smell a melon party in our future...
October 21, 2025 at 12:36 PM
So great to see - and 8 bugs??!?
October 21, 2025 at 10:52 AM
Getting closer to a melon party!
October 21, 2025 at 9:16 AM
Maude and I will be up to no good this whole week.
Get ready for Day One of #Pwn2Own Ireland 2025. We have 17 entries today, including a SOHO Smashup and a Sonos Era 300 exploit. It should bee spooktackular! #P2OIreland
youtube.com/shorts/twm8d...
P2O ZDI DAY 1 Kickoff
YouTube video by Trend Zero Day Initiative
youtube.com
October 21, 2025 at 7:59 AM
Reposted by The Dustin Childs
Day One of #Pwn2Own Ireland starts with four attempts at once - including a SOHO Smashup! #P2OIreland
October 21, 2025 at 7:50 AM
Reposted by The Dustin Childs
We're 30 minutes out from the live stream where we draw for the order of events for #Pwn2Own Ireland. You can watch it on LInkedIn or on YouTube at youtube.com/live/IzFsuXx...
Pwn2Own Ireland 2025: Drawing for Order
YouTube video by Trend Zero Day Initiative
youtube.com
October 20, 2025 at 1:27 PM
Reposted by The Dustin Childs
It’s always DNS.
> Based on our investigation, the issue appears to be related to DNS resolution of the DynamoDB API endpoint in US-EAST-1.

there it is
October 20, 2025 at 9:36 AM
The Cliffs of Insanity! Er…. I mean Moher.
October 19, 2025 at 12:36 PM
It looks even better in real life. Who will claim it?
October 16, 2025 at 4:48 PM
Reposted by The Dustin Childs
Announcing #Pwn2Own Automotive 2026! We're heading back to Tokyo and we're adding new targets Level 3 charging thanks to #Aplitronic & the OCTT thanks to the @openchargealliance.org. Tesla is back, too. Check out the details at www.zerodayinitiative.com/blog/2025/10...
Zero Day Initiative — Pwn2Own Automotive Returns to Tokyo with Expanded Chargers and More!
If you just want to read the rules, click here .  Now entering its third year, Pwn2Own Automotive returns to Automotive World in Tokyo on January 21 – 23, 2026. Over the last two years, ...
www.zerodayinitiative.com
October 16, 2025 at 3:07 PM
Reposted by The Dustin Childs
It's #Microsoft's biggest monthly release ever with more than 170 CVEs addressed - including 3 0-days being exploited in the wild. #Adobe had a small release, with a few interesting items. Join Dustin Childs as he breaks down a spooky patch Tuesday www.zerodayinitiative.com/blog/2025/10...
Zero Day Initiative — The October 2025 Security Update Review
I’m currently in Cork, Ireland as we prepare for Pwn2Own Ireland, but that doesn’t stop patch Tuesday from coming. Take a break from your scheduled activities and let’s take a look at the latest secur...
www.zerodayinitiative.com
October 14, 2025 at 6:43 PM
Come on @adobe.com - why are your security updates so late these days??!? I know I'm being impatient, but I gots blogs to publish and such! #PatchTuesday
October 14, 2025 at 5:56 PM
There are over 170 CVEs in the #Microsoft patch Tuesday release - including three 0-days being exploited in the wild. Wow. I’ll have my full thoughts out shortly - and once Adobe posts their patches as well.
October 14, 2025 at 5:05 PM
Ah Ireland - how I’ve missed ye
October 12, 2025 at 11:44 AM