Tencent's Xuanwu Lab retweeted
CVE-2025-67303 An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data. This was due to the applicat… cve.org/CVERecord?id=CVE-202…
2
3
859
Tencent's Xuanwu Lab retweeted
BadPower attack corrupts fast chargers to melt or set your device on fire zdnet.com/article/badpower-a…
1
8
8
Tencent's Xuanwu Lab retweeted
Our lab @XuanwuLab made a curated list of infosec resources available at sec.today. It provides global search for past research materials, in a way much like Everything or Spotlight, and also insights about current research focus and trends.
2
98
219
Tencent's Xuanwu Lab retweeted
We are proudly to release our slides for NTLM Relay is DEAD, Long Live NTLM Relay in HITB 2018 Dubai conference.hitb.org/files/hi… And the tools github.com/5alt/ultrarelay We even meet the author of ntlmrelayx! Thank you! @T0m4to_ @darkfloyd1014 @HITBSecConf @XuanwuLab
2
20
49
We are proud to introduce our spectre vulnerability online check tool: xlab.tencent.com/special/spe… Surface Pro, iPhone X, Chrome, Firefox, almost everything is supported. :-) #Meltdown #Spectre
4
86
95
Congratulation! By the way, we are a department of Tencent, not Tencent itself;) nitter.net/YoStartups/status/8759…
2
Microsoft introduced a new exploit mitigation "RFG" in Windows 10 Redstone 2 14942 to protect return address: xlab.tencent.com/en/2016/11/…
128
106
Our BadBarcode page: xlab.tencent.com/badbarcode/. No new domain name, no logo, just a page:-). #BadBarcode
6
4
The detailed technical report of #BadTunnel : "BadTunnel - A New Hope" xlab.tencent.com/en/2016/06/…
1
33
27
Abusing Special Cases in System Exception Handling to Achieve Unbelievable Vulnerability Exploitation - xlab.tencent.com/en/2016/04/…
1
13
12
Use Chakra engine again to bypass CFG - xlab.tencent.com/en/2016/01/…
5
12
Tencent's Xuanwu Lab retweeted
CanSecWest 2016 (Mar. 16-18) Presentation: Sandbox Escape with Generous Help from Security Software - Chuanda Ding, Tencent Xuanwu Lab
5
2
Drag & Drop Security Policy of IE Sandbox - xlab.tencent.com/en/2015/12/…
2
8
Use Chakra engine again to bypass CFG - xlab.tencent.com/en/2016/01/…
8
7
Bypass DEP and CFG using JIT compiler in Chakra engine - xlab.tencent.com/en/2015/12/…
50
44
As the most ancient tech of IoT, barcodes are everywhere, even starship Enterprise. See you #PacSec2015. @PacSecjp http://t.co/k5nsFWugRQ
7
6
Poking a Hole in the Patch: Escaping from IE Sandbox with a Poorly Patched Vulnerability - xuanwulab.github.io/2015/08/…
1
40
48