New exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
github.com/xoreaxeaxeax/skit…
Really grateful to @epsilon_sec for supporting us. Thanks to them, we can focus on DEF CON CTF this year with much less pressure around the costs.
They’re hiring globally for remote security research roles, so reach out if you’re interested!
@epsilon_sec is hiring security researchers focused on:
- iOS: 0-click, SBX, PE
- Android: 0-click
- Chrome for Windows: RCE, SBX, PE
South Korea-based candidates are welcome, and all roles are available for remote work worldwide!
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
XS-Leaks challenges just got harder. Chrome shipped Socket Pool Randomization which should hopefully make it much harder to learn about opened sockets!
chromestatus.com/feature/649…
We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax.
These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.
I’ll start working at @ENKI_official_X from next Tuesday as a Technical Research Personnel (Alternative Military Service)!
Probably you know them as Codegate Organizer 🙂