dangerously powerful agentic security

We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome. This PoC Downloads the file, then pops open the file manager for unsandboxed RCE (lovingly refered to as the full chain from temu)
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
3
30
362
24,469
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
7
14
175
29,972
Ghostscript is widely used, including by document viewers, ImageMagick/Pillow, and thumbnails across many Linux distros. These bugs were found by @rdjgr of the V12 security team. He presented Ghostscript bugs and exploits today from the BSides Canberra main stage. PoC: github.com/v12-security/pocs…
2
31
1,356
🪿🪿🪿 goose rce 🪿🪿🪿
5
6
120
11,354
V12 retweeted
Interestingly this is a very similar primitive to one of the "unexploitable" dead ends in @trailofbits recent article about sandbox escapes. (although this is a slightly different bug) It did take some manual nudging for me to convince 5.6-sol that AppArmor could be bypassed :)
user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇
5
31
3,600
user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇
9
71
540
43,429
The vulnerability gives us an arbitrary file write as root, but we still need to bypass AppArmor: 1. Use the file overwrite to overwrite part of /etc/cups/cups-files.conf (allowed by AppArmor) 2. Use a crash bug to restart CUPS, making /etc/cups/interfaces writable by our group 3. Drop a malicious cups-exec file in the interfaces folder that will be executed by root POC: github.com/v12-security/pocs…
2
4
24
2,659
This bug was found by @rdjgr using V12. V12 is our autonomous AI hacker. Find bugs like this in your code: v12.sh/
6
1,765
V12 retweeted
My PlayStation 5 $10,000 bounty along with Firefox XSS bugs and many more vulnerable apps research are now public
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps. PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance... Breakdown and POC. 🧵
7
28
381
30,328
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps. PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance... Breakdown and POC. 🧵
5
55
332
47,315
We contacted dozens of other vendors. Some patched the issue; many reports remained unacknowledged or unresolved. For more information, see: v12.sh/blog/webkit
1
1
8
1,494
POC: Open webkitxss.v12.sh in an affected app Found by @RenwaX23 using V12. V12 is our autonomous AI hacker. Find bugs like this in your code: v12.sh
1
12
1,384