Aaron Schaffer(@aaronjschaffer) 's Twitter Profile Photo

Apple releases iOS 15.7.1 and iPadOS 15.7.1 software updates patching Kernel zero-day CVE-2022-42827 ('An application may be able to execute arbitrary code with kernel privileges'). support.apple.com/en-us/HT213490

account_circle
Haifei Li(@HaifeiLi) 's Twitter Profile Photo

In short, a zero-day hacking contest is better reflecting the real-world threat landscape (reducing ?), and I hope a contest like could help that. :)

account_circle
Miguel Gonzales Jimenez(@z3r0cool) 's Twitter Profile Photo

One Windows in-the-wild 0-day in today's patch Tues: CVE-2022-24521. Discovered by NSA and Crowdstrike 🔥

msrc.microsoft.com/update-guide/v…

account_circle
Maddie Stone(@maddiestone) 's Twitter Profile Photo

Microsoft patches in-the-wild 0-day in Windows CSRSS: CVE-2022-22047. Kudos to MSTIC and MSRC for discovery.

msrc.microsoft.com/update-guide/v…

account_circle
Aaron Schaffer(@aaronjschaffer) 's Twitter Profile Photo

Another WebKit zero-day (CVE-2022-42856) apparently exploited in the wild (against 'versions of iOS released before iOS 15.1')
Safari: support.apple.com/en-us/HT213537
tvOS: support.apple.com/en-us/HT213535
iOS: support.apple.com/en-us/HT213531
macOS: support.apple.com/en-us/HT213532

account_circle
Metacurity @metacurity@infosec.exchange(@Metacurity) 's Twitter Profile Photo

RT @[email protected]
First in-the-wild 0-day of 2023 🔥

CVE-2023-21674: Windows ALPC elevation of privilege discovered by Avast

msrc.microsoft.com/update-guide/e…

All 2023 itw 0-days will be tracked here: docs.google.com/spreadsheets/d…


infosec.exchange/@maddiestone/1…

account_circle
Bioshock(@bioshock_hk) 's Twitter Profile Photo

UnderNews_fr: RT Maddie Stone: 2021 was a wild year for 0-day exploitation detection. 2021 was also full of Google Project Zero & TAG publishing lots of good (in my biased opinion) stuff on 0-day exploits. 🧵ICYMI here they are:

account_circle
Maddie Stone(@maddiestone) 's Twitter Profile Photo

✨New RCA up for Chromium 0-day CVE-2022-1096. Patched in March 2022. And it even has a tweetable trigger!

style = document.createElement('p').style;
style.prop = { toString: () => {
style.prop = 1;
}};

googleprojectzero.github.io/0days-in-the-w…

account_circle
Aaron Schaffer(@aaronjschaffer) 's Twitter Profile Photo

Apple's new iOS 16.1 and iPadOS 16 software updates patch Kernel zero-day CVE-2022-42827 ('An application may be able to execute arbitrary code with kernel privileges'). support.apple.com/en-us/HT213489

account_circle
Maddie Stone(@maddiestone) 's Twitter Profile Photo

Chrome patches an in-the-wild 0-day: CVE-2023-2136, an integer overflow in Skia. Discovered by clem1 of Google TAG 🎯

Kudos to Chrome on some super quick patching -- 3 days for the RCE, patched on Friday, and 6 days for this sbx escape. 👏🏽

chromereleases.googleblog.com/2023/04/stable…

account_circle
Aaron Schaffer(@aaronjschaffer) 's Twitter Profile Photo

Apple announces it has patched WebKit type confusion bug CVE-2023-23529 on iOS/iPadOS 16.3.1. “Apple is aware of a report that this issue may have been actively exploited.” support.apple.com/en-us/HT213635

account_circle
Maddie Stone(@maddiestone) 's Twitter Profile Photo

3 in-the-wild 0-days patched in the last two days:
* CVE-2022-2856 in Chrome discovered by Ashley Shen & PewZ of Google TAG
* CVE-2022-32893 in Safari
* CVE-2022-32894 in iOS/macOS kernel

docs.google.com/spreadsheets/d…

account_circle