39C3 - Escaping Containment: A Security Analysis of FreeBSD Jails

FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)

Overview Earlier this year, a team at Praetorian was building Constantine, our automated 0-day discovery engine. I wanted to find techniques worth folding into it, so on the side I started poking ...
What Mythos Tells Us About the Future of Vulnerability Management

What Mythos Tells Us About the Future of Vulnerability Management

Security teams have operated on the same assumption for years: when a vulnerability gets disclosed, there’s time to deal with it. Not much, but enough to assess, prioritize, and patch before anyone ...
Security Boulevard

Spring Core on JDK9+ is vulnerable to remote code execution

Overview Spring Core on JDK9+ is vulnerable to remote code execution due to a bypass for CVE-2010-1622. At the time of writing, this vulnerability is unpatched in Spring Framework and there is ...
PDF File Format: Basic Structure [updated 2020]

PDF File Format: Basic Structure [updated 2020]

| | Exploit Development, feature, PDF
Introduction We all know that there are a number of attacks where an attacker includes some shellcode in a PDF document. This shellcode uses some kind of vulnerability in how the PDF ...