You are here |
www.nynaeve.net | ||
| | | |
googleprojectzero.blogspot.com
|
|
| | | | Posted by Mateusz Jurczyk of Google Project Zero This post series is about how we used at-scale fuzzing to discover and report a tot... | |
| | | |
m417z.com
|
|
| | | | This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in Decembers Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or otherwise inaccessible process, allowing for privilege escalation. The vulnerability is caused by a lack of security checks in the InitializeXamlDiagnosticsEx API, which is used for inspecting applications that use Extensible Application Markup Language... | |
| | | |
www.sonatype.com
|
|
| | | | Learn about a new, targeted backdoor supply chain attack against the popular XZ compression utility seen in many Linux distributions such as fedora and debian. Understand its impact, potential risks and what you can do about it. | |
| | | |
johannesbrodwall.com
|
|
| |