shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

286
active users

#pwn2own

0 posts0 participants0 posts today

@marcan nodds in agreement #Apple doesn't need to have backdoors in Hardware when their entire #iCould is backdoored and can be weaponized to brick devices.

  • OFC similar functionality can be achieved with #CompuTrace on #amd64-based #Laptops (i.e. #ThinkPads) and compared to that, #AMT + #ManagmentEngine is trivial to #exploit and should be considered real #backdoors (abeit "well meaning" in the sense of remote provisioning of entire fleets of devices, but still allowing to bypass the OS and offering DMA access to the CPU, so basically "#pwned")...

Either way, these are not inherent to the used #Silicon, but entirely #Firmware-based.

  • AMT for example requires a "#Intel #vPro" configuration with Intel-made Ethernet NICs (i.e. i2xx & i3xx - Series) with a Q- or C-series Chipset & supporting #UEFI, so most Systems with cheap #Realtek-NICs aren't exploitable straight-away, and even then it requires certain settings to work, so not an easy "#Pwn2Own" style exploitability...
#intel#vpro#uefi

I don’t usually post work stuff but #ibm #xforce doesnt have a Mastodon presence so once in a while I have to post the important stuff.

Congratulations to @chompie1337 who scored a win in the Windows 11 LPE category! Her exploit circumvents the latest Virtualization Based Security mitigations. She becomes the first solo female competitor to score a full win at #Pwn2Own, the world’s most prestigious hacking competition.

(Only links I have are to Xitter and I won’t post those)

New by me at Forbes, a round-up of the #Pwn2Own Toronto 2022 #hacking event. Some 63 #zeroday vulns successfully exploited in the allotted time, earning payouts from #ZDI of very nearly [Professor Evil] One Million Dollars [/Professor Evil] in total.

#infosec #news

forbes.com/sites/daveywinder/2

ForbesElite Hackers Made Almost $1 Million Last Week, Here’s HowBy Davey Winder