If u think that Windows research is all we do, think again! In our first IOT blog, @voix44er details the Wolfbox EV charger setup, attack surface, his #Pwn2Own Automotive 2025 bug, exploitation, and best of all, displaying our name on it (in styleee...)!
pixiepointsecurity.com/blog/pwn2own-2…
Happy Friday! Our intern, @__neverm0r_ , discovered and reported a NPD due to race-condition in afd.sys. Wasn’t assigned a cve doesn’t mean it’s less interesting, right!?
pixiepointsecurity.com/blog/advisory-…
Proud to see @_jaelkoh (with @saidelike) talking about undocumented internals of KTM, the bugs and exploits in 'Hunting for Overlooked Cookies in Windows 11 KTM and Baking Exploits for Them'. No ovens required for this recipe!
Confirmed (with a collision)! Rafal Goryl of PixiePoint Security used a 2 bug chain to exploit the WOLFBOX Level 2 EV Charger, but one of the bugs was previously known. He earns himself $18,750 and 3.75 Master of Pwn points. #P2OAuto
Annnddd... the odds ARE in your favor! Congrats @voix44er ! This result is just the cherry on the cake. Regardless of what it may be, what we don't see is the dedication and hard work put into the research.. 💪💪💪
Success! On his second attempt, Rafal Goryl of PixiePoint Security was able to exploit the WOLFBOX EV charger. He heads off the the disclosure room to provide us with all the details. #P2OAuto#Pwn2Own
All shells are spawned equal, regardless of memory-corruption bugs or not!
CVE-2021-34462: Exploiting the Windows AppXSvc Service Logic-Error Vulnerability
pixiepointsecurity.com/blog/nday-cve-…
33K Followers 1K Following意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / BHUSA Review Board
3K Followers 1K FollowingWrite some shit code. Do shit research. DEFCON 31/32/33 finalist. Co-founder and ultimate pwning machine @nebusecurity. CTF with @r3kapig. Prev. at @zellic_io.
30 Followers 491 Followingattempting to forge handcrafted, bespoke :)
userland
kernel
hypervisors.
if the decompiler lies, trust assembly. if assembly lies, read the ARM ETM trace
3K Followers 5K FollowingCHA is my family name. Threat Intelligence Researcher at AhnLab / Keybase : mstoned7 , Signal : mstoned7.21 / Tweets are my own.