Phrack 72 article and WHY2025 conference talk
Phrack 72 article and WHY2025 conference talk
A logical vulnerability in OpenPGP.js, allowing for spoofed signatures using a crafted PGP packet sequence
Two vulnerabilities in LibreOffice allowing semi-arbitrary file read/write and env var leakage
A bunch of bugs in Ghostscript, including a classic format string vulnerability leading to RCE
A bug in PDF.js (and Firefox) with widespread XSS consequences
Write-up on several bugs in Feathers.js, Sequelize, and Socket.IO relating to type confusion and incorrect interop assumptions
Hacking the Verifone VX820 payment terminal to run Doom and more.
Exploiting a remotely-triggerable stack-based buffer overflow vulnerability on a Zyxel VMG8825-T50 router.
Finding and chaining multiple vulnerabilities to get root access on a Zyxel VMG8825-T50 router.