modzero @modzero.bsky.social · 03/06/2026And here is the detailed report on our PSA from last week: "Please Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free" modzero.com/en/blog/plea...modzero.comPlease Do Not Hack Me - The Tale of a TeamSpeak Use-After-Free 011
modzero @modzero.bsky.social · 28/05/2026🎶 PSA: Multiple Denial of Service vulnerabilities in TeamSpeak. Find our colleague Michael Imfelds advisory here modzero.com/en/advisorie...modzero.com[MZ-26-01] TeamSpeak 012
modzero @modzero.bsky.social · 12/03/2026We're Hiring! We are currently looking for a Penetration Tester and a Senior Red Teamer. Check out our open positions and reach out if you think you’d be a great fit. Here: modzero.com/en/jobs/modzero.comJobs 034
Reposted by modzero netzpolitik.org @netzpolitik.org · 07/01/2026Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und praktischen Lösungen will sich Nikonole einer zusammenbrechenden Welt entgegenstellen.netzpolitik.orgHacken & Kunst: „Kunst allein reicht nicht aus“Helena Nikonole hat Kameras in Russland gehackt und Anti-Kriegsbotschaften verbreitet. Nun entwickelt die Künstlerin ein winziges Gerät, um ohne Internet Nachrichten zu verschicken. Mit kreativen und ... 625078
Reposted by modzero Drew Harwell @drewharwell.com · 07/01/2026X basically industrialized the creation of fake porn of women who don't consent. Others did it first, but Grok made it normalized and centralized: publicly visible, instantly creatable by anyone, regardless of who's being targeted and dehumanized. Only question now is will X suffer any consequences 20748561272
Reposted by modzero Stadt Wien-Büchereien @buechereienwien.bsky.social · 07/01/2026Sollen wir Büchertische zum Thema Fitness und Fasten machen oder gleich die Oster-Backbücher rausstellen? 1519114
modzero @modzero.bsky.social · 10/11/2025No Leak, No Problem - Remember our PSA about updating your INSTAR cameras? Here’s the reason in detail, worked out and noted by our teammate Michael Imfeld: modzero.com/en/blog/no-l...modzero.comNo Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE 031
modzero @modzero.bsky.social · 06/11/2025Does anyone here have a working way to contact archive.org? It's about a security issue... 000
modzero @modzero.bsky.social · 28/09/2025catch a glimpse of us holding our annual “state of the zero” meetup - to wrap our heads around all of IT and us. we also took a boat trip, ate too many sweets, touched some grass, saved the world, had a barbecue and a drink or two…💓 #modzero #infosec #itsecurity #captainitswednesday 061
modzero @modzero.bsky.social · 14/08/2025PSA update your INSTAR cameras. Our teammate Michael Imfeld identified a critical RCE (CVE-2025-8760) on 2k+ and 4K devices. Find the advisory here: modzero.com/en/advisorie...modzero.com[MZ-25-03] INSTAR 2K+ and 4K Series 094
modzero @modzero.bsky.social · 29/06/2025This blog post contains the full technical walk-through and discovery of the vulnerability, its impact, and our experience during the responsible disclosure process with Synology. 030
modzero @modzero.bsky.social · 29/06/2025Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...modzero.comWhen Backups Open Backdoors: Accessing Sensitive Cloud Data via 12214
modzero @modzero.bsky.social · 25/06/2025donate! www.thetinychefshow.com/fan-club-log...thetinychefshow.comSUPPORT CHEF — The Tiny Chef Show 010
modzero @modzero.bsky.social · 31/03/2025"kick off" passt ganz gut. wenn auch noch ein wenig zu höflich 120
modzero @modzero.bsky.social · 31/03/2025vielleicht mal ein argument für bildungsgeld, das auch neolibs verstehen? 030
modzero @modzero.bsky.social · 07/02/2025Dive into the process of reverse engineering, gadget hunting, and crafting a working exploit. 020
modzero @modzero.bsky.social · 07/02/2025Via Return-Oriented Programming chain small code snippets, or gadgets, already present in a program’s memory can be leveraged By chaining these gadgets together, they can execute arbitrary code without injecting anything new 110
modzero @modzero.bsky.social · 07/02/2025ROPing our way to “Yay, RCE” - and a lesson in the importance of a good nights sleep! Follow our Colleague Michaels journey of developing an ARM ROP chain to exploit a buffer overflow in uc-http modzero.com/en/blog/ropi...modzero.comROPing our way to RCE 274
Reposted by modzero abgeordnetenwatch @abgeordnetenwatch.de · 03/02/2025🔔 Unser #kandidierendencheck ist online: 18 Thesen beantworten - und ihr erfahrt, welche Kandidierenden in eurem Wahlkreis so denken wie ihr. 👇 www.kandidierendencheck.de/bundestagkandidierendencheck.dekandidierendencheck Bundestagswahl 2025 | Wahlhilfe für deine ErststimmeVergleichen Sie Ihre Meinung mit der Ihrer Kandidierenden über 18 Themen zur Wahl! Jetzt mitmachen! 11324151
Reposted by modzero netzpolitik.org @netzpolitik.org · 29/01/2025Seit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das Abstimmungsverhalten. netzpolitik.org/2025/real-o-...netzpolitik.orgReal-O-Mat: Taten zählen mehr als WorteSeit heute ist der Real-O-Mat online. Das Tool vergleicht die eigene Position bei relevanten Fragen mit denen der Fraktionen im Bundestag. Grundlage dafür sind keine Wahlkampfversprechen, sondern das ... 18258124
modzero @modzero.bsky.social · 16/01/2025learn all about it from our colleagues Pascal and Christoph at their 37c3 talk or from our published disclosure report: modzero.com/en/blog/mult...modzero.comMultiple Vulnerabilities in Poly VoIP Products 000
modzero @modzero.bsky.social · 16/01/2025attackers could then listen in on conversations using the built-in microphones or could reroute incoming and outgoing calls ... and so on 100
modzero @modzero.bsky.social · 16/01/2025we found several vulnerabilities in commonly used desk phones and smart conference speakers. combined, the issues can be used to take over a device through the local network or with physical access 100
modzero @modzero.bsky.social · 16/01/2025was just listening to #DeLaSoul's classic #RingRingRing on the radio and thought about the time we broke a phone. or: how some coupled minor pinches can become a proper headache colleagues @yonk42.bsky.social and @parzel.bsky.social talked about it at #37c3 www.youtube.com/watch?v=K9mm...youtube.com37C3 - Finding Vulnerabilities in Internet-Connected DevicesYouTube video by media.ccc.de 220
Reposted by modzero dunja hayali @dunjahayali.de · 13/01/2025 Wenn Sie sich die Unwörter der letzten 11 Jahre anschauen, was fällt Ihnen auf? • 2024 Biodeutsch • 2023 Remigration 1641642438
modzero @modzero.bsky.social · 10/01/2025We were quite happy - at least for a minute - for there are probably easier ways to achieve the final result. So let us know if you have a better approach :) contact via link! 010
modzero @modzero.bsky.social · 10/01/2025 The post outlines the current state of SSTI on Spring Boot, explains where we got stuck with existing payloads and how to find your own exploitable libraries to bypass defenses. 110
modzero @modzero.bsky.social · 10/01/2025We broke something: in a recent pentest on a hardened target, we were able to achieve unauthenticated Remote Code Execution (RCE) via Server-Side Template Injection (SSTI) in a Spring Boot application We wrote it down for you to try at home: modzero.com/en/blog/spri...modzero.comExploiting SSTI in a Modern Spring Boot Application (3.3.4) 1195
Reposted by modzero linuzifer @linuzifer.bsky.social · 29/12/2024Der @ths.ch und ich haben uns beim #38C3 mal wieder mit Wahlsoftware beschäftigt. media.ccc.de/v/38c3-der-t...media.ccc.deDer Thüring-Test für WahlsoftwareWähle Dein Risiko! Vor der Bundestagswahl 2017 veröffentlichten wir unsere Analyse über haarsträubende Sicherheitslücken in einer weit v... 37917
modzero @modzero.bsky.social · 18/12/2024i am going on a trip and i am taking with me ... 💓 #38C3 031
Reposted by modzero Manuel 'HonkHase' Atug @honkhase.de · 03/12/2024Wieder ein mega Programm! Der CCC hat zu seinem Chaos Communication Congress #38C3 den ersten Fahrplan veröffentlicht: Version Alpha-0.1 fahrplan.events.ccc.de/congress/202... 13816
Reposted by modzero parzel @parzel.bsky.social · 27/11/2024I can highly recommend Shazzer from @garethheyes.co.uk, such a great tool for XSS research!youtube.comDigging for XSS Gold: Unearthing Browser Quirks with ShazzerYouTube video by PortSwigger 0224
modzero @modzero.bsky.social · 21/11/2024Hello Bluesky 👋 We are an IT security company. Our team consists of like-minded hackers located in Germany and Switzerland. Our core areas of expertise are comprehensive technical security analyses, penetration tests and red teaming services. Want to learn more about us? Check: modzero.com/en/modzero.comIn-depth IT Security 052