Neodyme @neodyme.io · 24/03/2026New blog post 🚨 We're diving deeper into a privilege escalation issue (CVE-2024-476) in Lenovo Display Control Center used across Windows enterprise environments. 👉 Read the full breakdown: neodyme.io/en/blog/leno...neodyme.ioLenovo DCC: Part 2 - Trusted IPC and a Malicious Firmware UpdateThe [Lenovo Display Control Center](https://support.lenovo.com/de/de/downloads/ds547223-lenovo-display-control-center-thinkcolor), commonly deployed in Windows enterprise environments, could be used f... 100
Neodyme @neodyme.io · 14/01/2026Drones are hot - their security is not. Here is how removed the NAND, dumped firmware, and reverse-engineered ECC on a consumer drone. Stay tuned for part 2! neodyme.io/de/blog/dron...neodyme.ioDrone Hacking Part 1: Dumping Firmware and Bruteforcing ECCDesoldering a drone's flash chip and reconstructing the firmware from broken data. 022
Neodyme @neodyme.io · 23/10/2025Thanks to @thezdi.bsky.social for hosting yet another well-run and inspiring Pwn2Own edition! 030
Neodyme @neodyme.io · 23/10/2025Another amazing #Pwn2Own in the books! 💪 Our team pulled off some great hacks: 🖨️ HP Printer — $20K / 2 MoP 🏠 Home Assistant — $15K / 3 MoP 🔌 Smart Plug — $20K / 2 MoP 📸 Canon — $10K / 2 MoP Total: $65K / 9 MoP So proud of what we achieved together! 🧠⚡ 111
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 23/10/2025Verified! Team @neodyme.io used a single integer overflow to exploit the Canon imageCLASS MF654Cdw. Their unique bugs earns them $10,000 for the 8th round win and 2 Master of Pwn points. #Pwn2Own 011
Neodyme @neodyme.io · 23/10/2025Check out our new blog post on a research-driven look at software-only DRM. Explore how the Qiling emulation framework can be used to analyze Widevine and how Differential Fault Analysis (DFA) and emulation aid de-obfuscation. ▶️ Read more: neodyme.io/en/blog/wide...neodyme.ioDiving into the depths of Widevine L3This post explores various approaches to attacking Widevine L3, a DRM system commonly used by streaming services. We analyzed the Android library and instrumented it dynamically to extract the keybox ... 030
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 23/10/2025🖨️ Print victory! Team @neodyme.io just hacked the Canon imageCLASS MF654Cdw at #Pwn2Own. They head off to the disclosure room once more to provide the details of their exploit. #P2OIreland 052
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025Confirmed! Team @neodyme.io used three bugs to exploit the Amazon Smart plug. In doing so, they earn themselves $20,000 and 2 Master of Pwn points. #Pwn2Own 011
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025Success! We had a little configuration confusion, but Team Neodyme hopped for joy as their exploit of the Amazon Smart Plug was successful. Their attack went over Bluetooth & WiFI, so they used the RF enclosure. They head off to the disclosure room with details. #Pwn2Own 011
Neodyme @neodyme.io · 22/10/2025Shout-out to our colleagues at #Pwn2Own in Cork: www.youtube.com/watch?v=e20D...youtube.comFrom Pwn2Own Ireland 2025: NEODYME VS HPYouTube video by Trend Zero Day Initiative 000
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025📢 Confirmed: Team Neodyme used 2 bugs to exploit the Home Assistant Green, but only 1 was unique. They still earn $15,000 and 3 Master of Pwn points. #Pwn2Own 021
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 22/10/2025🏠 Well that was quick. Team Neodyme needed only one second to demonstrate their exploit of the Home Automation Green. We know they took their time creating the exploit, but wasted no time showing it off. The head off to the disclosure room to dish the deets. #Pwn2Own 011
Neodyme @neodyme.io · 21/10/2025While our colleagues hack live at #Pwn2Own in Cork, take a look at our newly published last year's writeup on our blog: We compromised a QNAP router to take over a networked Canon printer. ▶️ Read the findings and how we got there: neodyme.io/en/blog/pwn2...neodyme.ioPwn2Own Ireland 2024: QNAP Qhora-322In 2024, we competed as team Neodyme in the Pwn2Own Ireland contest, targeting the "SOHO Smashup" category and all available printers. For our entry, we focused on the QNAP QHora-322 router, successfu... 000
Reposted by NeodymeTrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025Our first confirmation of #Pwn2Own Ireland is in! Team Neodyme used a stack based buffer overflow to exploit the HP DeskJet 2855e. They earn $20,000 and 2 Master of Pwn points. #P2OIreland 031
Neodyme @neodyme.io · 17/10/2025Heading to #hack_lu? 🔐 Our colleague Felipe will discuss how partial emulation and DFA can be used to study a legacy version of Widevine L3, Google's software-based DRM. ➡️ Dive into the past to strengthen future DRM security. 🗓️ Oct 23 at 2:15pm 2025.hack.lu/agenda/2025.hack.luAgendaAgenda - Hack.lu and CTI summit 2025 010
Neodyme @neodyme.io · 01/10/2025⚡️ Lenovo DCC contained an easy-to-exploit LPE: a weak ACL bug → local privilege escalation → full admin 🖥️👨💻 We break it down with reverse engineering, process tracing, & two exploit strategies. Read Part 1 of our deep dive: 👉 neodyme.io/de/blog/leno...neodyme.ioLenovo DCC: Part 1 - A simple ACL ExploitThe Lenovo Display Control Center (DCC), widely deployed in Windows enterprise environments, contained a critical local privilege escalation vulnerability enabling unauthorized elevation to administra... 000
Neodyme @neodyme.io · 16/09/2025▶️ We built a proof-of-concept post-quantum FIDO authenticator. It's phishing- AND quantum-resistant. ✅️ Bonus: it even outperforms Google's prototype. 👀 Full write-up here: neodyme.io/en/blog/pqc-...neodyme.ioBuilding Our Own Post-Quantum FIDO TokenWe have built our own FIDO2 token based on post-quantum crypto. Here is how. 010
Neodyme @neodyme.io · 05/09/2025☀️ Teamwork doesn't just happen at the desk. This week, our crew is in Mallorca, building ideas, strengthening bonds, and enjoying some well-deserved sunshine together. 🌴 Great collaboration comes from trust, connection, and a shared good vibe ✨ 000
Neodyme @neodyme.io · 13/08/2025Back from @blackhatevents.bsky.social & @defcon.bsky.social! 🎉 Our colleagues delivered insightful trainings on crypto hacking and binary exploitation and got amazing feedback from the crowd 🙌 Missed it? We offer tailored security trainings for companies too. Just reach out. 000
Neodyme @neodyme.io · 25/07/2025We reported a vulnerability in Parallels Client via the ZDI last year. 🔥 The issue (CVE-2025-6812) - now fixed: A privileged service searched for an OpenSSL config file in an unsecured location, enabling LPE. ➡️ Advisory here: neodyme.io/en/advisorie... ☂️ Patch your systems!neodyme.ioCVE-2025-6812 ‒ Parallels Client Local Privilege Escalation VulnerabilityThe AppServer service installed with Parallel Client searches for an OpenSSL config file in an unsecured location, which allowed low privileged users to escalate their privileges. 010
Neodyme @neodyme.io · 10/07/2025🔧✨ On our company retreat this week, we're diving into hardware and protocol hacking: fingerprint sensors, smart locks, drones and Bluetooth speakers. A great mix of hands-on research, creative exploration, and team bonding over board games! 🎲 021
Neodyme @neodyme.io · 03/07/2025🎤At 4pm today at the "Festival der Zukunft", our colleagues dive into: "Black Hat, White Hat, Cyberwar - Modern Attacks and Defense" From hacking-as-a-service to cyberwarfare, discover how attacks are evolving and what it means for digital defense. 🕵️♀️ Don't miss it! 020
Neodyme @neodyme.io · 02/07/2025Think your speech model is secure? It might be quietly leaking what it was trained on. In a new blog post, we explain membership inference attacks and why they matter for cyber security experts. 🔗 neodyme.io/en/blog/memb...neodyme.ioDid You Train on My Voice? Exploring Privacy Risks in ASRThis post explores a recent research paper on membership inference attacks targeting Automatic Speech Recognition (ASR) models. It breaks down how subtle signals like input perturbation and model loss... 052
Neodyme @neodyme.io · 23/06/2025Meet our colleagues at the "Festival der Zukunft" at Deutsches Museum in Munich. Don't miss our talk on July 3 at 4pm! Check it out here: www.1e9.community/festival-der... 010
Neodyme @neodyme.io · 06/06/2025🏆 Throwback to #Pwn2Own Toronto 2022: "Routers are just Linux boxes with antennas." So we treated one like it. At #Pwn2Own 2022, we turned a Netgear RAX30 into a stepping stone for a full LAN pivot. Story: neodyme.io/en/blog/pwn2...neodyme.ioYour router might be a security nightmare: Tales from Pwn2Own Toronto 2022Three years ago, Neodyme took aim the "SOHO Smashup" category at Pwn2Own Toronto 2022, targeting a Netgear RAX30 router and an HP M479fdw printer. We successfully gained remote code execution on both ... 051
Neodyme @neodyme.io · 28/05/2025Part 3 of our Riverguard series is out! We're looking under the hood at the "fuzzcases" Riverguard uses to catch real-world bugs in Solana smart contracts. Still shocked how often some of these pop up. Check it out 👉 neodyme.io/en/blog/rive...neodyme.ioRiverguard: Mutation Rules for Finding VulnerabilitiesRiverguard, the first line of defense for all Solana contracts 010
Neodyme @neodyme.io · 28/05/2025Once again this year, a few colleagues couldn’t resist jumping into the HTB CTF to take on experts from around the world. 💻 A great challenge with a wide range of categories. The result: 1st place in 🇩🇪 and top 3 in 🇪🇺. 000
Neodyme @neodyme.io · 22/05/2025At #Pwn2Own Ireland 2024, we successfully targeted the SOHO Smashup category. 🖨️ Starting with a QNAP QHora-322 NAS, we pivoted to the Canon imageCLASS MF656Cdw - and ended up with shellcode execution. Read the full vulnerability deep dive here 👉 neodyme.io/en/blog/pwn2...neodyme.ioPwn2Own Ireland 2024: Canon imageCLASS MF656CdwThis blogpost starts a series about various exploits at Pwn2Own 2024 Ireland (Cork). This and the upcoming posts will detail our research methodology and journey in exploiting different devices. We st... 032
Neodyme @neodyme.io · 17/05/2025Day 2 at OffensiveCon has just started and our colleagues Kolja Grassmann and Alain Rödel are right in the middle of it! 🔥 Can't wait to hear the insights they bring back from some of the sharpest minds in offensive security. If you're there too, make sure to say hi! 010
Neodyme @neodyme.io · 02/05/2025From iframes and file reads to full RCE. 🔥 We found an HTML-to-PDF API allowing file reads and SSRF - then chained it into remote code execution via a Chromium 62 WebView exploit. 👉 Read the full write-up here: neodyme.io/en/blog/html...neodyme.ioHTML to PDF Renderer: A tale of local file access and shellcode executionIn a recent engagement, we found an HTML to PDF converter API endpoint that allowed us to list local directories and files on a remote server. One of the PDF files we created, revealed that the conver... 033
Neodyme @neodyme.io · 29/04/2025Sign up here: training.defcon.org/collections/...training.defcon.orgKolja and Felipe - Binary Exploitation on Windows - DCTLV2025 **4-Day Training****Please note: This is a four-day training that will be held Saturday-Tuesday (August 9-12). Participants will receive DEF CON Human Badge with their registration** Name of Training: Binary Exploitati... 000
Neodyme @neodyme.io · 29/04/2025Interested in learning about Windows exploitation? This August, join us in Las Vegas for an intensive, hands-on 4-day DEFCON training: Binary Exploitation on Windows, led by Felipe and Kolja! 🗓️ When: August 9–12, 2025 📍 Where: Las Vegas Convention Center 111
Neodyme @neodyme.io · 26/02/2025Wrapping up our COM hijacking series! 🎉 In the final part, we discuss a custom IPC protocol, use a registry write to gain SYSTEM privileges, and explore Denial of Service attacks on security products. 💥💻 Don't miss it! neodyme.io/en/blog/com_...neodyme.ioThe Key to COMpromise - Writing to the Registry (again), Part 4In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r... 022
Neodyme @neodyme.io · 12/02/2025🔎 Digging deeper into COM hijacking! In Part 3, we explore two new vulnerabilities: 🗑️ Webroot Endpoint Protect (CVE-2023-7241) – SYSTEM via arbitrary file deletion 📥 Checkpoint Harmony (CVE-2024-24912) – SYSTEM via a file download primitive Read more: neodyme.io/en/blog/com_...neodyme.ioThe Key to COMpromise - Downloading a SYSTEM shell, Part 3In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r... 011
Neodyme @neodyme.io · 05/02/2025🪝Introducing HyperHook! 🪝 A harnessing framework for snapshot-based #fuzzing using Nyx. ⚒️ HyperHook simplifies guest-to-host communication & automates repetitive tasks, making snapshot-fuzzing easier & more efficient! 🔗 Read more: neodyme.io/en/blog/hype...neodyme.ioIntroducing HyperHook: A harnessing framework for NyxIn this post, we introduce HyperHook, a harnessing framework for snapshot-based fuzzing for user-space applications using Nyx. HyperHook simplifies guest-to-host communication and automates repetitive... 033
Neodyme @neodyme.io · 29/01/2025🔎Part 2 of our COM hijacking series is live! This time, we discuss a vulnerability in AVG Internet Security, where we bypass an allow-list, disable self-protection, and exploit an update mechanism to escalate privileges to SYSTEM 🚀💻 neodyme.io/en/blog/com_...neodyme.ioThe Key to COMpromise - Abusing a TOCTOU race to gain SYSTEM, Part 2In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r... 052
Neodyme @neodyme.io · 17/01/2025From startups to large companies, we've seen this setup used by many corporate clients in the wild. Here's why this is so difficult to fix and Microsoft has not changed the exploitable default settings yet: neodyme.io/blog/bitlock...neodyme.ioOn Secure Boot, TPMs, SBAT, and downgrades -- Why Microsoft hasn't fixed BitLocker yetOn Secure Boot, TPMs, SBAT and Downgrades -- Why Microsoft hasn't fixed BitLocker yet 032
Neodyme @neodyme.io · 17/01/2025Your laptop was stolen. It’s running Windows 11, fully up-to-date, device encryption (BitLocker) and Secure Boot enabled. Your data is safe, right? Think again! This software-only attack grabs your encryption key. Following up on our #38C3 talk: neodyme.io/blog/bitlock...neodyme.ioWindows BitLocker -- Screwed without a ScrewdriverBreaking up-to-date Windows 11 BitLocker encryption -- on-device but software-only 142
Neodyme @neodyme.io · 15/01/2025Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog series! 🎊 Check out our first blog post on our journey to 💥 exploit five reputable security products to gain privileges via COM hijacking: neodyme.io/blog/com_hij...neodyme.ioThe Key to COMpromise - Pwning AVs and EDRs by Hijacking COM Interfaces, Part 1In this series of blog posts, we cover how we could exploit five reputable security products to gain SYSTEM privileges with COM hijacking. If you've never heard of this, no worries. We introduce all r... 055
Neodyme @neodyme.io · 27/12/2024cfp.cccv.de/38c3-communi...cfp.cccv.deWindows BitLocker: Screwed without a Screwdriver 38C3 Community StagesEver wondered how Cellebrite and law enforcement gain access to encrypted devices without knowing the password? In this talk, we’ll demonstrate how to bypass BitLocker encryption on a fully up-to-date... 010
Neodyme @neodyme.io · 27/12/2024cfp.cccv.de/38c3-communi...cfp.cccv.deDer Schlüssel zur COMpromittierung: Local Privilege Escalation Schwachstellen in AV/EDRs 38C3 Community StagesIm vergangenen Jahr wurden von uns in fünf kritische Schwachstellen in Endpoint Protection Software entdeckt, die es uns ermöglichen, auf Basis von COM-Hijacking unsere Privilegien auf Windows-Endpunk... 120
Neodyme @neodyme.io · 27/12/2024ND people are @ #38C3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YELL) and a not yet mitigated Bitlocker Flaw! (Saturday, 7:15 PM HUFF) 123
Neodyme @neodyme.io · 29/11/2024💥When security software itself becomes a target! 💥 Learn how we've uncovered critical vulnerabilities in Wazuh, turning a powerful security tool into an unexpected attack vector. 👉 Read more about the findings: neodyme.io/en/blog/wazu...neodyme.ioFrom Guardian to Gateway: The Hidden Risks of EDR VulnerabilitiesExplore the hidden risks within security software as we dive into vulnerabilities of Wazuh, a popular EDR solution. This post reveals how even trusted tools can become targets, highlighting the import... 022