SSD Secure Disclosure @ssd-disclsoure.bsky.social · 1hGot research worth presenting on stage? TyphoonCon 2027 CFP is now open. We’re looking for original work in exploitation, vulnerability research, reverse engineering, mitigation bypass, cryptography, and AI-assisted security research. Seoul. May 27-28, 2027 Submit: typhooncon.com/call-for-pap... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 1hGot a security technique worth teaching? TyphoonCon 2027 Call for Training is open! We’re looking for advanced, hands-on courses in exploitation, vulnerability research, reverse engineering, AI-assisted security research, and more. Seoul. May 23–26, 2027. Submit: typhooncon.com/call-for-tra... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 10/09/2026🚨 New advisory was just published! Learn how a heap buffer overflow in a Windows DCOM service can be leveraged to escalate privileges from a Medium IL standard user to SYSTEM IL: ssd-disclosure.com/dcom-service...ssd-disclosure.comDCOM Service PsmServiceExtHost LPE - SSD Secure DisclosureSummary Threre is a heap buffer overflow vulnerability in a DCOM service that can be leveraged to achieve LPE from a Medium IL standard user to System IL. This was tested on Windows 11 25H2 Build 2620... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 17/08/2026🚨 New advisory was just published! A critical vulnerability in UNISOC modem firmware allows an attacker to disable protections on the first MPU region which could lead to arbitrary code execution with kernel privileges, including modification of kernel code: ssd-disclosure.com/unisoc-t612-...ssd-disclosure.comUNISOC T612 LPE - SSD Secure DisclosureSummary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device ... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 13/08/2026Did you read our latest publication: ssd-disclosure.com/linux-bridge... We are actively looking for Linux vulnerability research. You focus on the research. We handle the rest. Learn more at ssd-disclosure.com/product-index/ssd-disclosure.comLinux Bridge STP Timer Use-After-Free - SSD Secure DisclosureSummary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 05/08/2026🚨 New advisory was just published! 2 independent security researchers discovered and submitted a use-after-free vulnerability in the Linux kernel's Bridge STP implementation during TyphoonPWN 2026 and won 2nd place. Read our full advisory: ssd-disclosure.com/linux-bridge...ssd-disclosure.comLinux Bridge STP Timer Use-After-Free - SSD Secure DisclosureSummary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 27/07/2026🚨 New advisory was just published! An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server: ssd-disclosure.com/vbulletin-ru...ssd-disclosure.comvBulletin Runtime Template runMaths Preauth RCE - SSD Secure DisclosureSummary A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. Vendor Response ... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 25/06/2026Our latest advisory covers the technical details, exploitation path, and remediation guidance: ssd-disclosure.com/cisco-unifie... If you've discovered a vulnerability and are looking for a trusted disclosure partner, DM or email us at contact@ssd-disclosure.com for more information.ssd-disclosure.comCisco Unified Communications Manager Arbitrary File Write to RCE - SSD Secure DisclosureSummary A vulnerability in Cisco Unified Communications Manager (CUCM) allows unauthenticated attackers to arbitrarily write files in the server which in turn can be used to run arbitrary commands/cod... 010
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 23/06/2026🚨 New advisory was just published! A vulnerability in Cisco Unified Communications Manager allows unauthenticated attackers to arbitrarily write files in the server which could be used to run arbitrary commands or code on the server: ssd-disclosure.com/cisco-unifie...ssd-disclosure.comCisco Unified Communications Manager Arbitrary File Write to RCE - SSD Secure DisclosureSummary A vulnerability in Cisco Unified Communications Manager (CUCM) allows unauthenticated attackers to arbitrarily write files in the server which in turn can be used to run arbitrary commands/cod... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 15/06/2026In our new article, we examine a high-severity TOCTOU bug between Blink and V8's WebAssembly compiler that allowed a benign module to pass validation while a malicious one was compiled. This resulted in renderer RCE without requiring a V8 sandbox escape: ssd-disclosure.com/readablestre...ssd-disclosure.comReadableStream TOCTOU: V8 Sandbox Bypass via Wasm Streaming - SSD Secure DisclosureSummary Issue 433533359 is a TOCTOU data race between Blink’s ReadableStream consumer pipeline and V8’s WebAssembly streaming compiler. A renderer-controlled SharedArrayBuffer(SAB) mutated by a worker... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 12/05/2026🚨 New advisory was just published! A pre-auth remote code execution vulnerability was found in the CWMP implementation of ipTIME routers, allowing unauthenticated attackers to execute arbitrary code remotely: ssd-disclosure.com/iptime-pre-a...ssd-disclosure.comipTIME Pre-Auth RCE in CWMP - SSD Secure DisclosureSummary An unauthenticated attacker can remotely execute arbitrary code via the CWMP protocol on the ipTIME router. Vendor Response We have tried to reach out to the vendor through multiple channels (... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 11/05/2026All 20 seats for “Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research” training have been SOLD OUT! ⚡ Only a few spots remaining for: * Automated Reverse Engineering * Hacking the Satellite * QEMU Internals from IoT to iPhone (Fuzzing) www.eventbrite.com/e/1968561639...eventbrite.comTyphoonCon 2026TyphoonCon is an all Offensive Security Training & Conference focused on offensive security, vulnerability discovery and reverse engineering 010
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 29/04/2026Want to know how a “small” WebAssembly issue can become a big security problem? In our new article, SSD Labs researcher, Aaron Cho, analyzes CVE-2024-12053. An arbitrary WebAssembly type confusion vulnerability leading to an RCE. Read about it here: ssd-disclosure.com/webassembly-...ssd-disclosure.comWebAssembly Canonical vs. Relative Type Index Confusion Leading to RCE - SSD Secure DisclosureSummary CVE -2024 -12053 is an arbitrary WebAssembly type confusion vulnerability stemming from a mix-up between the canonical and relative indices of WebAssembly types. The Chromium team noted that t... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 15/04/2026The full TyphoonCon 2026 conference agenda is now live: typhooncon.com/full-2026-ag... Join us May 28-29 in Seoul for a highly curated program focused on advanced offensive security. From vulnerability research to real-world exploitation. 🎟️ Tickets are going fast - secure your spot now 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 26/03/2026Explore the offensive side of space systems with Romel Marin at TyphoonCon 2026! See how flaws in space protocols enable RF interception, telemetry abuse, replay attacks, and even command injection from orbit: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 24/03/2026Yuanzhen Xu will present at TyphoonCon 2026! Join us as we expose hidden attack paths in ClickHouse - from JDBC components to memshell and RASP evasion: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 23/03/2026LSASS under the microscope at TyphoonCon 2026! Erik Egsgard joins our lineup to uncover how even Windows’ most protected process can be turned into an attack surface: typhooncon.com/2026-agenda/ 031
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 23/03/2026Lidor Ben Shitrit is bringing cloud & Java exploitation to TyphoonCon 2026! “Pre-auth RCE in Enterprise Java” dives into real-world middleware attack paths. Register at: typhooncon.com/2026-agenda/ 010
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 22/03/2026Don’t miss Connor Du Plooy at TyphoonCon 2026! “Terminally Bad Credit” dives into rooting, skimming, and hijacking mobile card machines. Read more and get your tickets at: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 18/03/2026Kirils Solovjovs takes the stage at TyphoonCon 2026! He’ll dive into reverse engineering the DUOX PLUS intercom system exposing protocol flaws and demonstrating MITM, spoofing, and signal manipulation using simple hardware tools. typhooncon.com/2026-agenda 001
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 18/03/2026Alexander Kozlov & Sergey Anufrienko are joining TyphoonCon 2026! They’ll showcase real-world automotive vulnerabilities: from SMS to cloud attacks and what it means for vehicle security. Don’t miss it: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 16/03/2026Aryan Jogia joins the TyphoonCon 2026 lineup. In his talk, Aryan will explore how attackers can leverage Windows’ own architecture to dismantle modern security tools from userland hooks all the way down to the kernel. ♟💻 typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 16/03/2026Nicola Stauffer and Gürkan Gür will be part of the TyphoonCon 2026 lineup! In their talk they’ll show how exploiting the firmware of MediaTek’s Wi-Fi 7 MT7925 chip can lead to a full Windows 11 privilege-escalation chain bridging userspace, firmware, and the Windows kernel. 001
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 12/03/2026We’re excited to welcome Dr. Bramwell Brizendine to TyphoonCon 2026! In this talk, Dr. Bramwell will explore how ROP techniques can generate multiple highly reliable ASLR bypasses against essential Windows system DLLs. Learn more and get your tickets at: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 12/03/2026We’re excited to welcome Ron Ben Yizhak as a speaker at TyphoonCon 2026! Ron will present his research on how a low-privileged process can masquerade as a trusted RPC server leading to the discovery of two Microsoft vulnerabilities. Read more at typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 11/03/2026🚨 New advisory was just published! A critical vulnerability in UNISOC modem firmware allows one User Equipment (UE) to remotely attack another over the cellular network: ssd-disclosure.com/unisoc-t612-...ssd-disclosure.comUNISOC T612 RCE - SSD Secure DisclosureSummary UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device ... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 10/03/2026Cyber operations have become a core element of modern warfare and Allie Mellen will break it down as a keynote speaker at TyphoonCon 2026! Her talk examines how cyber capabilities have reshaped military strategy and coordination across decades: typhooncon.com/2026-agenda/ 🚀 010
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 10/03/2026We’re excited to welcome Sammy Azdoufal as a keynote speaker! Sammy will share his research on uncovering a critical cloud vulnerability that exposed thousands of connected devices worldwide to remote takeover. typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 27/02/2026TyphoonCon 2026 Training #5 is now open: Automated Reverse Engineering by Kyle Martin! Learn more and register: typhooncon.com/2026-agenda/ 010
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 26/02/2026TyphoonCon 2026 Training #4 has just dropped! Deep Dive into Android Binder by Tiana Razafindralambo. Explore the session: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 26/02/2026In our latest article, we break down two critical Android GPU driver vulnerabilities that enabled Chrome sandbox escape from a compromised renderer and were used in full device exploit chains. Read the full technical analysis here: ssd-disclosure.com/chrome-gpu-s...ssd-disclosure.comChrome GPU Sandbox Escape via Qualcomm Adreno and ARM Mali GPU Drivers - SSD Secure DisclosureSummary Google’s Threat Analysis Group (TAG) recently discovered two critical vulnerabilities in Android GPU drivers being actively exploited in the wild. Both bugs enable Chrome sandbox escape when e... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 23/02/2026Last call for TyphoonCon 2026 CFP🌪️ This is your final week to secure your spot at the best all-offensive security conference in Asia! Submit now at: typhooncon.com/call-for-pap...typhooncon.comCall for Papers 2026 – TyphoonCon 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 18/02/2026SSD Secure Disclosure is now on WIRE Ask questions, validate findings, consult on exploitability or research direction — and get real answers, quickly. Add us on WIRE: @ssdcontact 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 16/02/2026🚨 New advisory was just published! Source code review of the Novarain/Tassos framework uncovered 3 critical primitives. Chained together these bugs allow reliable RCE and administrator account takeover on unpatched Joomla! Instances: ssd-disclosure.com/joomla-novar...ssd-disclosure.comJoomla! Novarain/Tassos Framework Vulnerabilities - SSD Secure DisclosureSummary Source code review of the Novarain/Tassos Framework revealed three critical primitives – unauthenticated file read, unauthenticated file deletion, and SQL injection leading to arbitrary databa... 011
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 13/02/2026TyphoonCon 2026 Training #3 is live: Hacking the satellite: Offensive Cyber Security Operations in Aerospace Technology & Satellites by Romel Marin & Kevin Leon: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 12/02/2026We’re excited to announce the first confirmed speaker for TyphoonCon 2026! João Pedro (aka Tricta) will be joining us in Seoul to share insights, research, and real-world experience in The Age of Zygote Injection talk. typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 12/02/2026 TyphoonCon 2026 Training #2 is live: Fuzzing Against the Machine: QEMU Internals from Iot to Iphone by Antonio Nappa & Eduardo Blázquez: typhooncon.com/2026-agenda/ 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 05/02/2026🚨 New advisory was just published! A flaw that exists within the handling of sch_cake can allow a local user under the CentOS 9 to trigger an UAF. This can be leveraged to escalate privileges and execute arbitrary code in the context of root: ssd-disclosure.com/linux-kernel...ssd-disclosure.comLinux Kernel net/sched CAKE Qdisc Use-After-Free LPE - SSD Secure DisclosureSummary A local user under the CentOS 9 operating system can trigger an use-after-free, which in turn can be used to elevate to root privileges. Vendor Response The vendor has been notified more than ... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 01/02/2026🌪️ Early bird tickets are sold out! If you missed your chance, no worries - regular tickets are still up for grabs, but they’re going quickly: www.eventbrite.com/e/typhooncon...eventbrite.comTyphoonCon 2026TyphoonCon is an all Offensive Security Training & Conference focused on offensive security, vulnerability discovery and reverse engineering 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 29/01/2026🚨 New advisory was just published! 🚨 Three new post auth vulnerabilities have been found in ISPConfig. These vulnerabilities allow attackers who have either Reseller or Client accounts to escalate to root level access via backup restore/download symlink abuse: ssd-disclosure.com/ispconfig-mu...ssd-disclosure.comISPConfig Multiple Post Auth Privilege Escalation Vulnerabilities - SSD Secure DisclosureSummary Three post authentication vulnerabilities have been found in ISPConfig, these vulnerabilities allow attackers who are either a Reseller or Client account to escalate to root level access. Vend... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 20/01/2026Excited to announce our first TyphoonCon 2026 training! "Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research" by Omri Ben-Bassat & Vladimir Tokarev typhooncon.com/exploiting-1... Stay tuned for more! 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 15/01/2026The CFT for TyphoonCon 2026 remains open, with only a few slots left. We invite trainers with innovative offensive security workshops to apply and join Asia’s leading security conference! Submit your training now: typhooncon.com/call-for-tra...typhooncon.comCall for Training 2026 – TyphoonCon 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 10/01/2026TyphoonCon 2026이 오는 5월 25일부터 29일까지 서울에서 개최됩니다! 현재 컨퍼런스 발표자 및 트레이닝 진행자를 모집 중입니다. 2026년 연사 라인업에 합류하고 싶으신가요? 아래 링크에서 Call for Papers & Trainings에 대한 자세한 내용을 확인해보세요. Call for training: typhooncon.com/call-for-tra... Call for papers: typhooncon.com/call-for-pap...typhooncon.comCall for Training 2026 – TyphoonCon 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 01/01/2026🌪️ TyphoonCon 2026 Early Bird tickets now on sale! Dive into exploits, reverse engineering and cutting-edge insights in offensive security. May 28-29 in Seoul, South Korea. 🎟️ Limited tickets available: www.eventbrite.com/e/typhooncon...eventbrite.comTyphoonCon 2026TyphoonCon is an all Offensive Security Training & Conference focused on offensive security, vulnerability discovery and reverse engineering 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 17/12/2025🚨 New advisory was just published! 🚨 CVE-2025-55681 - A new Desktop Window Manager LPE: ssd-disclosure.com/desktop-wind...ssd-disclosure.comDesktop Window Manager Array Out Of Bounds LPE - SSD Secure DisclosureVendor Response The vendor has released a patch for Windows that addresses this vulnerability: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55681 CVE CVE-2025-55681 Credit The vulner... 000
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 11/11/2025🌪️TyphoonCon 2026 CFP & CFT are live & our inbox is filling up. Ready to share your research or lead a deep-dive course in Seoul next year? CFT: typhooncon.com/call-for-tra... CFP: typhooncon.com/call-for-pap...typhooncon.comCall for Training 2026 – TyphoonCon 000