🦜 Zero Day Initiative - Blog
@www.thezdi.com.blog@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Your feed and you don't want it here? Just
e-mail the birb.
Pwn2Own Berlin 2025: Day One Results
https://www.thezdi.com/blog/2025/5/15/pwn2own-berlin-2025-day-one-results
Published: May 15, 2025 10:10
Welcome to the first day of Pwn2Own Berlin 2025! We have 11 different attempts, including our first ever AI attempts. We’ll be updating this blog with results as we have them.
SUCCESS - Pumpkin (@u1f383) from DEVCORE Research…
Pwn2Own Berlin: The Full Schedule
https://www.thezdi.com/blog/2025/5/14/pwn2own-berlin-the-full-schedule
Published: May 14, 2025 16:01
Willkommen and welcome to the inuaguaral Pwn2Own Berlin! Not only is this our first time at the OffensiveCon conference, but it’s also our first time including an AI category in the event. We’ve assembled some of the finest security researchers in the…
The May 2025 Security Update Review
https://www.thezdi.com/blog/2025/5/13/the-may-2025-security-update-review
Published: May 13, 2025 18:27
It’s the second Tuesday of the month, and the final patch Tuesday before Pwn2Own Berlin. I know several contestants are sweating it out and hoping their entries are patched out. While they quiver with anticipation, take a break from your scheduled…
CVE-2024-44236: Remote Code Execution vulnerability in Apple macOS
https://www.thezdi.com/blog/2025/5/7/cve-2024-44236-remote-code-execution-vulnerability-in-apple-macos
Published: May 7, 2025 18:30
In this excerpt of a Trend Vulnerability Research Service vulnerability report, Nikolai Skliarenko and Yazhi Wang of the Trend™ Research Team detail a recently patched code execution vulnerability in the Apple macOS operating system. This bug was…
The April 2025 Security Update Review
https://www.thezdi.com/blog/2025/4/8/the-april-2025-security-update-review
Published: April 8, 2025 18:14
It’s the second Tuesday of the month, and, as expected, Microsoft and Adobe have released their latest security offerings – all tariff free. Take a break from your scheduled activities and join us as we review the details of their latest security alerts.…
MindshaRE: Using Binary Ninja API to Detect Potential Use-After-Free Vulnerabilities
https://www.thezdi.com/blog/2025/3/20/mindshare-using-binary-ninja-api-to-detect-potential-use-after-free-vulnerabilities
Published: March 27, 2025 15:04
Use-after-free is a memory corruption condition where a program references memory after it has been released back to the allocator. Statically detecting these bugs can be challenging. In the past, several approaches have addressed this problem, such as…
Building an electric vehicle simulator to research EVSEs
https://www.thezdi.com/blog/2025/3/14/building-an-electric-vehicle-simulator-to-research-evses
Published: March 19, 2025 18:40
Researching and reverse engineering Level 2 Electric Vehicle Supply Equipment (EVSE or loosely “charger”) efforts might require the equipment to be placed beyond the idle state. The idle state is straightforward and usually involves nothing more than…
The March 2025 Security Update Review
https://www.thezdi.com/blog/2025/3/11/the-march-2025-security-update-review
Published: March 11, 2025 17:39
We’ve reached the third Patch Tuesday of 2025, and, as expected, Microsoft and Adobe have released their latest security offerings. Take a break from your scheduled activities and join us as we review the details of their latest security alerts. If you’d…
CVE-2024-43639: Remote Code Execution in Microsoft Windows KDC Proxy
https://www.thezdi.com/blog/2025/3/3/cve-2024-43639
Published: March 4, 2025 17:02
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Simon Humbert and Guy Lederfein of the Trend Micro Research Team detail a recently patched code execution vulnerability in the Microsoft Windows Key Distribution Center…
Announcing Pwn2Own Berlin and Introducing an AI Category
https://www.thezdi.com/blog/2025/2/24/announcing-pwn2own-berlin-2025
Published: February 24, 2025 16:45
If you just want to read the contest rules, click here.Willkommen, meine Damen und Herren, zu unserem ersten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). While the Pwn2Own competition started in Vancouver in 2007, we…