OMG. There was a heapdump endpoint?!
Around 20:15.
"We are currently clean on OPSEC: The Signalgate Saga"
From this morning: #DEFCON tidbits, US Pacer hack outs sealed arrests and witnesses, hackers infiltrate Google’s Gemini AI smart home functions via calendar invite, Reddit blocked Internet Archive, Meta surveilled period-tracker app users, and more:
https://www.patreon.com/posts/cybersecurity-12-136290025 #Cybersecurity
The talk from @micahflee at DEFCON 33 was amazing, and such important work right now!
If you haven't watch it already, I highly recommend it. Especially if you are American. You will not regret it
https://micahflee.com/we-are-currently-clean-on-opsec-the-signalgate-saga/
One of my highlights from last week is getting to meet @TindrasGrove - SO smart and fun to speak with and full of info and experience.
Mistodon: Happy Zero Cool day! This elite #PETSCII feline #hackercore badge art was designed by @littlebitspace and used at last year's #Defcon conference (this year's wraps today.) It was also included in the new cat-themed MIST0725 artpack collection.
DEF CON 33 is winding down now, and we want to take a moment to thank the whole DEF CON community for another amazing year. Thank you for bringing your boundless energy and curiosity to this little party we throw. Thank you for spending another long enchanted weekend teaching each other, learning from each other, and partying with each other.
It’s good to spend some time with your people.
As always, if you want to keep that DEF CON feeling going all year long, consider joining a DEF CON Group. If you can’t find one close to home, consider starting one. Join our Discord. Start a project you might want to share next year.
Thanks for sticking with us through the last few crazy years. Know that we’re already scheming how to make next year even better.
#retrotech and #badgelife - two great #defcon tastes that go great together.
The little scambait competition happening by the bathrooms in W1 is the closest I've come at this con to feeling OG Alexis Park vibes. That needs to be a village next year.
If you want a sticker, or if you just want to boop the Honey Bear Hard Hat’s nose, find me walking around #defcon!
DARPA touts value of AI-powered vulnerability detection as it announces competition winners https://www.cybersecuritydive.com/news/darpa-ai-cyber-challenge-winners-def-con/757252/ #cybersecurity #AI #VulnerbilityManagement #Discovery #Patching #DEFCON #DARPA
So when it's this easy to get a MITM going things like making posts in public chats as anyone you want feels kinda low key.
But I do hope that extended warranty works out, everyone seems pretty concerned about them.
Which brings me to part two, MeshMarauder.
An open source tool demonstrating proof-of-concept exploits against the DEFCON 33 Meshtastic firmware.
MeshMarauder will demostrate:
- Tracking user activity on any mesh regardless of encryption usage
- Hijack all meshtastic user profile metadata
- Change any users public key
- Send messages as any user in channel chats that appear authentic
- MITM direct messages