Listen

Description

MD5 is trending in 2021...a few kernel vulnerabilities, and some drama around pwn2own.


[00:00:26] Update on git.php.net incident


[00:06:38] Pwn2Own 2021 - Results


[00:18:53] CSGO exploit allows hackers to steal passwords, and Valve hasn't fixed it


[00:26:20] I Built a TV That Plays All of Your Private YouTube Videos


[00:33:27] Leak of all accounts mail login md5 pass


[00:37:11] What if you could deposit money into your Betting account for free?


[00:41:41] Zero click vulnerability in Apple’s macOS Mail


[00:44:54] Stored XSS on the DuckDuckGo search results page


[00:49:13] Breaking GitHub Private Pages for $35k


[00:57:03] Royal Flush: Privilege Escalation Vulnerability in Azure Functions


[01:01:38] QNAP Pre-Auth CGI_Find_Parameter RCE


[01:04:14] Domain Time II Upgrade Attack


[01:07:12] Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel


[01:15:57] BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution


[01:28:05] BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution


[01:29:07] Exploiting Windows RPC to bypass CFG mitigation


[01:34:00] security things in Linux v5.9

Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)

Or the video archive on Youtube (@dayzerosec)