VUPEN Security

VUPEN Security

@VUPEN Worldwide
VUPEN is the leading provider of defensive & offensive cyber security intelligence for Govs. Company of the Year 2011 in the Vulnerability Research Market.
Text follow VUPEN to 40404 in the United States
»
VUPEN Security
We are proudly sponsoring CanSecWest 2012. Maybe we'll pwn IE+Chrome+Firefox+Safari at pwn2own or maybe we'll not
»
VUPEN Security
Microsoft fixed 8 vulns which could allow SafeSEH bypass, remote code execution and privilege escalation
»
VUPEN Security
Research Blog: Technical Analysis & Exploitation of ProFTPD Remote Use-after-free CVE-2011-4130 (Part I)
»
VUPEN Security
MS released an out-of-band security update MS11-100 for .NET Framework to fix the hash tables DoS & other flaws
»
VUPEN Security
A new DoS vuln involving hash tables & affecting many products was disclosed. More info published by our friends at MS
»
VUPEN Security
A untethered jailbreak for iOS 5.0.1 was released. It uses two exploits: one in Racoon and the other in kernel. Apple should react soon...
»
VUPEN Security
A critical remote root 0day vulnerability affecting FreeBSD telnetd is being exploited in the wild. Patch now!
»
VUPEN Security
We finished writing the tech. analysis and advanced exploitation (25 pages) of the ProFTPD Remote Use-After-Free vuln. Preparing blog now!
»
VUPEN Security
We added to our offensive exploits a new government-grade 0Day for IE 9/8/7/6 on Win7/Vista/XP with ASLR/Sandbox bypass
»
VUPEN Security
A critical double-free vuln was discovered in VLC media player when processing malformed TY files. Upgrade to v1.1.13
»
VUPEN Security
We successfully exploited the recent and amazing ProFTPD Remote Use-After-Free vuln. Full details on our blog soon
»
VUPEN Security
Acrobat/Reader v9.4.7 fixes the PDF U3D 0Day. Another PDF 0day (in PRC) was also in the wild. Acro X is unpatched
»
VUPEN Security
PuTTY (SSH client) keeps passwds in memory after authenticating to a srv, leading to pwd leakage. Upgrade to v0.62 asap
»
VUPEN Security
The 0-day vulnerability exploited by the PDF in the wild is caused by an uninitialized memory in the "rt3d.dll" (3D Runtime) module
»
VUPEN Security
Glad to see that blackhats still have their sense of humor. The PDF 0-day in the wild uses a crafted U3D labeled "a pwning u3d model"
»
Chaouki Bekrar VUPEN
The Adobe PDF 0-Day sample in the wild looks like it was targeting ManTech corp, a US Gov contractor, affiliated to Lockheed Martin
»
VUPEN Security
A zero-day exploit taking advantage of an Adobe PDF vulnerability is exploited in the wild in targeted attacks
»
VUPEN Security
Apple released Safari 5.1.2 with No security updates included, thus our 0-day exploits (Mac OS X / Win) work with no modification
»
VUPEN Security
We are a key sponsor of ISS World 2012 in Dubai. Access is restricted to Govs. We will show Government-grade zero-day exploits
»
VUPEN Security
RealPlayer v15 has been released to fix 19 critical flaws. If you're still using this player, update it or uninstall it