
Zhenpeng (Leo) Lin
@Markak_ • 3,549 subscribers
AI x Security @depthfirstlabs, Ph.D., CTF player @Nu1L_team, now @StrawHat_CTF. #Pwn2Own winner. Author of #DirtyCred #Badiouring
Shorts
Videos

Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!). F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at depthfirst caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.
Zhenpeng (Leo) Lin29,695 次观看 • 7 天前
没有更多内容可加载