SSD Secure Disclosure

SSD provides the quick and responsible way to get zero-day vulnerabilities reported to vendors.
Visit ssd-disclosure.com/ for more information.

2025-06-10

🚨 New advisory was just published! 🚨

ISPConfig contains design flaws in the user creation and editing functionality, which allow a client user to escalate their privileges to superadmin. Additionally, the language modification feature enables arbitrary PHP code injection due to improper input validation: ssd-disclosure.com/ssd-advisor

2025-06-05

Submit your pfSense, Sophos & KerioControl vulnerabilities at: ssd-disclosure.com/submit/

2025-05-31

🌪️ TyphoonCon 2025 has officially wrapped up and it was an incredible experience, all thanks to YOU!

Shoutout to our attendees, crew, and sponsors for bringing the energy and making it an unforgettable event!

:sparkles_red: Stay tuned... TyphoonCon 2026 is already in the works, and we can't wait to see you there!

2025-05-30

🌪️ Last but not least! Closing Remarks and TyphoonPWN winners with SSD Secure Disclosure's Aviram Jenik and Noam Rathaus

2025-05-30

🌪️ Closing the day with @scannell_simon desyncing the planet

2025-05-30

🌪️ Up next, Assaf Morag is unveiling the invisible pathways to breaching AWS accounts

2025-05-30

🌪️ SOS! Thai Nguyen & Chuong Nguyen are showing us how to discover and exploit 0-days from 1-days at scale

2025-05-30

🌪️ Now on stage, NeoTheone is showing us how to steal a drone!

2025-05-30

🌪️ Up next, we’re attacking debug modules in the Android ecosystem with Lewei Qu

2025-05-30

🌪️ Now on stage at TyphoonCon 2025: just having fun with binary polynomials with @arnaugamez

2025-05-30

🌪️ Starting day 2 with our keynote Phuong Nguyen and his wonderful talk about building a low profile elite hacking team!

2025-05-30

🌪️ Conference day 2 starts now. Get ready for another day of great talks!

2025-05-29

It looks like Kerio Control was PWNed with a Pre auth RCE! We're going through the exploit now to see everything works like it should #TyphoonCon25

2025-05-29

🌪️ Ending day one of #TyphoonCon25 with SeongJoon Cho’s Pwning shopping mall CMS

2025-05-29

🌪️ Tapping into the past @typhooncon with @rdjgr & Carlo Meijer’s RCE via Fax Machine!

2025-05-29

🌪️ Up next, Satoki Tsuji is explaining the hidden risks of URL protocol handler leaks

2025-05-29

🌪️ Now on stage, Boris Larin is diving into the crypto game of North Korea

2025-05-29

🌪️ Back from lunch just in time to escape VirtualBox and unchaining objects in the Windows Kernel with Corentin Bayet

2025-05-29

💻 A TyphoonPWN attempt! Another LG WebOS is being targeted

2025-05-29

💻 A TyphoonPWN attempt! ipTime is being targeted

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst