Attacking Browser Extensions and CyberPanel
Day[0] - A podcast by dayzerosec
Categories:
In this week's episode, we talk a little bit about LLMs and how they can be used with static analysis. We also cover GitHub Security Blog's post on attacking browser extensions, as well as a somewhat controversial CyberPanel Pre-Auth RCE that was disclosed. Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/261.html [00:00:00] Introduction [00:01:56] Autonomous Discovery of Critical Zero-Days [00:14:43] Attacking browser extensions [00:25:26] What Are My OPTIONS? CyberPanel v2.3.6 pre-auth RCE [00:52:15] Security research on Private Cloud Compute [01:01:02] Bluetooth Low Energy GATT Fuzzing Podcast episodes are available on the usual podcast platforms: -- Apple Podcasts: https://podcasts.apple.com/us/podcast/id1484046063 -- Spotify: https://open.spotify.com/show/4NKCxk8aPEuEFuHsEQ9Tdt -- Google Podcasts: https://www.google.com/podcasts?feed=aHR0cHM6Ly9hbmNob3IuZm0vcy9hMTIxYTI0L3BvZGNhc3QvcnNz -- Other audio platforms can be found at https://anchor.fm/dayzerosec You can also join our discord: https://discord.gg/daTxTK9