Natalie Silvanovich
@natashenka.bsky.social
đ€ 584
đ„ 183
đ 34
Google Project Zero
Super cool potential ASLR leak involving dictionary hashes!
googleprojectzero.blogspot.com/2025/09/poin...
loading . . .
Pointer leaks through pointer-keyed data structures
Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...
https://googleprojectzero.blogspot.com/2025/09/pointer-leaks-through-pointer-keyed.html
4 days ago
0
10
6
fseek and you shall lfind
15 days ago
0
1
0
reposted by
Natalie Silvanovich
Lorenzo Franceschi-Bicchierai
about 2 months ago
Zero-day developer and seller Exodus casually brags in a blog post about having found a WebKit zero-day and sold it for a year and a half.
blog.exodusintel.com/2025/08/04/o...
Clément Lecigne and Benoßt Sevens of Google's Threat Analysis Group were the ones that reported it to Apple.
1
21
10
Left blue, right red
#defcon
about 2 months ago
0
3
0
How to use your Defcon badge
about 2 months ago
1
4
1
âYou wouldnât happen to have anything that could help me understand todayâs ever-changing threat landscape? Perhaps involving a bit of AI?â
about 2 months ago
0
3
1
Peak BH slide
about 2 months ago
0
1
0
Do you ever feel like maybe you should sign something, but arenât quite sure you can follow through?
about 2 months ago
0
4
0
We also posted our first Transparency Report
googleprojectzero.blogspot.com/p/reporting-...
loading . . .
Reporting Transparency
As part of our 2025 Policy Trial , Project Zero will use this page to publicly track our Reporting Transparency effort. The trial commenced ...
https://googleprojectzero.blogspot.com/p/reporting-transparency.html
2 months ago
0
3
1
While most vendors ship timely patches for vulnerabilities reported by Project Zero, they donât always reach users. Today, weâre announcing Reporting Transparency, a new policy to encourage downstream fixes
googleprojectzero.blogspot.com/2025/07/repo...
loading . . .
Policy and Disclosure: 2025 Edition
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...
https://googleprojectzero.blogspot.com/2025/07/reporting-transparency.html
2 months ago
1
6
9
reposted by
Natalie Silvanovich
Microplastics Sommelier
2 months ago
maybe there's still some good left in this world after all
loading . . .
317
17238
4901
The new Tamagotchi Switch game has rap battles where the Tamas rap about how they respect and enjoy each othersâ unique differences
3 months ago
0
3
0
reposted by
Natalie Silvanovich
lukelukeluke
3 months ago
Inventor of the GIF, hearing about Notre Dame burning: oh no the jarjoyles
73
5342
1260
reposted by
Natalie Silvanovich
Dr. Jen Gunter
3 months ago
I accidentally closed a browser yesterday with 72 VERY IMPORTANT TABS that have been following me around like Jacob Marley and somehow my history is not recoverable. Reader, I let them go, and have lived to tell the tale.
30
432
14
At least 3 miles of protesters along El Camino in Sunnyvale
4 months ago
1
6
0
I Googled âhow to shorten a chain,â and got no good answers, so hereâs the answer, hereâs how you temporarily shorten it
4 months ago
0
1
0
reposted by
Natalie Silvanovich
Pookleblinky
4 months ago
www.ibiblio.org/harris/500mi...
You might be one of the lucky people to learn today about an emailing bug that turned out to be caused by the speed of light.
loading . . .
The case of the 500-mile email
https://www.ibiblio.org/harris/500milemail.html
2
43
16
If thereâs one thing Iâve learned, itâs that tab completion is never âjust broken todayâ
4 months ago
0
0
0
4 months ago
0
2
0
If $106,050.10 was the size of a quarter, it would fit in 424,200.4 fewer shipping containers than âŠ
4 months ago
0
0
0
The world never says hello back
4 months ago
2
8
2
The final part of Mateuszâs Windows Registry series is live! Contains all the hive memory corruption exploitation youâve been waiting for
googleprojectzero.blogspot.com/2025/05/the-...
loading . . .
The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
Posted by Mateusz Jurczyk, Google Project Zero In the previous blog post , we focused on the general security analysis of the registry a...
https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-8-exploitation.html
4 months ago
0
6
4
reposted by
Natalie Silvanovich
DistrictCon
4 months ago
đš CALLING ALL VULNERABILITY RESEARCHERS đš The Junkyard is officially open! This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs! Prizes range from $100 to $5,000 for categories like: âïž Most Impactful System đŸ Best Meme Target đ Most Engaging Presentation
1
20
18
Movie you've watched more than 1000 times using gifs. ("Hard mode" no Star Wars, Star Trek, or LoTR)
add a skeleton here at some point
5 months ago
0
1
0
Should be a Canada goose
5 months ago
0
2
0
reposted by
Natalie Silvanovich
RE//verse
6 months ago
Another must-watch talk from RE//verse 2025 is live! Zion Basque challenges decompilers to step up their game and introduces a roadmap for a practical solution to solve some of the trickiest compiler behavior's to analyze. Check it out here:
loading . . .
RE//verse 2025: Buccaneers of the Binary (Zion Basque)
Full Title: Buccaneers of the Binary: Plundering Compiler Optimizations for Decompilation Treasure. Zion's talk is both a challenge for decompilers to step up ...
https://youtu.be/VP29biKLoSw
0
7
2
7 months ago
1
5
0
Comment 6: I donât know, ask Past Natalie
7 months ago
0
4
0
reposted by
Natalie Silvanovich
Wes Miller
8 months ago
I know, Word. "syncable" isn't a word. But the dictionary is powerless against Microsoft.
0
2
2
You wouldnât download an orange tree
8 months ago
1
4
2
Not correct, yet a strange window into my soul
8 months ago
0
0
0
reposted by
Natalie Silvanovich
Alt National Park Service
8 months ago
551
60319
14116
reposted by
Natalie Silvanovich
evacide
8 months ago
tl;dr WhatsApp fixed the vuln on the back end, so you don't need to do anything to your phone, up to and including enabling Lockdown mode. Paragon Solutions sucks and you should be mad at them for enabling spying on civil society.
www.theguardian.com/technology/2...
loading . . .
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had âhigh confidenceâ some users were targeted and âpossibly compromisedâ by Paragon Solutions spyware
https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware
4
125
50
reposted by
Natalie Silvanovich
James Forshaw
8 months ago
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process.
googleprojectzero.blogspot.com/2025/01/wind...
loading . . .
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html
2
65
41
reposted by
Natalie Silvanovich
Azeria
9 months ago
Killer lineup! Canât wait to attend. If you are into reverse engineering, check out the new Re-Verse conference, launching in February! The team behind it is incredible. This is going to be the new Infiltrate.
add a skeleton here at some point
0
12
4
reposted by
Natalie Silvanovich
RE//verse
9 months ago
We're pleased to announce Natalie Silvanovich
@natashenka.bsky.social
as the keynote speaker for the inaugural RE//verse. She might have started out hacking Tamagotchis, but she certainly didn't stop there!
1
17
9
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium.org/issues/36869...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/368695689
9 months ago
1
38
18
reposted by
Natalie Silvanovich
Steve Klabnik
9 months ago
WARNING: This product contains programming languages known to the State of California to cause memory unsafety
64
3486
258
Project Zero is hiring đ Please share with anyone you think would be great for the team
www.google.com/about/career...
loading . . .
Senior Security Engineer, Security Research â Google Careers
https://www.google.com/about/careers/applications/jobs/results/112297012816159430/
9 months ago
0
12
10
This Justin: Canadian PM resigns. Not sure if Trudeau
9 months ago
0
1
1
reposted by
Natalie Silvanovich
Adam J.B. Lane
9 months ago
Another masterwork by courtroom sketch artist Jane Rosenberg, whose piercing documentation of Rudy Giuliani's descent into madness is one of the most exciting things going on right now in American art.
59
3019
618
Oh look, itâs the consistent use of tabs and spaces police
9 months ago
0
0
0
reposted by
Natalie Silvanovich
Ken Shirriff
10 months ago
I recently saw an amazing Navajo rug at the National Gallery of Art. It looks abstract at first, but it is a detailed representation of the Intel Pentium processor. Called "Replica of a Chip", it was created in 1994 by Marilou Schultz, a Navajo/Diné weaver and math teacher. 1/n
33
2850
962
reposted by
Natalie Silvanovich
Katie Moussouris (she/her/she-hulk/she-ra)đ»
10 months ago
I thought everyone knew not to shine lasers at anything in the sky this time of year due to the chance of blinding a reindeer
3
92
7
Can you find an ITW 0-day from crash logs? Project Zero finds out
googleprojectzero.blogspot.com/2024/12/qual...
loading . . .
The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
Posted by Seth Jenkins, Google Project Zero This blog post provides a technical analysis of exploit artifacts provided to us by Google's Thr...
https://googleprojectzero.blogspot.com/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html
10 months ago
0
15
7
TIL there is a herd of 500,000 caribou in Alaska. They know this because Fish and Wildlife stitches together arial photos, like you would when imaging a silicon die. Then a guy named Don Williams counts them all
www.adfg.alaska.gov/index.cfm?ad...
loading . . .
Alaska's Largest Caribou Herd Grows, Alaska Department of Fish and Game
Alaska Wildlife News is an online magazine published by the Alaska Department of Fish and Game
https://www.adfg.alaska.gov/index.cfm?adfg=wildlifenews.view_article&articles_id=15
10 months ago
0
1
0
reposted by
Natalie Silvanovich
James Forshaw
10 months ago
A companion blog to my Bluehat 2024 presentation on OleView.NET is up now.
googleprojectzero.blogspot.com/2024/12/wind...
loading . . .
https://googleprojectzero.blogspot.com/2024/12/windows-tooling-updates-oleviewnet.htm
0
20
13
you reached the end!!
feeds!
log in