Natalie Silvanovich
@natashenka.bsky.social
š¤ 603
š„ 183
š 38
Google Project Zero
I love how my city sends me text message alerts when thereās the chance to see a sinkhole
1 day ago
0
0
0
New Blog Post: Seth Jenkins broke kASLR by doing ⦠nothing š©
googleprojectzero.blogspot.com/2025/11/defe...
loading . . .
Defeating KASLR by Doing Nothing at All
Posted by Seth Jenkins, Project Zero Introduction I've recently been researching Pixel kernel exploitation and as part of this research I ...
https://googleprojectzero.blogspot.com/2025/11/defeating-kaslr-by-doing-nothing-at-all.html
19 days ago
0
10
5
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click.
project-zero.issues.chromium.org/issues/42807...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/428075495
about 1 month ago
1
10
1
Super cool potential ASLR leak involving dictionary hashes!
googleprojectzero.blogspot.com/2025/09/poin...
loading . . .
Pointer leaks through pointer-keyed data structures
Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...
https://googleprojectzero.blogspot.com/2025/09/pointer-leaks-through-pointer-keyed.html
about 2 months ago
0
10
6
fseek and you shall lfind
2 months ago
0
1
0
reposted by
Natalie Silvanovich
Lorenzo Franceschi-Bicchierai
3 months ago
Zero-day developer and seller Exodus casually brags in a blog post about having found a WebKit zero-day and sold it for a year and a half.
blog.exodusintel.com/2025/08/04/o...
ClƩment Lecigne and BenoƮt Sevens of Google's Threat Analysis Group were the ones that reported it to Apple.
1
21
10
Left blue, right red
#defcon
4 months ago
0
3
0
How to use your Defcon badge
4 months ago
1
4
1
āYou wouldnāt happen to have anything that could help me understand todayās ever-changing threat landscape? Perhaps involving a bit of AI?ā
4 months ago
0
3
1
Peak BH slide
4 months ago
0
1
0
Do you ever feel like maybe you should sign something, but arenāt quite sure you can follow through?
4 months ago
0
4
0
We also posted our first Transparency Report
googleprojectzero.blogspot.com/p/reporting-...
loading . . .
Reporting Transparency
As part of our 2025 Policy Trial , Project Zero will use this page to publicly track our Reporting Transparency effort. The trial commenced ...
https://googleprojectzero.blogspot.com/p/reporting-transparency.html
4 months ago
0
3
1
While most vendors ship timely patches for vulnerabilities reported by Project Zero, they donāt always reach users. Today, weāre announcing Reporting Transparency, a new policy to encourage downstream fixes
googleprojectzero.blogspot.com/2025/07/repo...
loading . . .
Policy and Disclosure: 2025 Edition
Posted by Tim Willis, Google Project Zero In 2021, we updated our vulnerability disclosure policy to the current "90+30" model. Our goals we...
https://googleprojectzero.blogspot.com/2025/07/reporting-transparency.html
4 months ago
1
6
9
reposted by
Natalie Silvanovich
Microplastics Sommelier
4 months ago
maybe there's still some good left in this world after all
loading . . .
317
17383
4939
The new Tamagotchi Switch game has rap battles where the Tamas rap about how they respect and enjoy each othersā unique differences
4 months ago
0
3
0
reposted by
Natalie Silvanovich
lukelukeluke
5 months ago
Inventor of the GIF, hearing about Notre Dame burning: oh no the jarjoyles
72
5330
1254
reposted by
Natalie Silvanovich
Dr. Jen Gunter
5 months ago
I accidentally closed a browser yesterday with 72 VERY IMPORTANT TABS that have been following me around like Jacob Marley and somehow my history is not recoverable. Reader, I let them go, and have lived to tell the tale.
30
432
14
At least 3 miles of protesters along El Camino in Sunnyvale
5 months ago
1
6
0
I Googled āhow to shorten a chain,ā and got no good answers, so hereās the answer, hereās how you temporarily shorten it
5 months ago
0
1
0
reposted by
Natalie Silvanovich
Pookleblinky
6 months ago
www.ibiblio.org/harris/500mi...
You might be one of the lucky people to learn today about an emailing bug that turned out to be caused by the speed of light.
loading . . .
The case of the 500-mile email
https://www.ibiblio.org/harris/500milemail.html
2
43
16
If thereās one thing Iāve learned, itās that tab completion is never ājust broken todayā
6 months ago
0
0
0
6 months ago
0
2
0
If $106,050.10 was the size of a quarter, it would fit in 424,200.4 fewer shipping containers than ā¦
6 months ago
0
0
0
The world never says hello back
6 months ago
2
8
2
The final part of Mateuszās Windows Registry series is live! Contains all the hive memory corruption exploitation youāve been waiting for
googleprojectzero.blogspot.com/2025/05/the-...
loading . . .
The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
Posted by Mateusz Jurczyk, Google Project Zero In the previous blog post , we focused on the general security analysis of the registry a...
https://googleprojectzero.blogspot.com/2025/05/the-windows-registry-adventure-8-exploitation.html
6 months ago
0
6
4
reposted by
Natalie Silvanovich
DistrictCon
6 months ago
šØ CALLING ALL VULNERABILITY RESEARCHERS šØ The Junkyard is officially open! This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs! Prizes range from $100 to $5,000 for categories like: āļø Most Impactful System š¾ Best Meme Target š Most Engaging Presentation
1
20
18
Movie you've watched more than 1000 times using gifs. ("Hard mode" no Star Wars, Star Trek, or LoTR)
add a skeleton here at some point
7 months ago
0
1
0
Should be a Canada goose
7 months ago
0
2
0
reposted by
Natalie Silvanovich
RE//verse
8 months ago
Another must-watch talk from RE//verse 2025 is live! Zion Basque challenges decompilers to step up their game and introduces a roadmap for a practical solution to solve some of the trickiest compiler behavior's to analyze. Check it out here:
loading . . .
RE//verse 2025: Buccaneers of the Binary (Zion Basque)
Full Title: Buccaneers of the Binary: Plundering Compiler Optimizations for Decompilation Treasure. Zion's talk is both a challenge for decompilers to step up ...
https://youtu.be/VP29biKLoSw
0
7
2
9 months ago
1
5
0
Comment 6: I donāt know, ask Past Natalie
9 months ago
0
4
0
reposted by
Natalie Silvanovich
Wes Miller
9 months ago
I know, Word. "syncable" isn't a word. But the dictionary is powerless against Microsoft.
0
2
2
You wouldnāt download an orange tree
9 months ago
1
4
2
Not correct, yet a strange window into my soul
10 months ago
0
0
0
reposted by
Natalie Silvanovich
Alt National Park Service
10 months ago
546
60146
14067
reposted by
Natalie Silvanovich
evacide
10 months ago
tl;dr WhatsApp fixed the vuln on the back end, so you don't need to do anything to your phone, up to and including enabling Lockdown mode. Paragon Solutions sucks and you should be mad at them for enabling spying on civil society.
www.theguardian.com/technology/2...
loading . . .
WhatsApp says journalists and civil society members were targets of Israeli spyware
Messaging app said it had āhigh confidenceā some users were targeted and āpossibly compromisedā by Paragon Solutions spyware
https://www.theguardian.com/technology/2025/jan/31/whatsapp-israel-spyware
4
126
51
reposted by
Natalie Silvanovich
James Forshaw
10 months ago
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process.
googleprojectzero.blogspot.com/2025/01/wind...
loading . . .
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
https://googleprojectzero.blogspot.com/2025/01/windows-bug-class-accessing-trapped-com.html
2
65
41
reposted by
Natalie Silvanovich
Azeria
10 months ago
Killer lineup! Canāt wait to attend. If you are into reverse engineering, check out the new Re-Verse conference, launching in February! The team behind it is incredible. This is going to be the new Infiltrate.
add a skeleton here at some point
0
13
4
reposted by
Natalie Silvanovich
RE//verse
10 months ago
We're pleased to announce Natalie Silvanovich
@natashenka.bsky.social
as the keynote speaker for the inaugural RE//verse. She might have started out hacking Tamagotchis, but she certainly didn't stop there!
1
17
9
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium.org/issues/36869...
loading . . .
Project Zero
https://project-zero.issues.chromium.org/issues/368695689
11 months ago
1
38
18
reposted by
Natalie Silvanovich
Steve Klabnik
11 months ago
WARNING: This product contains programming languages known to the State of California to cause memory unsafety
62
3476
258
Project Zero is hiring š Please share with anyone you think would be great for the team
www.google.com/about/career...
loading . . .
Senior Security Engineer, Security Research ā Google Careers
https://www.google.com/about/careers/applications/jobs/results/112297012816159430/
11 months ago
0
12
10
This Justin: Canadian PM resigns. Not sure if Trudeau
11 months ago
0
1
1
reposted by
Natalie Silvanovich
Adam J.B. Lane
11 months ago
Another masterwork by courtroom sketch artist Jane Rosenberg, whose piercing documentation of Rudy Giuliani's descent into madness is one of the most exciting things going on right now in American art.
59
3015
618
Oh look, itās the consistent use of tabs and spaces police
11 months ago
0
0
0
reposted by
Natalie Silvanovich
Ken Shirriff
12 months ago
I recently saw an amazing Navajo rug at the National Gallery of Art. It looks abstract at first, but it is a detailed representation of the Intel Pentium processor. Called "Replica of a Chip", it was created in 1994 by Marilou Schultz, a Navajo/DinƩ weaver and math teacher. 1/n
35
2935
994
reposted by
Natalie Silvanovich
Katie Moussouris (she/her/she-hulk/she-ra)š»
11 months ago
I thought everyone knew not to shine lasers at anything in the sky this time of year due to the chance of blinding a reindeer
3
92
7
Can you find an ITW 0-day from crash logs? Project Zero finds out
googleprojectzero.blogspot.com/2024/12/qual...
loading . . .
The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
Posted by Seth Jenkins, Google Project Zero This blog post provides a technical analysis of exploit artifacts provided to us by Google's Thr...
https://googleprojectzero.blogspot.com/2024/12/qualcomm-dsp-driver-unexpectedly-excavating-exploit.html
11 months ago
0
15
7
TIL there is a herd of 500,000 caribou in Alaska. They know this because Fish and Wildlife stitches together arial photos, like you would when imaging a silicon die. Then a guy named Don Williams counts them all
www.adfg.alaska.gov/index.cfm?ad...
loading . . .
Alaska's Largest Caribou Herd Grows, Alaska Department of Fish and Game
Alaska Wildlife News is an online magazine published by the Alaska Department of Fish and Game
https://www.adfg.alaska.gov/index.cfm?adfg=wildlifenews.view_article&articles_id=15
11 months ago
0
1
0
Load more
feeds!
log in