SLF Digest

We are the Security Liberation Front.

Subscribe via our feed or follow @slffish for announcements.

2026 Q1

mirror 20260408
Pixel 9 0-click exploit chain
HackerBot Claw
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
CosmicHammer: detecting naturally-occurring bitflips.

2025 Q4

mirror 20260112
Cross-container communication using POSIX Advisory Locks
Controlled memory write with disabled denormalized floats in Chrome
Breaking Trusted Execution Environments via DDR5 Memory Bus Interposition
Nvidia UAF Kernel Bug
Glass Cage: Zero-Click PNG Exploit Chain for iOS 18.2.1
clown cracker sudo-rs reveals password on timeout; allows running commands as any user
Take a conceptually wrong idea (sudo) and re-write it in a sekure language only to obtain a security hole.

2025 Q3

mirror 20250930
SwissBorg watched $41.5M in SOL vanish through Kiln's backdoor
Apple A17 Pro Chip: Critical Flaw Causes Dual Subsystem Failure
Obtaining Global Admin in every Entra ID tenant via Actor tokens
NPM Supply Chain Attack: What we know about it

2025 Q1

mirror 20250303
Mossad's pagers & walkie-talkies sabotage operations
No reliable details source available
Hackers deployed to facilitate drug smuggling
The invalid 68030 instruction that accidentally allowed the Mac Classic II to boot
LinuxPDF: Linux running inside a PDF file via a RISC-V emulator
CVE-2025-26465: MitM attack against OpenSSH VerifyHostKeyDNS & CVE-2025-26466: DoS against OpenSSH client/server

2024 Q3

mirror 20240910
RegreSSHion — Remote unauthenticated RCE in OpenSSH
When Samsung meets MediaTek: the story of a small bug chain
EUCLEAK
PassPort: Forwarding TCP ports through Passkey servers to bypass censorship
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI

2024 H1

mirror 20240601
XZ Utils backdoor in liblzma and JiaT75's operation
Randar Minecraft exploit
PuTTY biased ECDSA-P-521 nonces

2023 Q4

mirror 20240121
Operation Triangulation: The last (hardware) mystery
An analysis of an in-the-wild iOS Safari WebContent to GPU Process exploit
A Study on Implementation Attacks against QKD Systems

2023 Q3

mirror 20231014
CVE-2023-38408: Remote Code Execution in OpenSSH's forwarded ssh-agent
Compromised Microsoft MSA key by Storm-0558
Looney Tunables: Local Privilege Escalation in glibc's ld.so (CVE-2023-4911)

2023 Q2

mirror 20230706
SectorC: A C Compiler in 512 bytes
faulTPM: Exposing AMD fTPMs' Deepest Secrets
acme.sh runs arbitrary commands from a remote server
Accidental $70k Google Pixel Lock Screen Bypass

2023 Q1

mirror 20230402
OpenSSH Pre-Auth Double Free CVE-2023-25136
Dota 2 Under Attack: How a V8 Bug Was Exploited in the Game
BlackLotus UEFI bootkit
Exploiting aCropalypse: Recovering Truncated PNGs

2022 Q4

mirror 20230122
The destruction of FTX by CZ
The Profanity vanity address generator bug
The Android certificates leak

2022 Q3

mirror 20220923
Doom-in-Doom
MicrocodeDecryptor
Custom Processing Unit
An efficient key recovery attack on SIDH + You could have broken SIDH
Process injection: breaking all macOS security layers with a single vulnerability

2022 Q2

mirror 20220707
"ExtraReplica" — cross-account database vulnerability in Azure PostgreSQL
Exploiting Intel Graphics Kernel Extensions on macOS — Pwn2Own 2021 Safari Sandbox Escape
Notes on OpenSSL remote memory corruption
idiot security prize Idiot Security Prize

2022 Q1

mirror 20220412
Winning a $31337 Bounty after Pwning Ubuntu and Escaping Google's KCTF Containers
DeFi protocol KLAYswap theft via BGP hijack
A one in a million bug in Switch kernel
Win32 MMIO kernel exploit
FORCEDENTRY: Sandbox Escape
FBI forensics of the Bitfinex hack
Wormhole Solana bridge incident

2021 Q4

mirror 20211224
How a simple Linux kernel memory corruption bug can lead to complete system compromise
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
Titan M chip reverse engineering and bugs
Alpha-Rays: key extraction attacks on threshold ECDSA implementations

2021 Q3

mirror 20210929
Frontrunning a scammer
Sequoia: A deep root in Linux's filesystem layer (CVE-2021-33909)
Downlevel Driver Enabler
Improving the exploit for CVE-2021-26708 in the Linux kernel to bypass LKRG
Autodiscovering the Great Leak

2021 Q2

mirror 20210706
Send My
ChromeOS root privilege escalation and android-root persistence
Theodosius: JIT linker, mapper, obfuscator, and mutator
Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
GCP DHCP takeover code-exec
An EPYC escape: Case-study of a KVM breakout

2021 Q1

mirror 20210413
sudo bug
CVE-2021-1782 XNU kernel exploit
Hunting for bugs in Windows mini filter
One day short of a full chain
Quantifying blockchain extractable value: How dark is the forest?
nft_ptr
Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027)