Brian Gorenc (@maliciousinput) 's Twitter Profile
Brian Gorenc

@maliciousinput

Leader of the Zero Day Initiative. Pwn2Own organizer and adjudicator. Trafficker of export-controlled intrusion software. Bug Hunter.

ID: 148015459

calendar_today25-05-2010 16:28:44

527 Tweet

2,2K Followers

473 Following

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Announcing #Pwn2Own Vancouver 2021! Over $1.5 million available across 7 categories. #Tesla returns as a partner, and we team up with #Zoom for the new Enterprise Communications category. Read all the details at bit.ly/3ooKM6J #P2O

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

A successful #VMware #ESXi demo at #Pwn2Own is worth $150K. Lucas Leong had 2 unauth RCEs in ESXi patched last week. Not only does he break down the details in his latest blog, he went further & wrote a full code execution exploit for one of the bugs. bit.ly/2OgdfiK

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

For everyone finding variants while analyzing the in-the-wild #Exchange bugs, remember they are worth $200K at the upcoming #Pwn2Own contest. Bugs reported at the event have a 90-day disclosure timeline. Remember, no more patch Tuesdays before the contest. bit.ly/3ooKM6J

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

CVE-2021-27076: A complex bug that leads to reliable code execution. HexKitchen details this replay-style deserialization attack against #Microsoft #SharePoint. As a reminder, we're paying $50k for SharePoint exploits at #Pwn2Own. bit.ly/3r4CGSt

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Here's a quick preview of the Master of Pwn trophy for the upcoming #Pwn2Own. Creatify Shop is adding LEDs to this version, and so far, it looks amazing.

AdobeSecurity (@adobesecurity) 's Twitter Profile Photo

We’re supporting community #security research by partnering with Trend Zero Day Initiative for this year’s #Pwn2Own competition – check out the details and get involved here: bit.ly/396Uwht

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

The live drawing for #Pwn2Own will be at 9am Eastern tomorrow (April 6). You can watch the draw and all the contest live on YouTube at youtu.be/dA3aIMgRFY8

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

With that last award, we're now at $1,020,000 awarded for the contest with 9 attempts to go. It's the first time we've crossed the million dollar mark at #Pwn2Own. More to come...

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Announcing #Pwn2Own Austin! Our fall contest includes phones, printers, NAS devices and more. More than $500,000 USD in cash and prizes are available as 22 different devices will be put to the test. Read all of the details at zerodayinitiative.com/blog/2021/8/11…

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

An analysis of a #Parallels #Desktop stack clash vulnerabilities. renorobert describes some recently patched bugs and looks at how Binary Ninja’s static data flow capability can be used in automating bug finding tasks. zerodayinitiative.com/blog/2021/9/9/…

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

This year at #BHUSA, Brian Gorenc & The Dustin Childs present “Calculating Risk in the Era of Obscurity: Reading Between the Lines of Security Advisories” - A look at how enterprises can estimate risk in an era where patches aren't what they used to be. blackhat.com/us-22/briefing…

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

In a #Pwn2Own first, AI was involved in a successful exploit. The Claroty team used OpenAI 's #ChatGPT to write one of the backend modules used in their RCE of #Softing edgeAggregator. What a time to be alive.

The Dustin Childs (@dustin_childs) 's Twitter Profile Photo

Since no one from the MSRC is here at #Pwn2Own, we're disclosing the Teams exploit over a Teams call. You can join us if you want to hear the details: msteams.link/ZPRX

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

CONFIRMED! Synacktiv used a heap overflow & an OOB write to exploit the Infotainment system on the Tesla. When they gave us the details, we determined they actually qualified for a Tier 2 award! They win $250,000 and 25 Master of Pwn points. 1st ever Tier 2 award. Stellar work!

CONFIRMED! <a href="/Synacktiv/">Synacktiv</a> used a heap overflow &amp; an OOB write to exploit the Infotainment system on the Tesla. When they gave us the details, we determined they actually qualified for a Tier 2 award! They win $250,000 and 25 Master of Pwn points. 1st ever Tier 2 award. Stellar work!
Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Recapping #Pwn2Own Vancouver 2023. We had an amazing contest and awarded over $1 million (plus a Tesla Model 3) for 27 unique 0-days. Join ZDI's Brian Gorenc and The Dustin Childs as they go through all the highlights of this year's event. youtu.be/c0cS4R0ja-I

Trend Zero Day Initiative (@thezdi) 's Twitter Profile Photo

Announcing #Pwn2Own Ireland! Our fall contest is on the move (again) as we head to Cork, Ireland. We also welcome Meta as a sponsor with #WhatsApp being a target at $300K. Plus the return of the SOHO Smashup. Read all the details at zerodayinitiative.com/blog/2024/7/16… #P2OIreland