home > posts
  • August 6, 2026
    HD Moore
    @hdm

    The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD - all critical issues if you use HA with your FreeBSD-based firewalls. Noteworthy is that these bugs were found months ago with relatively old model. Vulnerability discovery continues to accelerate!

    https://blog.calif.io/p/the-taking-of-freebsd-one-two-three

    ↪ reply
  • August 6, 2026
    HD Moore
    @hdm

    Hello Las Vegas (and hackers following along at home)! I'm excited to share the first batch of our Out-of-Band / Baseboard Management Controller research at Black Hat USA today and DEFCON 34 this weekend. Read an exclusive by Ars Technica at:

    https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/

    Interested in checking your network? The pre-release of OOBscan is live on GitHub: https://github.com/runZeroInc/oobscan

    Thank you to our friends at Dragos.com, NetRise.io, and all of the researchers abroad who helped with review & feedback!

    ↪ reply
  • June 30, 2026
    HD Moore
    @hdm

    Skipping Black Hat and DEFCON this year? Consider presenting at BSides Hanoi instead. Now in its second year, the conference takes place on August 5th, 2026, and a few more talk slots are still open - but the submission deadline is today. Apply here: https://www.bsideshanoi.net/en/call-for-paper

    Thank you to everyone who has already submitted!

    ↪ reply
  • June 5, 2026
    HD Moore
    @hdm

    My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/

    ↪ reply
  • May 6, 2026
    HD Moore
    @hdm

    ATX Go is TONIGHT (a week early this month):

    Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go. Bring a talk, a friend, or an idea!

    https://www.meetup.com/atxgolang/events/312781570/

    ↪ reply
  • May 6, 2026
    HD Moore
    @hdm

    ATX Go is a week early this month, tomorrow night!

    Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, a few short talks on Go, and general discussion. Whether you write Go all day or just dabble on the weekends, come hang out and meet other folks in the Austin Go community.

    https://www.meetup.com/atxgolang/events/312781570/

    ↪ reply
  • April 30, 2026
    HD Moore
    @hdm

    RE: https://infosec.exchange/@runZeroInc/116493908814143481

    Excited to share what we've been cooking for the last few months:

    Interactive attack graphs, with hop-by-hop planning, support for over 220 protocols, and no-auth backplane enumeration to identify non-IP systems unauth over the network!

    Our free trial includes a fun Demo Organization you can explore and converts into our free Community Edition at the end (with all of the same capabilities, just a lower asset limit)!

    ↪ reply
  • March 30, 2026
    HD Moore
    @hdm

    Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
    https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

    ↪ reply
  • March 25, 2026
    HD Moore
    @hdm

    https://www.linkedin.com/posts/kylecgoode_network-asset-inventory-is-basically-frogger-activity-7442556028744994819-lpRA?utm_medium=ios_app&rcm=ACoAAAAGmUkB9m8hS0mY3OmsMriYFVH2oOQ3gpQ&utm_source=social_share_send&utm_campaign=share_via

    ↪ reply
  • March 23, 2026
    HD Moore
    @hdm

    Joseph Menn, renowned journalist & author of "The Cult of the Dead Cow," joins us for a special book signing event at RSAC! runZero and Mallory are thrilled to co-host a private book signing with renowned investigative journalist Joseph Menn during RSA Conference 2026! This is your chance to meet the man who writes the stories the industry talks about.

    Join us to grab a signed copy:

    https://www.runzero.com/joseph-menn-book-signing/

    ↪ reply
  • View older posts >>

Copyright 1998-2026 HD Moore