home.social

#projectzero — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #projectzero, aggregated by home.social.

fetched live
  1. 🔍🎉 Oh look, another "groundbreaking" #discovery by Project Zero, where they prove the obvious: if there's a #flaw, someone can exploit it. 🚪🔓 Bravo, geniuses, for uncovering that doors sometimes close, but windows open—literally a 0-click revelation! 🙄🔧
    projectzero.google/2026/05/pix #ProjectZero #Exploitation #Cybersecurity #0Click #Vulnerability #HackerNews #ngated

  2. 🔍🎉 Oh look, another "groundbreaking" #discovery by Project Zero, where they prove the obvious: if there's a #flaw, someone can exploit it. 🚪🔓 Bravo, geniuses, for uncovering that doors sometimes close, but windows open—literally a 0-click revelation! 🙄🔧
    projectzero.google/2026/05/pix #ProjectZero #Exploitation #Cybersecurity #0Click #Vulnerability #HackerNews #ngated

  3. Googles #ProjectZero follows a 90 days disclosure deadline policy. Meaning they will publish a vulnerability 90 days after informing the vendor (or 30 days after the patch is published)

    Sometimes they grant an additional 14 days grace period. Leading to a 104 days fix period.

    googleprojectzero.blogspot.com

  4. Googles #ProjectZero follows a 90 days disclosure deadline policy. Meaning they will publish a vulnerability 90 days after informing the vendor (or 30 days after the patch is published)

    Sometimes they grant an additional 14 days grace period. Leading to a 104 days fix period.

    googleprojectzero.blogspot.com

  5. On the day I finally got the physical versions of Project Zero 4/5, I finish the third game. My first full playthrough after over 15 years since I first got that game.

    And what a GREAT game in the series this was.

    Coincidentally this now also concludes my replay of the entire series and that has fully re-ignited my love for it. Just... outstanding games.

    #ProjectZero #FatalFrame

  6. On the day I finally got the physical versions of Project Zero 4/5, I finish the third game. My first full playthrough after over 15 years since I first got that game.

    And what a GREAT game in the series this was.

    Coincidentally this now also concludes my replay of the entire series and that has fully re-ignited my love for it. Just... outstanding games.

    #ProjectZero #FatalFrame

  7. Today my physical collection of Project Zero/Fatal Frame (main line) games has become complete.

    I only owned Mask Of the Lunar Eclipse and Maiden Of Black Water digitally before, but thanks to Play Asia I got the physical releases.

    I love this series so much, it's great to finally have all (*) of them on the shelf.

    (* Except for Spirit Camera... I am still looking for a copy with reasonable price)

    #ProjectZero #FatalFrame

  8. Today my physical collection of Project Zero/Fatal Frame (main line) games has become complete.

    I only owned Mask Of the Lunar Eclipse and Maiden Of Black Water digitally before, but thanks to Play Asia I got the physical releases.

    I love this series so much, it's great to finally have all (*) of them on the shelf.

    (* Except for Spirit Camera... I am still looking for a copy with reasonable price)

    #ProjectZero #FatalFrame

  9. I’m looking for a feed that aggregates recent reverse engineering and vulnerability centric security writeups, like the ones posted by Google project zero. I know there are many different security firms and academics that post these kind of articles now and then, but I’m having a hard time with discovery as every news site or feed I find is focused on cybersecurity threats and CVEs, or simply just malware actor reports.

    Does anyone have something that fits the bill?
    #reverseengineering #googleprojectzero #projectzero #vulnerability #vulnerability_research

  10. I’m looking for a feed that aggregates recent reverse engineering and vulnerability centric security writeups, like the ones posted by Google project zero. I know there are many different security firms and academics that post these kind of articles now and then, but I’m having a hard time with discovery as every news site or feed I find is focused on cybersecurity threats and CVEs, or simply just malware actor reports.

    Does anyone have something that fits the bill?
    #reverseengineering #googleprojectzero #projectzero #vulnerability #vulnerability_research

  11. Mateusz Jurczyk with Google Project Zero posted a nice two part blog post on their journey of auditing the Windows Registry...

    The Windows Registry Adventure

    Part #1: Introduction and research results
    🔥⁠googleprojectzero.blogspot.com

    Part #2: A brief history of the feature
    🔥⁠googleprojectzero.blogspot.com

    #InfoSec #ProjectZero #Windows

  12. Mateusz Jurczyk with Google Project Zero posted a nice two part blog post on their journey of auditing the Windows Registry...

    The Windows Registry Adventure

    Part #1: Introduction and research results
    🔥⁠googleprojectzero.blogspot.com

    Part #2: A brief history of the feature
    🔥⁠googleprojectzero.blogspot.com

    #InfoSec #ProjectZero #Windows

  13. Got a lot of things to obsess over. My recent rekindled love with the #ProjectZero/#FatalFrame series, my stupid little #Atari Gamestation Pro and now those excellent Toaplan #Arcade ports.

    How you all keep sane at my incessant ramblings about all of that, I have no idea, but I think you for it anyway. :)

  14. Got a lot of things to obsess over. My recent rekindled love with the #ProjectZero/#FatalFrame series, my stupid little #Atari Gamestation Pro and now those excellent Toaplan #Arcade ports.

    How you all keep sane at my incessant ramblings about all of that, I have no idea, but I think you for it anyway. :)

  15. Finished Chapter 2 of #ProjectZero/#Fatal Frame II - #Wii Edition (getting tired of always writing EU and US titles).

    Oh boy I remember why I liked the game so much. Also getting better with the Wii controls - although I still wish the game would get a Remaster. I don't mind motion controls, but the lack of a second thumbstick is cumbersome. And the devs knew it. A lot of the ghosts are REALLY slow.

  16. Finished Chapter 2 of #ProjectZero/#Fatal Frame II - #Wii Edition (getting tired of always writing EU and US titles).

    Oh boy I remember why I liked the game so much. Also getting better with the Wii controls - although I still wish the game would get a Remaster. I don't mind motion controls, but the lack of a second thumbstick is cumbersome. And the devs knew it. A lot of the ghosts are REALLY slow.

  17. Google has removed a video posted by academic researchers demonstrating how a newly discovered side channel in Apple's A- and M-series CPUs can be used to steal a password.

    I thought for sure the removal was a mistake, but a Google representative told me the video was removed for violating a term of service barring "demonstrating how to use computers or information technology to steal credentials, compromise personal data, or cause serious harm to others."

    The video, demonstrating important research by @genkin, @YuvalYarom , @themadstephan and jason kim, is here:

    onedrive.live.com/?authkey=%21

    Just to underscore how arbitrary and patently asinine Google's ToS enforcement is here, two additional videos the researchers posted demonstrating the same side channel remain available.

    I wonder how researchers from #projectzero feel about this. Is there any chance any of them can intervene?

  18. Google has removed a video posted by academic researchers demonstrating how a newly discovered side channel in Apple's A- and M-series CPUs can be used to steal a password.

    I thought for sure the removal was a mistake, but a Google representative told me the video was removed for violating a term of service barring "demonstrating how to use computers or information technology to steal credentials, compromise personal data, or cause serious harm to others."

    The video, demonstrating important research by @genkin, @YuvalYarom , @themadstephan and jason kim, is here:

    onedrive.live.com/?authkey=%21

    Just to underscore how arbitrary and patently asinine Google's ToS enforcement is here, two additional videos the researchers posted demonstrating the same side channel remain available.

    I wonder how researchers from #projectzero feel about this. Is there any chance any of them can intervene?

  19. In mid-2022, #ProjectZero was provided with access to pre-production hardware implementing the #ARM #MTE specification. This blog post series is based on that review, and includes general conclusions about the effectiveness of MTE as implemented, specifically in the context of preventing the #exploitation of memory-safety #vulnerabilities.

    googleprojectzero.blogspot.com

  20. In mid-2022, #ProjectZero was provided with access to pre-production hardware implementing the #ARM #MTE specification. This blog post series is based on that review, and includes general conclusions about the effectiveness of MTE as implemented, specifically in the context of preventing the #exploitation of memory-safety #vulnerabilities.

    googleprojectzero.blogspot.com

  21. @GNUmatic @MrsLoecksley

    Ich höre gerade zum ersten mal von dem allem. Ich bin noch weit davon entfernt mir eine endgültige Meinung zu bilden, aber was ich
    rausgefunden habe beim lesen durch #Project92 ist dass Meta geld in die Hand nimmt um, ja was genau zu machen?
    Admins zu kaufen? Devs zu bezahlen?
    Beides kann gut oder schlecht sein.

    #Google zB. ist jetzt auch nicht das sympathischte Unternehmen. Trotzdem bin ich Dankbar für #ProjectZero und besonders fürs Engagement bei SSL

  22. #Google tells users of some #Android phones: Nuke voice calling to avoid infection | #ArsTechnica

    “Tests conducted by #ProjectZero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim's phone number.
    With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational #exploit to #compromise affected devices silently and remotely.”

    arstechnica.com/information-te