A "trivial" Bhyve VM escape, a BitWarden "RCE", a ModSecurity "Denial of Service" and more scare quotes for your enjoyment in this week's episode.
[00:14:29] BitWarden Blind HTTP GET SSRF
https://github.com/bitwarden/server/pull/812/commits/f094b76b6638932b13bb5ed2d9295185c54ce332
https://github.com/bitwarden/desktop/issues/552
[00:38:09] Bhyve VM Escape
https://bsdsec.net/articles/freebsd-announce-freebsd-security-advisory-freebsd-sa-20-29-bhyve_svm
[01:12:07] FANS: Fuzzing Android Native System Services via Automated Interface Analysis
https://github.com/iromise/fans
[01:19:52] OneFuzz framework, an open source developer tool to find and fix bugs at scale
https://github.com/microsoft/onefuzz
[01:37:25] Hypervisor Exploitation Compiled Research List
https://github.com/bitwarden/server/pull/812/commits/f094b76b6638932b13bb5ed2d9295185c54ce332
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@DAY[0])