Hacker News with Generative AI: Exploitation

'So immoral': gig economy workers forced to pay fee to receive their wages (theguardian.com)
Retail assistants have accused a gig economy firm of “holding them to ransom” by making them pay a fee if they want to receive their wages within a month.
Mitigations are attack surface, too (2020) (blogspot.com)
This blog post discusses a bug leading to memory corruption in Samsung's Android kernel (specifically the kernel of the Galaxy A50, A505FN - I haven't looked at Samsung's kernels for other devices). I will describe the bug and how I wrote a (very unreliable) exploit for it.
SELinux bypasses (klecko.github.io)
This post aims at giving an overview of what SELinux is, how it is implemented, and how to bypass it, from the point of view of Android kernel exploitation.
Exploit Released for New Windows Server "WinReg" NTLM Relay Attack (bleepingcomputer.com)
Proof-of-concept exploit code is now public for a vulnerability in Microsoft's Remote Registry client that could be used to take control of a Windows domain by downgrading the security of the authentication process.
The Pig Butchering Invasion Has Begun (wired.com)
More than 200,000 people in Southeast Asia have been forced to run online scams in recent years, often being enslaved and brutalized, as part of criminal enterprises that have netted billions in stolen funds.
0.0.0.0 Day: Exploiting Localhost APIs from the Browser (oligo.security)
Creative workers deserve better than a choice as to who rips them off (pluralistic.net)
Microsoft's Recall is already exploited (github.com/Pennyw0rth)
Abusing Go's Infrastructure (reverse.put.as)
PoC to demonstrate root permission hijacking by exploiting “systemd-run” (twitter.com)
The hero tax: Why 'selfless' workers are professionally exploited (bbc.com)