rehackxyz

2K posts

rehackxyz banner
rehackxyz

rehackxyz

@rehackxyz

RE:HACK official Twitter account

Malaysia انضم Eylül 2021
108 يتبع1.4K المتابعون
rehackxyz أُعيد تغريده
OtterSec
OtterSec@osec_io·
New research: We were able to access camera permissions and obtain user GPS coordinates across 20+ major mobile wallets by exploiting WebView misconfigurations. Here's how ↓
OtterSec tweet media
English
2
23
104
13.8K
rehackxyz أُعيد تغريده
sofyank96
sofyank96@sofyank96·
Alhamdulillah diberi peluang untuk hasilkan video travel Malaysia bersama @mshaffuan07
Indonesia
45
2.1K
5.3K
135.6K
rehackxyz أُعيد تغريده
payloadartist
payloadartist@payloadartist·
There are very few people in the #bugbounty community that share their stellar research in this day and age. Massive respect. @brutecat made half a million hacking Google with AI, and he also shared his prrompts and techniques! brutecat.com/articles/hacki…
payloadartist tweet media
English
3
51
321
12.5K
rehackxyz أُعيد تغريده
Calif
Calif@calif_io·
We sent Claude Mythos Preview spelunking through Squid’s guts, and it surfaced clutching a 29-year-old bug. Meet Squidbleed: a Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration. Full story: blog.calif.io/p/squidbleed-c…
Calif tweet media
English
5
91
337
58.4K
rehackxyz أُعيد تغريده
rehackxyz أُعيد تغريده
avtokyo
avtokyo@avtokyo·
今年も AVTOKYO2026 ! 📅 2026年11月21日(土)※今年は土曜日に戻ります 📅 November 21, 2026 (Sat) — back to Saturday! 📍 TK NIGHTCLUB, Shibuya, Tokyo CFP/CFX will open soon. no drink, no hack. avtokyo.org/avtokyo2026 #avtokyo
avtokyo tweet media
日本語
0
34
64
6K
rehackxyz أُعيد تغريده
vx-underground
vx-underground@vxunderground·
> be pakistan government > develop custom malware > used to target high profile targets > used against indian military and political ppl > named SHEETCREEP > send indian ppl file > UAE-India Strategic Partnership Week > malicious .lnk file > .lnk executes malicious c sharp code > does a bunch of stuff for persistence > exfiltrates data to Google Sheets > Google Sheets can be used to control victim pcs > pakistan gov hardcodes google c2 sheet > PAKISTAN GOV HARDCODES GOOGLE C2 SHEET > embed access key in payload > EMBED ACCESS KEY IN PAYLOAD > malware nerds find it > look inside > find all targets from pakistan gov > monitoring 91 ppl they think important THEY STARTED SO STRONG. WHY DID YOU HARDCODE EVERYTHING. YOU BURNED YOUR OPERATION securonix.com/blog/sheetcree…
English
51
314
2.7K
121.2K
rehackxyz أُعيد تغريده
ABX
ABX@vx_antibi0tic·
My first attempt Exploit Developer (OSED) EXP-301 exam just passed! I enjoyed especially content that pushed down from exp-401. x64 vm-escape & dev shellcode. It's also fun to be able to read assembly in depth, heap/stack, reverse, and bypass aslr/dep. Thank you @offsectraining.
ABX tweet media
English
10
5
64
6.6K
rehackxyz أُعيد تغريده
Alexander Popov
Alexander Popov@a13xp0p0v·
The video of the Kernel-Hack-Drill Masterclass that I gave in Kuala Lumpur🌴 A lot of live demos of Linux kernel attacks and defenses🛠 youtube.com/watch?v=zXVqGa…
YouTube video
YouTube
English
1
36
136
9.7K
rehackxyz أُعيد تغريده
Aretiq.AI
Aretiq.AI@AretiqAI·
SharePoint Server RCE via webshell upload — CVE-2026-45454. A user with basic Contribute perms can upload an ASPX webshell to the Master Page Gallery and get code execution as the app pool identity. One HTTP request, no admin needed. Patch now. aretiq.ai/research/12/
English
0
47
157
17.5K
rehackxyz أُعيد تغريده
nknwn
nknwn@nknwn_eth·
meanwhile in Kuala Lumpur.. am i going to jail?
nknwn tweet media
English
45
137
1K
140.4K
rehackxyz أُعيد تغريده
Dark Web Intelligence
Dark Web Intelligence@DailyDarkWeb·
🇲🇾 Malaysia: Municipal Government VPN Access Advertised for Sale * Threat actor is advertising alleged VPN access to a Malaysian municipal government organization * The listing claims: * OpenVPN access * Domain Administrator privileges * Approximately 50 hosts within the environment * Revenue estimated between $50M–$100M * Cylance EDR reportedly deployed in the network * The access is being offered for sale on a cybercrime marketplace for approximately $978 USD * No specific government entity was identified in the visible portion of the listing * At the time of reporting, the claims remain unverified and should be treated as allegations until independently confirmed Analyst Note: Initial access listings remain one of the most reliable early indicators of potential ransomware activity. Government environments are frequently targeted because attackers can monetize privileged access through ransomware operators, data theft groups, and espionage actors. Even if the advertised access is exaggerated, the presence of claimed domain administrator privileges significantly increases the potential impact should the access prove legitimate. #DDW #Intelligence #Malaysia #DarkWeb
Dark Web Intelligence tweet media
English
0
21
56
9.7K
rehackxyz أُعيد تغريده
Calif
Calif@calif_io·
Introducing HTTP/2 Bomb: a remote DoS in nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client pins 32GB of server memory in 10s. Found by Codex. Blog post: blog.calif.io/p/codex-discov… PoCs: github.com/califio/public…
English
25
435
2K
185.9K
rehackxyz أُعيد تغريده
RyotaK
RyotaK@ryotkak·
Claude Codeに対してサプライチェーン攻撃を行うことが可能だった脆弱性についての記事を公開しました!
GMO Flatt Security株式会社@flatt_security

セキュリティリサーチャー RyotaK @ryotkak の技術ブログを公開しました。 今回、Claude Code GitHub Actions の権限制御を外部の GitHub Issue 経由でバイパスし、ワークフロー権限を悪用できる脆弱性、並びにそれに付随する設定ミスを発見・報告しました。 当該の脆弱性は v1.0.94 で修正済みですが、設定ミスについては各リポジトリにて対応が必要であるため、当該製品を利用されている場合は設定の見直しと実行ログの確認を推奨します。 flatt.tech/research/posts…

日本語
10
26
237
35.6K