n0s

29 posts

n0s banner
n0s

n0s

@n_zero_s

...

Bergabung Ocak 2022
682 Mengikuti111 Pengikut
n0s me-retweet
Calif
Calif@calif_io·
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747) To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI. blog.calif.io/p/mad-bugs-cla…
English
14
118
534
83.1K
n0s me-retweet
Calif
Calif@calif_io·
A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets. A step-by-step guide to exploiting a 20-year-old bug in the Linux kernel to achieve full privilege escalation and container escape, plus a cool bug-hunting heuristic. open.substack.com/pub/calif/p/a-…
English
3
60
204
23.5K
n0s me-retweet
Kirill Firsov
Kirill Firsov@k_firsov·
Our latest research is out! If you missed a good write-up for nice vulnerabilities, I brought you one! Enjoy the reading! @FearsOff @Cloudflare
Kirill Firsov tweet media
English
10
105
500
136.4K
n0s me-retweet
Robert Youssef
Robert Youssef@rryssf_·
RIP fine-tuning ☠️ This new Stanford paper just killed it. It’s called 'Agentic Context Engineering (ACE)' and it proves you can make models smarter without touching a single weight. Instead of retraining, ACE evolves the context itself. The model writes, reflects, and edits its own prompt over and over until it becomes a self-improving system. Think of it like the model keeping a growing notebook of what works. Each failure becomes a strategy. Each success becomes a rule. The results are absurd: +10.6% better than GPT-4–powered agents on AppWorld. +8.6% on finance reasoning. 86.9% lower cost and latency. No labels. Just feedback. Everyone’s been obsessed with “short, clean” prompts. ACE flips that. It builds long, detailed evolving playbooks that never forget. And it works because LLMs don’t want simplicity, they want *context density. If this scales, the next generation of AI won’t be “fine-tuned.” It’ll be self-tuned. We’re entering the era of living prompts.
Robert Youssef tweet media
English
239
1.2K
7.8K
714.2K
n0s
n0s@n_zero_s·
@M0ngii Nice work!
English
0
0
0
45
n0s me-retweet
M0ngi
M0ngi@M0ngii·
Dropping my kernel exploitation notes I've been working on since I first started researching in this I'll keep updating the repo so please, let me know if there's smthg unclear or must be fixed You'll also find future writeups & challenges authored there. github.com/M0ngi/Kernel-E…
English
3
7
20
1.2K
n0s
n0s@n_zero_s·
@ptrYudai Wow! Congrats!
English
0
0
1
89
n0s me-retweet
Matan Berson
Matan Berson@MtnBer·
Just wrote a ~2.5 page blog post on Client Side Path Traversal, covering what CSPT is, why it can be so impactful, some advanced exploitation and WAF bypass techniques, and a bug which I found in a live hacking event (redacted ofc) matanber.com/blog/cspt-leve…
English
8
107
385
36.8K
n0s me-retweet
c0m0r1
c0m0r1@c0m0r1·
I'm speechless
c0m0r1 tweet media
English
31
234
2.3K
510.3K
n0s
n0s@n_zero_s·
The vulnerability is about request smuggling, looks like there is a misleading information about RCE in the description. I requested a description update for that. Sorry for any inconvenience.
English
0
0
3
190
ptr-yudai
ptr-yudai@ptrYudai·
I wrote 70 CTF challenges this year, which is my personal record🫠 @ptr-yudai/HyL3TASfK" target="_blank" rel="nofollow noopener">hackmd.io/@ptr-yudai/HyL…
English
22
29
323
28.5K
n0s
n0s@n_zero_s·
I contributed with 7 web challenges for #BHMEA2023 this year, hope you like them! Congrats to @strellic for blooding today’s insane chall 🤯
n0s tweet media
English
1
0
28
2.9K
n0s me-retweet
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
Excited to launch my first browser extension, DOMLogger++! Now available for both Firefox and Chromium! 🎉 DOMLogger++ allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations 🔥 Check it out 👇 github.com/kevin-mizu/dom… 1/5
English
9
106
337
42.4K
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Web Security vs. Binary Exploitation
English
99
1.9K
10.2K
833.1K
n0s me-retweet
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I wasn't knowing what to do yesterday night so, I decided to create an XSS challenge 🚩 There is nothing to win, I made it just for fun! If you want to try it out, click on the link below 👇 mizu.re/challenges/xss… The final goal it to pop an alert without any interaction 🔥
Kévin GERVOT (Mizu) tweet media
English
5
23
101
24K