WaterBucket

1K posts

WaterBucket banner
WaterBucket

WaterBucket

@windeebug

windows vuln research & adversarial AI/ML

C:\Windows\system32\ 가입일 Kasım 2021
362 팔로잉254 팔로워
WaterBucket 리트윗함
dru1d
dru1d@_dru1d·
@chompie1337 @seanhn My experience with this so far is that it’s really only good at identifying known bad patterns/exploit primitives. Humans are still GOATed for the novel stuff.
English
0
1
4
157
WaterBucket 리트윗함
Origin
Origin@originhq·
Windows Insider builds now have a native, OS-level broker for MCP servers. We reverse engineered Odr.exe to understand how it validates clients, manages consent, and controls access - uncovering undocumented COM interfaces and a full ETW audit trail. originhq.com/blog/msft-odr-…
English
2
25
58
5.3K
WaterBucket 리트윗함
eleven red pandas
eleven red pandas@bytecodevm·
Research shows how Palo Alto Cortex XDR predefined BIOC behavioral rules can be decrypted and analyzed. By understanding rule logic and built-in exceptions, attackers can adapt techniques to evade detection and bypass behavioral protections. core-jmp.org/2026/03/decryp…
eleven red pandas tweet mediaeleven red pandas tweet mediaeleven red pandas tweet mediaeleven red pandas tweet media
English
0
53
162
13.4K
WaterBucket 리트윗함
Taszk Security Labs
Taszk Security Labs@TaszkSecLabs·
Now You See mi - Now You're Pwned: Exploiting Xiaomi Smart Cameras for fun and credit labs.taszk.io/articles/post/… Our intern's research post is up, full code of an RCE exploit + a "cloud jailbreak" released with it. After embargo expiry, 3 vulnerabilities currently remain unfixed.
English
2
41
139
8.7K
DARKNAVY
DARKNAVY@DarkNavyOrg·
Hi @thezdi @OpenAI, asking for the rules of Pwn2Own26 Coding Agent directory, particularly the "interact with ... repository" If a user opens someone else's git repo using CodeX App with default permissions and is immediately RCE’d, does this fall within the threat model? :)
English
6
10
143
85.3K
WaterBucket 리트윗함
mert
mert@merterpreter·
Discovered a Mark-of-the-Web (MOTW) bypass using native Windows extraction tools. CAB - TAR - TAR - XLSM chain causes the final file to lose MOTW, allowing macros in Microsoft Excel to run without the security warning. Reported to MSRC and classified as moderate. Enjoy
English
4
70
350
21.7K
WaterBucket 리트윗함
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
I recently came across the need to obtain logging into WSL2 and was forced to look into function hooking. However, this was my first time dealing with a COM server that didn't symbols, so I had to learn about a C++ feature - RTTI. I decided to write a blog on this in case anyone else runs into or has run into this: jonny-johnson.medium.com/wsl-com-hookin… POC: github.com/jonny-jhnson/R…
English
1
23
108
10K
WaterBucket 리트윗함
Alex Neff
Alex Neff@al3x_n3ff·
Releasing one of my research tools: EVENmonitor🖥️ Inspired by LDAPmonitor, I implemented a monitoring tool for the Windows Event log in pure python. You can just attach it via the network and then filter for specific event IDs or keywords. Available at: github.com/NeffIsBack/EVE…
GIF
English
3
53
202
13.2K
WaterBucket 리트윗함
johnny
johnny@zeroxjf·
Published an attempted cleanroom reconstruction of the iOS Coruna exploit chain so it can be understood beyond original malware payloads. Disclaimer: largely done by Codex GPT-5.4 xhigh with iterative reviews. May contain mistakes. WIP; feedback welcome. github.com/zeroxjf/iOS-Co…
English
4
26
144
10.3K
WaterBucket 리트윗함
Security Level 5 Task Force
Security Level 5 Task Force@SL5TaskForce·
1/n Today we're releasing the first public draft of the Security Level 5 (SL5) standard, designed to protect frontier AI models against nation-state adversaries. This v0.1 focuses on long lead time interventions: the things that need to start now, before SL5 is urgently needed. standard.sl5.org
English
5
65
188
37.6K
WaterBucket 리트윗함
eleven red pandas
eleven red pandas@bytecodevm·
Analyze the Windows kernel driver BEDaisy.sys, used by BattlEye anti-cheat. Through static reverse engineering, it explores driver architecture, APC usage, hardware fingerprinting, import handling, and detection mechanisms used to monitor system activity. core-jmp.org/2026/03/revers…
eleven red pandas tweet mediaeleven red pandas tweet mediaeleven red pandas tweet mediaeleven red pandas tweet media
English
0
7
24
702
WaterBucket 리트윗함
Haidar
Haidar@haider_kabibo·
Hi, here is the first post of the second wave of RPC. RPC part 10. In this part, I talk about the structures inside the server stub. I tried to make it as simple as I did in the previous parts, so you don’t have to suffer as I did. Bye. sud0ru.ghost.io/windows-inter-…
English
2
14
46
2.7K