stratan

338 posts

stratan

stratan

@5tratan

Building products @TashitaSoftSec. Securious research on the side.

Katılım Ocak 2016
863 Takip Edilen578 Takipçiler
Sabitlenmiş Tweet
stratan
stratan@5tratan·
Introducing What The Claude: Browser Edition. A series where we pick apart browser bugs found/reported by Claude. First up: CVE-2026-2796, a SpiderMonkey Wasm import bug that leads to addrof/fakeobj/read-write. github.com/str8outtaheap/…
English
2
26
119
11.6K
stratan
stratan@5tratan·
What The Claude, episode 3. We're taking a break from content-process RCEs for Bug 2022034. A raw NaN. Typed JS actor IPC. A parent-process fake object. An XUL leak. Code execution outside the sandbox. NaN around and find out. github.com/str8outtaheap/…
English
1
14
62
12.4K
stratan retweetledi
Tashita Software Security
Tashita Software Security@TashitaSoftSec·
At Tashita, we always wanted a browser vulnerability research framework that researchers could actively guide and control over how research is conducted. Instead of forcing researchers to adapt to a tool, we built SeekZero to adapt to the researcher. That idea influenced almost every part of the platform. tashita.net/seekzero/
Tashita Software Security tweet media
English
0
3
5
510
stratan retweetledi
Tashita Software Security
Tashita Software Security@TashitaSoftSec·
What makes SeekZero unique is not generic automation. It is the ability to connect researcher judgment, campaign-based workflows, execution feedback, orchestration, and AI-assisted systems into one programmable framework. We believe this is where browser vulnerability research is heading. tashita.net/seekzero/
Tashita Software Security tweet media
English
0
1
1
377
stratan retweetledi
Javi T.
Javi T.@javi_teje·
We spent the last year developing SeekZero. We envolved years of research experience into a programmable system, designed from researchers to researchers. Today we're finally introducing it publicly. Really proud of what the team has built. A lot more to come!
Tashita Software Security@TashitaSoftSec

Over the last year, we have been developing a framework for advanced browser vulnerability research. Today we are introducing SeekZero. SeekZero is a programmable JavaScript engine vulnerability research framework designed for researcher-guided automation, scalable execution, and highly customizable research workflows. Access is currently limited. tashita.net/seekzero/

English
0
2
6
1.2K
stratan retweetledi
Tashita Software Security
Tashita Software Security@TashitaSoftSec·
Over the last year, we have been developing a framework for advanced browser vulnerability research. Today we are introducing SeekZero. SeekZero is a programmable JavaScript engine vulnerability research framework designed for researcher-guided automation, scalable execution, and highly customizable research workflows. Access is currently limited. tashita.net/seekzero/
Tashita Software Security tweet media
English
0
2
4
1.5K
stratan
stratan@5tratan·
What The Claude: Browser Edition, episode 2. This time: Bug 2024918. A phi node, SpiderMonkey's JIT pipeline, Wasm GC scalar replacement, escape analysis, and one wrong equality check. Let’s dive in. github.com/str8outtaheap/…
English
1
13
57
4.6K
stratan retweetledi
Javi T.
Javi T.@javi_teje·
We said it was raining Chrome bugs. Part 2 brings the thunder. @5tratan continues the CVE-2026-6307 analysis, taking the TurboFan JS-to-Wasm deopt type confusion from root cause to PoC. tashita.net/turbofan-js-to…
English
0
25
113
7.1K
stratan retweetledi
Javi T.
Javi T.@javi_teje·
It's been raining Chrome bugs lately, so we took a closer look. Part 1 by @5tratan is live: our analysis of CVE-2026-6307, a TurboFan JS-to-Wasm deopt type confusion bug. We cover the trigger and the background needed to follow along. tashita.net/turbofan-js-to…
English
0
15
87
6.5K
stratan
stratan@5tratan·
.@TashitaSoftSec 's mission is to revolutionise how security research is performed, by developing the most advanced vulnerability research frameworks. Join us and become part of an epic adventure! Career opportunities: tashita.net/careers/ DMs are open!
English
0
4
14
1.8K
stratan retweetledi
quarkslab
quarkslab@quarkslab·
[BLOG] An overview of macOS kernel debugging blog.quarkslab.com/an-overview-of… Deep dive into Kernel Debugging Protocol (KDP), from implementation to limitation
English
0
89
175
0
stratan retweetledi
Samuel Groß
Samuel Groß@5aelo·
Fuzzilli, my JavaScript engine fuzzer, is now open source: github.com/googleprojectz… \o/ Keep an eye on the Project Zero bugtracker in the next few weeks for some of the bugs found with it. Also let me know if you encounter any problems when using it! :)
English
9
427
975
0