Ivan

119 posts

Ivan banner
Ivan

Ivan

@Ivanklydz

Security researcher with deep focus on vulnerability detection.

Katılım Nisan 2025
67 Takip Edilen265 Takipçiler
Ivan
Ivan@Ivanklydz·
@ArnaldoCapo @LiamKearney99 @valigo that's still not the case, the key they got is a github pat, allows attackers to enumerate and read/write all repos in the org, that's how they exfiltrated everything
English
1
0
1
322
Arnaldo Capo
Arnaldo Capo@ArnaldoCapo·
@Ivanklydz @LiamKearney99 @valigo Let me explain. The extension got the user’s keys. The keys allowed the hacker to ssh into github.com and when you ls in the ssh terminal they got all the code that the hacked user had access. Pretty basic if you’ve ever ssh’ed or used *nix terminal
English
2
0
1
356
Valentin Ignatev
Valentin Ignatev@valigo·
🚨 BREAKING 🚨 Infamous Russian hacker and beatboxer exposes exactly how hackers got access to private GitHub repositories
English
128
737
8.6K
725K
Ivan
Ivan@Ivanklydz·
@C2IRIS how much did sam pay you?
English
0
0
0
110
IRIS C2
IRIS C2@C2IRIS·
GPT 5.5 Cyber is definitely better than Mythos And it doesn't come with all the doomer, virtue-signaling histrionics from Anthropic
English
5
1
21
1.4K
Ivan
Ivan@Ivanklydz·
@S1r1u5_ calling this a 0day is crazy wtf
English
0
0
17
2.7K
Ivan
Ivan@Ivanklydz·
@loop0420 I've been laying on this for a while before kimi existed
English
1
0
2
691
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨🇨🇳 BREAKING: We identified exposed admin panels for Chinese air defence and drone systems across an entire region. The panels are reachable from the open internet and protected only by default credentials. Our investigation shows this is not isolated. A large number of these intelligence and military systems are deployed the same way.
International Cyber Digest tweet mediaInternational Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
62
241
1.5K
292.5K
Jason Sawyer
Jason Sawyer@foilmanhacks·
Hey man, you know this is my work. We had an agreement and you blew it. "Our investigation" My investigation, you had a dead lead and I turned it into gold at 2am last night. We we're going to handle this properly but you posted without even consulting me.
English
15
31
302
43.3K
Ivan
Ivan@Ivanklydz·
@valigo they used an infected vsc extension to dump private keys, lucky them one of github employees was using it, his github private key got exfiltrated aswell as other keys, they used that github pat to access the org private repos
English
2
0
44
2.6K
Ivan
Ivan@Ivanklydz·
@rebane2001 nope, I'm demonstrating the exact vulnerability you found as you can see in the screenshot, I'm just hinting there is a chaining opportunity
English
1
0
0
759
Rebane
Rebane@rebane2001·
@Ivanklydz are you demonstrating full compromise?
English
1
0
0
688
Ivan
Ivan@Ivanklydz·
@p3rlynx why are you larping me?
English
1
0
0
15
Lynx
Lynx@p3rlynx·
imagine being the best, ppl use your name for everything, skrrrrrrrr
Lynx tweet media
English
1
0
1
1.7K
Ivan
Ivan@Ivanklydz·
@junmaitei dm me, I can't dm you lol
English
0
0
0
275
Ivan
Ivan@Ivanklydz·
@x0rz I do, it's still the best
English
0
0
0
336
Ivan
Ivan@Ivanklydz·
@luseemeow just copying the link and pasting it in the browser bar will decode it, no need for sending it on discord
English
0
0
0
95
Lusee
Lusee@luseemeow·
never send http://%6C%75%73%65%65%2E%6C%6F%6C/%73%6F%67%67%79%63%61%74/%73%6F%67%67%79%2E%6A%70%67 to anyone on discord trust me its horrifying
Lusee tweet media
English
69
240
8.4K
696.7K
Ivan
Ivan@Ivanklydz·
AI doomed us all
English
0
0
1
107
SandboxEscaper
SandboxEscaper@WeirdQuadratic·
Yo @NewYorkFBI , send me a written apology for everything you people ever did, like a truely sincere one, by 9pm, my timezone, and I wont upload what I'm about to upload. You can delay what is going to happen. Up to you whether you want to do it or now. I dont care either way.
English
5
6
67
22.6K
Ivan
Ivan@Ivanklydz·
Found an RCE in ollama and an other RCE in apache tomcat, tried to attend Pwn2Own but got rejected sadly, it reached full capacity
English
0
1
2
225
Ivan
Ivan@Ivanklydz·
@loop0420 @vectrw are you stupid man? confusing me for this kid is insulting.
English
1
0
0
20
vect
vect@vectrw·
CrowdStrikeware can be used to prevent ransomware, but also can be used to deploy ransomware
English
2
3
34
4K