Mails Nielsen

97 posts

Mails Nielsen banner
Mails Nielsen

Mails Nielsen

@MailsNielsen

Co-Founder | #CEO of @SolidProof_io Security pro, loves engines: V12, bike, boat. Ex-sysadmin, full-stack dev, now CEO & researcher.

Flensburg, Germany Katılım Temmuz 2011
187 Takip Edilen135 Takipçiler
Mails Nielsen
Mails Nielsen@MailsNielsen·
If you haven't patched today, now would be a good time. "Pack2TheRoot" in PackageKit lets any local user install system packages without a password - and become root. Affects Debian, Fedora, Ubuntu, Rocky in default config. CVSS 8.8. Updates have been out since April 22.
English
4
1
3
660
Mails Nielsen
Mails Nielsen@MailsNielsen·
AI-assisted vuln research is starting to deliver real results. Whether that's good news depends on which side of the disclosure inbox you sit on.
English
0
0
1
28
Mails Nielsen
Mails Nielsen@MailsNielsen·
One detail worth flagging: Telekom Security found this with Anthropic's Claude Opus. The starting point was odd behavior of pkcon install on a Fedora workstation – a system package installed without ever prompting for a password.
English
0
0
2
44
Mails Nielsen
Mails Nielsen@MailsNielsen·
For the curious about the mechanics: it's a TOCTOU on transaction->cached_transaction_flags. Three bugs in the code let those flags get rewritten between authorization and execution - classic race window. Affected versions: PackageKit 1.0.2 through 1.3.4. Fixed in 1.3.5.
English
0
0
2
31
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
Good morning web3! Let's kick this week off with some security updates. We have just finished the smart contract audit for @BricaCapital 🤝 More news on its way. Reports are online app.solidproof.io
English
2
1
21
425
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
We believe everyone knows that we remain fully neutral our actions and reactions are based solely on facts and real events. That said, X is currently flooded with @Pumpfun discussions, @a1lon9 got doxxed, and controversy. It raises an important question: Did we all really not see it coming? Did we pretend there was real utility when it was clearly more of a casino-like system? Did the space (not us, but the majority of Degens) forget its core principles and simply play along? A reminder we shouldn’t ignore: honesty lasts longest. It’s time to return to building honest projects with real use cases. We call the EVM run back!!!!!!!
English
3
2
16
557
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
Historic milestone! @krakenfx just became the FIRST crypto firm to gain direct access to the Federal Reserve's core payments system via a master account. Now on the same rails as thousands of US banks & credit unions. Faster, safer fiat moves for crypto. Integration era begins!
SolidProof.io Official tweet media
English
2
3
9
512
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
Not many audits lately, okay let's say not many meme audits. But more development and utility projects, which is absolutely fine and hopefully brings hope back to the #Web3Culture. Today we are working on the final report together with the @Veilonwallet team, power on!
English
2
1
7
397
Mails Nielsen retweetledi
Cyber Security News
Cyber Security News@The_Cyber_News·
🚨 Microsoft Office Word 0-day Vulnerability Actively Exploited in the Wild Source: cybersecuritynews.com/microsoft-offi… A critical zero-day vulnerability in Microsoft Word, tracked as CVE-2026-21514, was disclosed on February 10, 2026, allowing attackers to bypass essential security protections. CVE-2026-21514 exploits a weakness in how Microsoft Word handles security decisions based on untrusted inputs, categorized as CWE-807. The vulnerability specifically bypasses Object Linking and Embedding (OLE) mitigations implemented by Microsoft to protect users from malicious COM/OLE controls. These OLE controls enable documents to embed and interact with external objects. However, improper validation allows attackers to circumvent protective measures. #cybersecuritynews #vulnerability
Cyber Security News tweet media
English
7
127
366
23.7K
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
We’re proud to announce a significant breakthrough in the fight against criminal activity in the Web3 space. Countless inquiries from the community have driven us to tackle what many thought was impossible legal prosecution of digital thieves.
SolidProof.io Official tweet media
English
6
6
21
131.8K
kuno
kuno@kunoo·
What is this trading pattern called?
kuno tweet media
English
957
163
1K
128.5K
Mails Nielsen retweetledi
DarkShadow
DarkShadow@darkshadow2bd·
Privilege Escalation in Wordpress acf-extended Plugin tip: always check the post method endpoint and analyse which parameters are user control then play with them💀 #bugbountytips
DarkShadow tweet mediaDarkShadow tweet media
English
0
25
187
9.2K
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
We are pleased to report that more and more Solana projects are choosing the secure path and deciding to undergo an audit. A very good example of this: @cryptition_io The project will also be available on our TrustNet soon.
English
6
4
16
184.2K
Mails Nielsen retweetledi
blackorbird
blackorbird@blackorbird·
Blame CloudFlare for Website Issues The Cloudflare Error Page Generator (github.com/donlon/cloudfl…) is an open-source tool for creating highly customizable error pages in the style of Cloudflare.
It perfectly mimics Cloudflare’s famous error page designs (such as the 5xx internal server error pages) and can be embedded directly into your website. You can easily generate static HTML files to replace default error pages, allowing you to quickly shift the blame to CloudFlare whenever your site runs into problems.
blackorbird tweet media
English
77
1.1K
8K
1.6M
SolidProof.io Official
SolidProof.io Official@SolidProof_io·
Not to forget, our data specialists are super busy as well! Welcome, Team @FortunaPro_sol . It's good to see that teams are still focusing on KYCs. You can see whether they passed or not later on our TrustNet - @SP_TrustNet
English
2
1
18
181.4K