ShiRake

10.5K posts

ShiRake banner
ShiRake

ShiRake

@NotShiRake

cybersecurity enthusiast

Jupiter Katılım Nisan 2015
438 Takip Edilen127 Takipçiler
ShiRake retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
me @LiveOverflow, @rootxharsh, @iamnoooob and some cracked ctfers will be there. come talk to us about open models, security benchmarks, and building ai security agents.
Hacktron AI@HacktronAI

The best conversations at @defcon never happen at DEF CON. They happen in a hallway with people who found each other by accident. So we're skipping to that part. On August 7, @HacktronAI and @osec_io are putting one private dinner together in Vegas. No pitches or slides. Just good food, a strong technical crowd and conversations a conference floor makes impossible. At the table: top bug bounty hunters, CTF players, and security leaders worth knowing. Friday, August 7 · 6:30 PM @ Las Vegas. Seats are limited and by request. If you're in town, tell us a bit about yourself. Link in comments.

English
0
5
41
4.4K
ShiRake retweetledi
vx-underground
vx-underground@vxunderground·
Welcome to my DMs
English
41
25
1.2K
45.2K
ShiRake retweetledi
sakura
sakura@eternalsakura13·
Can any OpenAI security person give me the chatgpt.com/cyber certification since I can't pass KYC.🥲
English
12
3
94
19.8K
ShiRake retweetledi
vx-underground
vx-underground@vxunderground·
> be United States > sanction VPN > used for ransomware > ransomware VPN uses Telegram > Advertisement and customer support > US Treasury publishes sanction thingie > list VPNs Telegram channel > Domain people see it > See t.me/ransomwarethin… > "OMG BLOCK T.ME!!!" > Put global block on t.me > Breaks Telegram URLs > Telegram owner mad af > Complains, says they can't read > "hehe oops, me no think good" > Resolved like, 24 hours later
vx-underground tweet media
English
37
157
3K
105K
ShiRake retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️ Nightmare-Eclipse just dropped "LegacyHive," a new Windows privilege-escalation zero-day PoC that targets the Windows User Profile Service, the component that loads a user's settings during sign-in. The PoC reportedly uses a carefully timed path-switching trick to make Windows mount another user's Registry file, potentially an administrator's, under a standard "helper" account. Nightmare-Eclipse claims it works across supported Windows desktop and server builds patched through July 2026. Nightmare-Eclipse says a private version could load arbitrary Registry hives, but that broader version has not been published. Interestingly, Nightmare-Eclipse previously told us that vulnerability names are inspired by random events in his life. "LegacyHive" appears to break from that convention. Deja vu: Microsoft patched this broad ProfSvc trust-boundary failure in 2015 as CVE-2015-0004, which also loaded another user's hive. LegacyHive appears to use a new path-swap to revive that bug class. As of writing: no CVE, no Microsoft advisory, no comment.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
24
177
1.5K
80.2K
ShiRake retweetledi
vx-underground
vx-underground@vxunderground·
GIF
ZXX
32
253
3.8K
83.1K
eigen moomin
eigen moomin@eigen_moomin·
moomin has officially gradutated!!!
eigen moomin tweet media
English
41
5
1.1K
142.2K
ShiRake retweetledi
SaltyAom
SaltyAom@saltyAom·
What Anthropic keep us doing for a month
SaltyAom tweet media
English
2
2
78
2K
sky
sky@skydotcs·
happy grad to the class 2026 uncs
sky tweet media
English
39
1
256
13K
ShiRake retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Semgrep alternative! OSS, rust based, tree-sitter. Def will play with it.
Ahmad Sadeddin@asadeddin

🚀 We open-sourced Sighthound today. Sighthound is a Rust-based static vulnerability scanner for source code. It runs locally or in CI, uses Tree-sitter parsers, and supports pattern-based detection plus taint flow analysis. It also comes with all it's rulesets with no paid account or signup needed. github.com/Corgea/Sightho… Why build another static scanner in 2026? Semgrep and OpenGrep are useful, but we kept running into a few constraints: the OCaml core raises the contribution bar for many developers, adding language support is not as simple as we wanted, and some higher-signal rule content in the ecosystem sits behind accounts or paid offerings. We wanted something fast, inspectable, easy to extend, and fully open. A few implementation details: - Rust binary for local and CI use - Tree-sitter parsing - Pattern matching and taint analysis by default - Cross-file taint propagation and dependency tracking - Parallel file discovery and scanning - Text, JSON, and CSV output - Rules written in RON and deserialized into typed Rust structs/enums - MIT licensed Current support includes Python, JS/TS, Java, Go, C#, HTML, PHP and Ruby. It focuses on source-code vulnerability classes like command injection, SQL injection, XSS, path traversal, code injection, unsafe deserialization, and crypto issues. It is not a secrets scanner. We're still have a lot of work to getting to where we want it to be so, we would love the community to test it, break it, report issues, and tell us where it falls short. PRs for rules, language support, fixtures, and false-positive tuning are very welcome.

English
9
30
261
33.2K
ShiRake retweetledi
Zack Korman
Zack Korman@ZackKorman·
Bringing stickers to defcon
GIF
English
51
33
607
19.6K
ShiRake retweetledi
Michael Debono
Michael Debono@_mixy1·
I have been working on this blog post for an embarrassingly long time. While the thought of CTFs depressed me during most of this time period, I'm more hopeful now. I think what made the scene so beautiful to me will persist. I can't wait to show you all what we have in store.
Robert Chen@NotDeGhost

We're launching a $100,000 fund to save CTFs.

English
3
10
135
9.9K
ShiRake retweetledi
Smukx.E
Smukx.E@5mukx·
Yoo What 😭? Google search is weird sometimes ...
Smukx.E tweet media
English
2
3
34
3.2K
ShiRake retweetledi
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
I have been seeing reverse engineering / malware analysis courses that cost thousands of dollars. Do you know you can actually learn that for free, right? There are also a bunch of other courses out there that are way cheaper or even free: - courses.0ffset.net - malwareanalysis-for-hedgehogs.com - invokere.com - github.com/RPISEC/MBE - guyinatuxedo.github.io/index.html - openanalysis.net - p.ost2.fyi - taomm.org
English
21
168
824
126.5K