Ooggle

6.4K posts

Ooggle banner
Ooggle

Ooggle

@Ooggle_

hi ◕‿◕ Cybersecurity / Reverse engineering | Member of @rhackgondins CTF team | https://t.co/Ty1wuArKy7

Katılım Ekim 2014
518 Takip Edilen280 Takipçiler
Sabitlenmiş Tweet
Ooggle
Ooggle@Ooggle_·
Hey 👋 I am glad to introduce my latest tool: the @flipper_net Animation Manager This tool aims to facilitate visualization and management of animations on your Flipper from your computer, for both users and content creators! You can download it here⬇️ github.com/Ooggle/Flipper…
GIF
English
3
15
48
4.4K
Ooggle retweetledi
Vulnotes
Vulnotes@vulnotes·
It's official: Vulnotes is live 🎉 The platform for your entire pentest engagement ✍️ Visual report editor 🔁 Built-in review workflow 📤 Export to docx, pdf, csv.. 🤖 AI: screenshots → findings, translate, rewrite 🔌 API + MCP 👉 vulnotes.com
English
0
8
18
2.9K
Ooggle retweetledi
Hippie
Hippie@hiippiiie·
I left my pentest job to fix what every pentester complains about: reporting and team management. 18 months building, 6 months tested on real engagements. Today it goes live. Vulnotes is officially available 🚀
Vulnotes@vulnotes

It's official: Vulnotes is live 🎉 The platform for your entire pentest engagement ✍️ Visual report editor 🔁 Built-in review workflow 📤 Export to docx, pdf, csv.. 🤖 AI: screenshots → findings, translate, rewrite 🔌 API + MCP 👉 vulnotes.com

English
0
7
17
1.3K
Ooggle retweetledi
Ruulian
Ruulian@Ruulian_·
Hi! Shutlock CTF is opened! You can retrieve one of my challenges in the PWN category, an Android full chain 0 click RCE in 3 steps! It represents hours of development to provide you an unusual CTF challenge! 🙂 I hope you'll like it! Accessible at: https://shutlock[.]fr
English
0
6
29
2.3K
Ooggle retweetledi
Nirmata ☭🔻
Nirmata ☭🔻@kiffeur2brousse·
Merci pour tout, repose en paix….
Nirmata ☭🔻 tweet mediaNirmata ☭🔻 tweet media
Français
159
2.3K
24.6K
2M
Ooggle retweetledi
Renwa
Renwa@RenwaX23·
"Dad, what was it like playing CTFs before AI?"
English
26
274
1.7K
175.5K
Ooggle retweetledi
impulsive
impulsive@weezerOSINT·
the same technique giving cheaters wallhacks in Valorant is the same one being used in malware to pwn you. Still working no patch, undetected from AV's and AC's. I pulled the source from a cheating forum, built it, and ran it on my fully patched Windows 11 machine. it reads memory straight out of another running program without needing admin, without loading a driver, without calling any API that your EDR monitors. it just uses two normal Windows functions that have existed since the 90s, SetWindowsHookEx and SendMessage. I reversed the root cause in Ghidra. two functions that ship in every copy of Windows ntdll.dll and shell32.dll will blindly execute whatever function pointer you hand them through a window message. Microsoft's own exploit protection CFG signs off on it because they're legitimate functions. no CVE. no patch. 279 stars on GitHub. Microsoft won't fix it because they consider same-privilege process interaction "by design." Chinese researchers found the same technique in live malware back in 2023.
impulsive tweet mediaimpulsive tweet media
English
38
142
1.7K
159.6K
Ooggle retweetledi
Calif
Calif@calif_io·
Google paid us $57,000 for two bugs in Chrome. We’re not doing this for the bounty, but it’s always fun to get rewarded. These bugs were found using nothing fancier than a $20/month AI subscription. If you’re curious, come check out our talk at the Real World AI Security Conference at Stanford: seclab.stanford.edu/RealWorldAIsec/ We haven’t published the Chrome bugs in our MAD Bugs series. They work better as part of something even more fun, stay tuned!
Calif tweet media
English
19
94
1.1K
78.9K
Ooggle retweetledi
Stormslayer 🔜QUAKECON 2026 -HD Remasters/Gamedev
The Legend of Zelda: The Minish Cap (2004) It's been recompiled and ported to PC! With all the modern bells and whistles you'd expect! Gameplay improvements, improved framerate beyond the original 30FPS hard limit, controls and an expanded inventory system which was limited in the original GBA! You can play it on PC and handhelds like the Steam Deck! This is amazing, and Twilight Princess is just around the corner! ENJOY!
Stormslayer 🔜QUAKECON 2026 -HD Remasters/Gamedev tweet media
BeenTachi@Been777888

You can play the minish cap PC port right now! youtu.be/ZJRzqSttRcw

English
49
696
6.8K
428.1K
Ooggle retweetledi
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Biggest L take I have seen in a while. If they knew how cracked @gf_256 and team is they would know how embarrassing this take is.
The Lunduke Journal@LundukeJournal

Remember the security firm that Ubuntu hired to audit the (ill-advised, highly buggy) Rust-rewrites of all of the GNU Coreutils? Turns out that security firm is run by @gf_256, who: - Appears to be a man who thinks he's a woman ("trans"). - Uses an anime cartoon of a girl as his avatar. - Appears to have an OnlyFans page. I repeat: Ubuntu hired a "Trans" man, with an anime girl avatar and an OnlyFans page... to audit Rust code. It's hard to get more on-the-nose than that.

English
13
26
884
53.9K
Ooggle retweetledi
Iceman
Iceman@herrmann1001·
Mind blown 🤯 Some smartphones sold in mainland China (like certain OPPO models) can read MIFARE Classic cards, crack the keys in seconds, store them, and then fully emulate the card directly on the phone. No extra hardware. Just the phone. Access control, transit cards, hotel keys… game over. Huge thanks to Ian for showing me this in person. Really eye-opening how far NFC capabilities have gone in some regions. Who else has seen this in the wild? #NFC #MIFARE #TechSecurity​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​ #oppo
English
102
609
3.9K
456.7K
Ooggle retweetledi
Xint
Xint@xint_official·
Patch your Linux boxes! Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. Found by the teams at @theori_io and @xint_official More details below xint.io/blog/copy-fail…
English
23
361
981
252.3K
Ooggle retweetledi
impulsive
impulsive@weezerOSINT·
Windows defender has been compromised. right now there is a public unpatched exploit that gives any app on your windows PC full system admin access. no password. no popup. nothing your antivirus doesnt stop it. your antivirus IS the exploit. windows defender is the attack vector ransomware gangs can use this to encrypt your entire machine and steal every saved password, browser session, and discord token you have. fully patched windows 11. real time protection on thread
impulsive tweet mediaimpulsive tweet media
English
217
1.4K
8.6K
2.2M
Ooggle retweetledi
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
RCE in Ghidra: My fav bugs target security tools. In CVE-2026-4946, you can embed these into your binary, analyst loads binary, Ghidra auto-generates the comments, analyst clicks on it, command executes. Write-up: takeonme.org/cves/cve-2026-…
solst/ICE of Astarte tweet media
English
8
55
355
22.4K
Ooggle retweetledi
stacksmashing
stacksmashing@ghidraninja·
Option A: Upgrade iPhone to iOS26 and have to use liquid glass Option B: Get pwned by DarkSword malware I don't know which one is worse
English
24
21
577
40.5K
Ooggle retweetledi
Vulnotes
Vulnotes@vulnotes·
Creating cybersecurity report templates shouldn’t be painful. That’s why we built our own template editor, designed from the ground up for security teams. Also thinked for designing your slide deck for client briefings 👌 Easier, faster, smarter. 👾
English
0
3
6
199
Ooggle retweetledi
vx-underground
vx-underground@vxunderground·
> be nerds > look into persona (used by discord) > kyc (know your customer) service > used for age verification > search on internet (shodan) > find weird server > image 1 > openai-watchlistdb.withpersona > openai-watchlistdb-testing.withpersona > lolwtf > look inside > supposed to be behind cloudflare to hide ip > openai messed up > not behind cloudflare > real ip shown > using google cloud > lookup cert history > 2023-11-16 created > 2024-02-28 gets cert > 2024-03-04 prod goes live > google stuff > openai and persona partners > partner around timeline of certs > back to searching stuff > find withpersona-gov > look inside > okta (image 2) > lolwtf > look inside > website accidentally leaking stuff > fedramp-private-backend-api > look inside > api .js accidentally exposed > look inside > wtf "SARInstructionsCard" > wtf "app.onyx.withpersona-gov" > wtf "FINTRAC" > wtf "PrivatePartnershipProjectNameCodes" > image 3 > wtf "AsyncSelfie" > look inside > openai, persona, send data to us gov > feds map face to financial records > map face using AI > map face to ICE stuff > api stores data for lots of stuff > image 4 tl;dr persona kyc and openai are frens, using your selfie for verification and sending to ICE (or USGOV in general), using AI to tie to your financial records. see subsequent post for full write-up. its long and not mobile friendly
vx-underground tweet mediavx-underground tweet mediavx-underground tweet mediavx-underground tweet media
English
313
7.7K
44.4K
2.6M