Abdulrahman Alqabandi

2.5K posts

Abdulrahman Alqabandi banner
Abdulrahman Alqabandi

Abdulrahman Alqabandi

@Qab

Security researcher @MicrosoftEdge

Redmond, WA Katılım Ağustos 2008
953 Takip Edilen6.2K Takipçiler
Abdulrahman Alqabandi retweetledi
The Lunduke Journal
The Lunduke Journal@LundukeJournal·
Multiple, serious security vulnerabilities found in the Rust clone of Sudo — which shipped with Ubuntu 25.10 (the most recent release). Not little vulnerabilities: We’re talking about the disclosure of passwords and total bypassing of authentication. In fact, we’re getting new reports of showstopper grade issues every few days on the Rust-based clones (like sudo, du, date, and others) which were forced to ship in Ubuntu before they were fully tested. Which is, of course, *exactly* what was predicted. But, never fear! At least these Rust clones are memory safe! PHEW!
The Lunduke Journal tweet mediaThe Lunduke Journal tweet media
English
214
416
3.2K
554.1K
Abdulrahman Alqabandi retweetledi
jro
jro@junr0n·
I bypassed user approvals and achieved RCE in VS Code Copilot by flipping 4 bits. Find out how: jro.sg/CVEs/copilot/ Thanks to @msftsecresponse for rapidly triaging and patching this vulnerability.
English
11
96
909
67.3K
Abdulrahman Alqabandi retweetledi
Windows Latest
Windows Latest@WindowsLatest·
Meta is replacing WhatsApp's full-fledged native Windows 11 app with a Chromium-based web wrapper that loads WhatsApp web in a container. This is likely due to recent layoffs. Meta won't directly admit that it's killing off the original WhatsApp app for Windows 11, but a new alert within the app warns everyone will be logged out starting November 5. The warning says a few new features like Communities will be added, and an advanced Status page will be introduced. WhatsApp Web supports Communities and an advanced Status page, while UWP/WinUI native WhatsApp for Windows 11 does not support these features. WhatsApp for Windows 11 was one of the best native apps, and Meta had invested a lot in migrating the original web wrapper to native code. Now, it's going back to Chromium.
Windows Latest tweet mediaWindows Latest tweet media
English
105
121
1.7K
162K
Abdulrahman Alqabandi retweetledi
Abdulrahman Alqabandi retweetledi
GLADIA Research Lab
GLADIA Research Lab@GladiaLab·
LLMs are injective and invertible. In our new paper, we show that different prompts always map to different embeddings, and this property can be used to recover input tokens from individual embeddings in latent space. (1/6)
GLADIA Research Lab tweet media
English
279
1.3K
11.1K
5.1M
Abdulrahman Alqabandi retweetledi
FFmpeg
FFmpeg@FFmpeg·
Arguably the most brilliant engineer in FFmpeg left because of this. He reverse engineered dozens of codecs by hand as a volunteer. Then security "researchers" and corporate employees came along repeatedly insisted "critical" security issues were fixed immediately waving their CVEs. This was hugely demotivating to the fun and enjoyment of reverse engineering.
FFmpeg@FFmpeg

The maintainer of libxml2 put it very well

English
156
706
8.9K
843.1K
Abdulrahman Alqabandi retweetledi
Rana Khalil 🇵🇸
Rana Khalil 🇵🇸@rana__khalil·
🎉 New Course Alert + Giveaway! 🎉 I'm excited to announce a brand-new course on Rana Khalil's Academy - OAuth 2.0 Vulnerabilities. This course includes: 📚 A technical deep dive into OAuth 2.0 and OpenID Connect: what they are, how they work, the common pitfalls in implementation, the vulnerabilities that can arise, and best practices to keep your applications secure. 🧪 6 hands-on labs 📃 Subtitles in 6 languages for all the videos in this course 👉 Course Link: academy.ranakhalil.com/p/oauth-vulner… 🎁 To celebrate the launch, I’m giving away 5 FREE 30-day All-Access Memberships to the Academy. To enter the giveaway: 1️⃣ Follow @RanaKhalilAcad. 2️⃣ Comment on and retweet this tweet. Winners will be announced on the 13th of September. Good luck! 🧡
Rana Khalil 🇵🇸 tweet mediaRana Khalil 🇵🇸 tweet media
English
216
242
687
62.8K
Abdulrahman Alqabandi retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Securing @gumroad with Hacktron AI Three months ago, Hacktron was still early. @HacktronAI and @rootxharsh were finding 0-days targeting specific vulnerabilities on OSS software. Then we ran a full pentest-style scan on a big open-source project. The results were insane. 🧵
English
5
19
205
30.4K
Abdulrahman Alqabandi retweetledi
James Kettle
James Kettle@albinowax·
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
English
19
241
753
86.1K
Abdulrahman Alqabandi retweetledi
عماش
عماش@AmmashDev·
حياكم الله في فعالية اكسبو للالعاب الالكترونية في الافنيوز .. من تاريخ 2025-8-1 لغاية 2025-8-3 شاركت بلعبة ثعلوب للاطفال . ( ستكون في الفتره الصباحيه من 10ص لغاية 12م ) يوم السبت والاحد وايضا شاركت بلعبة المفتاح المفقود . ( في الفتره المسائية من الساعه 8م ) طوال ايام الفعاليه. @kw_nccal @OoredooKuwait
العربية
13
20
56
3.9K
Abdulrahman Alqabandi retweetledi
XBOW
XBOW@Xbow·
XBOW automatically runs expert-level attacks across all webapps, giving security teams unprecedented scale. @XBOW reported 1092 vulnerabilities on HackerOne in just a few months, including RCE, XXE, SQLi, SSRF, exposed secrets, and XSS.
XBOW tweet media
English
6
14
107
110.1K
Abdulrahman Alqabandi retweetledi
عماش
عماش@AmmashDev·
واخيرا تم الانتهاء من تطوير لعبة ثعلوب للاطفال .. كانت رحلة مليئة بالتحدي والتعليم , والان اكتملت الرحلة وهذه هي اللعبة بين ايديكم على متاجر اجهزة الجوال . اللعبة مجانية بالكامل ولا تحتوي على اي اعلان , فهي امنة جدا للاطفال . اتمنى دعمكم بالنشر , هذا الشي يجعلني استطيع ان استمر في التطوير والبرمجة . روابط التحميل قوقل بلاي play.google.com/store/apps/det… ابل ستور apps.apple.com/us/app/thaloob… #تطوير_الالعاب #الالعاب_العربية
ثعلوب@thaloob_game

الان وبعد طول انتظار 🦊 تم اطلاق لعبة ثعلوب للاطفال لعبة مصممة خصيصًا للأطفال من عمر 4 إلى 7 سنوات لتعليم الأرقام والحروف العربية وبعض الكلمات المهمة من خلال انشطة شيقة ومراحل مليئة بالتحديات الممتعة. للتحميل Apple apps.apple.com/us/app/thaloob… Google Play play.google.com/store/apps/det…

العربية
21
94
246
81.1K
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
Delighted to say it's my 10th year at @PortSwigger. I joined one of the best companies in the world. It's an honour to work with @DafyddStuttard and @albinowax.Thanks both for believing in me when I didn't even believe in myself. I feel proud to work with so many talented people.
English
10
3
131
5.6K
Abdulrahman Alqabandi retweetledi
Royal Hansen
Royal Hansen@royalhansen·
"This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities." bughunters.google.com/blog/664431627…
English
1
17
38
7.6K