Sabitlenmiş Tweet
chebuya
47 posts


Found a medium severity path traversal in Velociraptor (CVE-2025-14728). Will have funny/embarrassing story about it soon.
Shoutout to Mike Cohen of Rapid7/Velocidex for building such an awesome tool and swiftly triaging the vuln/severity upon report
CVE@CVEnew
CVE-2025-14728 Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside t… cve.org/CVERecord?id=C…
English

Also, big thanks to @ACEResponder for their work on RogueSliver - it was massively helpful while writing the PoC. Do check it out:
github.com/ACE-Responder/…
English

@vxunderground smelly let me talk about phishing minecraft players and c2 agent authentication
English

"Top 50 Techniques & Procedures"
blog.redteamguides.com/top-50-techniq…
Real world malware delivery and initial access techniques (red teaming). Good source of inspiration.
English

@vxunderground Cool but I feel like compared to the threats that affected Minecraft in the past, this is like a skiddie game.
I mean, why would you waste your time doing something so useless? I'm not criticizing cuz I'm the first one to do useless side projects, but I just don't get the point.
English
chebuya retweetledi

vx-underground Black Mass Research Group presents: Minegrief.
tl;dr a computer worm that targets minecraft
github.com/blackmassgroup…
English

I have hereby been declared GIGACHAD for the Minecraft malware I wrote for the @vxunderground JVM malware competition 🥰🥰
Do check out the Black Mass Research Group telegram as well!
t.me/blackmassresea…
b0t 👽🏴☠️@bot59751939
This is the contest winner :) Ships with a 0day for Crafty controller. Huge thanks to @_chebuya. Today I'm announcing Black Mass Research Group. Our goal is to make interesting malware for public study. Please enjoy our first project! github.com/blackmassgroup…
English
chebuya retweetledi

This is the contest winner :)
Ships with a 0day for Crafty controller. Huge thanks to @_chebuya.
Today I'm announcing Black Mass Research Group. Our goal is to make interesting malware for public study. Please enjoy our first project!
github.com/blackmassgroup…
English

Today @ESET released a paper on "Bootkitty" the first UEFI bootkit for Linux.
We didn't even read the paper, we just liked the name and artwork

English
chebuya retweetledi

🛠️ Sastsweep
A tool designed for identifying vulnerabilities in open source codebases at scale
It can gather and filter on key repo metrics such as popularity and project size, enabling targeted vulnerability research
It automatically detects potential vulnerabilities using @Semgrep
By @_chebuya
github.com/chebuya/sastsw…
English
chebuya retweetledi

📚 tl;dr sec 255
🤖 @ProjectZeroBugs AI finds bug in SQLite
☁️ New OSS: CloudTail, SkyScalpel @permisosecurity
🛣️ Auto-generate Terraform Secure Guardrails
📺 @SANSInstitute CloudSecNext Summit 2024 videos
🇨🇳 The TTPs Used to Neutralize China-Based Threats @SophosXOps
📊 Safer SCPs: Real-Time SCP Error Monitor @matthewdfuller
🛠️ sastsweep @_chebuya
and more!
tldrsec.com/p/tldr-sec-255
English
chebuya retweetledi

Here is running SASTsweep against HackerOne open source targets
It lets you open the semgrep finding in an HTML report, and from there you can open the affected section of code within GitHub/Github1s for further analysis
Tool: github.com/chebuya/sastsw…
chebuya@_chebuya
SASTsweep is now open source. Happy hunting! github.com/chebuya/sastsw…
English


