Q5Ca

244 posts

Q5Ca banner
Q5Ca

Q5Ca

@_q5ca

Chief Remote Work Officer at @u0Kplusplus

Vietnam Katılım Kasım 2017
395 Takip Edilen957 Takipçiler
Sabitlenmiş Tweet
Q5Ca
Q5Ca@_q5ca·
Happy to share that my colleague @vudq16 and I will be speaking at PHDays in Moscow 🇷🇺 next week, May 24th. I’ll share a story from one of our red team projects, with techniques to maximize stealth during the operation. Hope to make new connections there:D phdays.com/en/forum/progr…
English
5
4
49
3.6K
Q5Ca retweetledi
TrendAI Zero Day Initiative
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
TrendAI Zero Day Initiative tweet media
English
15
93
726
39.7K
Q5Ca retweetledi
TrendAI Zero Day Initiative
There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own #P2OBerlin
English
15
57
437
39.6K
Q5Ca retweetledi
TrendAI Zero Day Initiative
Boom! @rewhiles of Viettel Cyber Security was able to exploit Anthropic Claude Code! If confirmed, they win $40,000 and 4 Master of Pwn points. They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
English
1
4
51
5.2K
Dlive
Dlive@D1iv3·
Container escape with CopyFail
Dlive tweet media
English
13
107
918
81.1K
Zack Korman
Zack Korman@ZackKorman·
Microsoft isn’t paying a bounty because this related to “enterprise copilot” which apparently isn’t covered? I don’t even know what that means… I have an M365 copilot license and a P1 license lol. What are they talking about.
Zack Korman tweet media
Zack Korman@ZackKorman

Microsoft isn’t disclosing this so: M365 Copilot allowed users to access files without producing an audit log. All you had to do was ask Copilot to not link to the file. You don’t even have to ask; it sometimes just happens. If your org uses Copilot your audit log is likely wrong

English
13
22
255
19.3K
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
@_q5ca yeah, you can just set a flag in protobuf request
English
1
0
1
423
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Hacking Windsurf: I asked the AI for the shell, it said yes. new video’s out. I show how I could’ve hacked you… just by getting you to click my link. Link posted below.
s1r1us (mohan) tweet media
English
19
77
411
67.2K
Zeeshan M.
Zeeshan M.@by6153·
@haxor31337 @_q5ca Hi @haxor31337 it was a great talk loved it totally 🙌 also I have a question when you used ActivitySurrogateSelector gadget it prompted almost 16k+ characters payload and you mentioned that the querystring supports 2048 characters did you tried to use -minify option in ysoserial
English
1
0
0
100
Tuan Anh Nguyen⚡️ 🇻🇳
From SSRF to RCE and transfer money in core banking. It is really cool red team case. A perfect combination of external and internal vulnerabilities for each other to bypass the monitoring and detection of the blue team. Present by my colleague @_q5ca youtu.be/xBnMrNCuO_w?si…
YouTube video
YouTube
English
6
69
353
31K
Hussein Daher
Hussein Daher@HusseiN98D·
Burn out, platforms not always playing the right game , some programs scamming you.. it's not all beautiful in Bug Bounty. Find a backup plan ;) only the wise will start diversifying. The next years will become very hard.
English
1
3
57
5.8K
Q5Ca
Q5Ca@_q5ca·
Happy to share that my colleague @vudq16 and I will be speaking at PHDays in Moscow 🇷🇺 next week, May 24th. I’ll share a story from one of our red team projects, with techniques to maximize stealth during the operation. Hope to make new connections there:D phdays.com/en/forum/progr…
English
5
4
49
3.6K