Jonas Vestberg

5.9K posts

Jonas Vestberg

Jonas Vestberg

@bugch3ck

Privilege Escalation Engineer Principal Consultant @ Reversec (formerly WithSecure Consulting)

@bugch3ck.bsky.social Katılım Ağustos 2011
365 Takip Edilen1.9K Takipçiler
Adam Chester 🏴‍☠️
All this AI code and nobody has thought to create a replacement for infosec Twitter?? (me either)
GIF
English
4
0
5
415
Jonas Vestberg retweetledi
sakura
sakura@eternalsakura13·
Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter Microsoft's "safer" fallback when the WASM JIT is off? 23 paths to RCE in the interpreter itself. Slides now public — huge thanks to the OffensiveCon crew and everyone who came by. @offensive_con
English
2
21
136
9K
Rasta Mouse
Rasta Mouse@_RastaMouse·
Happy Bank Holiday weekend y’all
Rasta Mouse tweet media
English
12
0
65
7.9K
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@domchell "Journalist at prestigious publication named GitHub" Really? It sounds fake tbh 😅
English
0
0
2
127
Rob Fuller
Rob Fuller@mubix·
Have we seen malicious CLAUDE\.md files or malicious AI skills yet? This feels like the new “don’t copy and paste random command line or bash scripts from the internet”
English
6
2
20
3.5K
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@mubix @d0rkph0enix Ok maybe they assumed the settings were off since someone committed a key that would otherwise be blocked or ignored by the feature. If that is the case the wording is not great but it is not wrong either.
English
0
0
1
20
Lina
Lina@d0rkph0enix·
*SCREECHES IN ELDER SECURITY WITCH*
Lina tweet media
English
11
10
83
3.4K
Rob Fuller
Rob Fuller@mubix·
@d0rkph0enix How would commit logs show an administrative change at a repo or org level? That doesn’t make sense unless the log was hand written that that change was needed or mentioned which seems an odd thing to note in a commit log
English
1
0
1
473
Jonas Vestberg retweetledi
Andrea P
Andrea P@decoder_it·
Turns out that the fix for the CVE-2020-17103 , the Cloud Filter HsmOsBlockPlaceholderAccess driver bug reported by @tiraniddo was never ported to Windows 11 / Server 2025 and still not fixed. LPE from user to SYSTEM 🤦‍♂️
Andrea P tweet media
English
2
37
112
12.3K
Jonas Vestberg retweetledi
Led By Donkeys
Led By Donkeys@ByDonkeys·
Immigration makes Britain brilliant.
English
3.8K
16.1K
107.3K
3.8M
Jonas Vestberg retweetledi
Hamid Kashfi
Hamid Kashfi@hkashfi·
Gentle reminder that the Nginx RCE can be exploited remotely on any modern linux with protection enabled. All it takes is a second bug of arbitrary local file read, which is the reason we all love PHP and Node for. On a shared hosting environment, you should consider it as reliably exploitable, not just lab grade ASLR disabled RCE.
English
3
31
173
23.4K
Jonas Vestberg retweetledi
ChrisPy
ChrisPy@chrispy_sec·
If you’re interested in Claude Code and how skills can be abused to do bad things then check out the first in a series of few blogs from a colleague of mine who does 10/10 diagrams labs.reversec.com/posts/2026/05/…
English
0
2
1
211
Jonas Vestberg
Jonas Vestberg@bugch3ck·
Watching Americans discuss parental leave makes me sad.
Georgia Weidman@georgiaweidman

I’d encourage everyone to take a look at this. Technical founders are not employment lawyers, and he's right that kind of language was standard. The only company I’ve ever worked for that even offered paternity leave was based in Finland, a country with historically better human rights than the US. I continue to support @BHinfoSecurity and other companies created by members of our community. Running a business is hard and not a skill set that naturally follows from being a technical practitioner. @strandjs, if you need an evangelist or have overflow 1099, ping me.

English
0
0
0
85
Jonas Vestberg retweetledi
impulsive
impulsive@weezerOSINT·
I just reverse engineered the YellowKey BitLocker bypass Microsoft shipped code that checks for a flag called "FailRelock" in every Windows 11 recovery image. When it's set to 1, after recovery unlocks your BitLocker drive, it never relocks it. All you need is a USB stick. This code only exists in the recovery environment. Not in normal Windows. They left an entire debug testing framework in production.
impulsive tweet media
impulsive@weezerOSINT

The userland demon is about to drop again.

English
35
448
2.7K
274.6K
Dave Kennedy
Dave Kennedy@HackingDave·
Doing some time travel tonight
English
6
1
64
2.3K