Jonas Vestberg

5.9K posts

Jonas Vestberg

Jonas Vestberg

@bugch3ck

Privilege Escalation Engineer Principal Consultant @ Reversec (formerly WithSecure Consulting)

@bugch3ck.bsky.social Katılım Ağustos 2011
364 Takip Edilen1.8K Takipçiler
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@_EthicalChaos_ I would not be surprised if it was more common to build a modular approach with modules written as PIC.
English
0
0
0
45
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@_EthicalChaos_ This is a great question! I often think about this in relation to use of BOF execution.
English
1
0
1
401
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿
For all the malware analysts out there, how often do you see more advanced tradecraft out there utilizing memory execution techniques like reflective loading, BOF execution, etc... used outside of simulated attack scenarios?
English
8
11
51
6.2K
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@Bugcrowd I thought it said "Bug Bunny" there for a while. That would have been something 😅
English
0
0
0
54
bugcrowd
bugcrowd@Bugcrowd·
When they ask about my weekend plans Me:
bugcrowd tweet media
English
3
0
47
3.7K
Andrea Barisani
Andrea Barisani@AndreaBarisani·
I want to go back in a world where documentation is like this.
Andrea Barisani tweet media
English
1
0
6
300
Jonas Vestberg retweetledi
🕳
🕳@sekurlsa_pw·
In 1979 a name was needed for an European intelligence cooperation. They looked at the Maximator beer they were drinking and that became the name. Source: ‘Maximator: European signals intelligence cooperation, from a Dutch perspective’ Bart Jacobs  tandfonline.com/doi/full/10.10…
🕳 tweet media🕳 tweet media
English
0
1
4
406
Jonas Vestberg retweetledi
Leo Tsaousis
Leo Tsaousis@LAripping·
New blog post out: We built an AI Vishing system in 7 days to show that Scattered Spider's helpdesk campaigns can be automated at mass scale, easily. (clip included 🔊) labs.reversec.com/posts/2026/02/…
English
3
13
36
3.4K
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@PyroTek3 I love the misplaced irony of this movie. The author's fascism are passed as jokes. Great book. Great movie. Different reasons.
English
0
0
1
19
Jonas Vestberg retweetledi
Mullvad.net
Mullvad.net@mullvadnet·
God save the Mullvad ads. This one got banned too, by The City of London. @rickygervais do you have any pro tips?
Mullvad.net tweet media
English
54
342
4.8K
77K
Jonas Vestberg retweetledi
Or Yair
Or Yair@oryair1999·
New blog & exploit about CVE-2025-29969 - RCE by Yarin Aharoni @safebreach Labs. Findings allow: ---- * Checking arbitrary paths existence (unfixed!). * Writing files remotely (RCE). ---- On ALL Windows & Windows Server computers in the domain! Repo - github.com/SafeBreach-Lab…
English
1
34
97
6.5K
Jonas Vestberg retweetledi
CVE
CVE@CVEnew·
CVE-2026-2731 Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via … cve.org/CVERecord?id=C…
English
0
1
0
182
Jonas Vestberg
Jonas Vestberg@bugch3ck·
@Wakedxy1 If you haven't discovered "CSRF to print-job" fun yet: well you are welcome 😁
English
1
0
3
1.2K
Wakedxy
Wakedxy@Wakedxy1·
During your pentest mission, please don’t make the same mistake I did. Add printer IPs to your exclusion list when running Nuclei. Otherwise, the printer will interpret every packet sent to port 9100 as a print job.
English
59
143
2.4K
82.1K
Jonas Vestberg retweetledi
Co11ateral
Co11ateral@co11ateral·
CVE-2026-21508 - Windows LPE via arbitrary COM object initialization The vulnerability essentially works by forcing a process running as system and that uses the undocumented function Windows_Storage!_SHCoCreateInstance, to create an arbitrary COM object of our choice. For this to happen the object must be associated with an already registered COM class that supports CLSCTX_INPROC_SERVER. Arbitrary COM object creation is archived by manipulating a CoCreateInstance call first argument #pentest #cve #redteam #dfir #blueteam
Co11ateral tweet media
English
1
54
258
15K
vx-underground
vx-underground@vxunderground·
> be me > find something interesting > poke with stick > interesting > google > find website that describes exactly what im doing > x86matthew HOW TF THIS MFER BEAT ME TO IT TWICE IN A ROW
English
17
12
825
36.7K
Jonas Vestberg retweetledi
vas
vas@vasuman·
Holy cow dude! Look at what the AI said on the social media for AI! Haha dude wow this is the singularity bro! Skynet bro! Generational psyop
vas tweet media
English
42
47
609
29.5K
Jonas Vestberg retweetledi
SpecterOps
SpecterOps@SpecterOps·
Identity security in restricted environments shouldn’t be limited to periodic reviews. BloodHound Enterprise on-premises enables continuous Identity Attack Path Management without cloud connectivity. Learn more ➡️ ghst.ly/4bXPNQe
SpecterOps tweet media
English
0
12
42
5.1K