Faav

418 posts

Faav banner
Faav

Faav

@efaav

Hacker & Developer. Hunting bugs. Building https://t.co/qiMEJOUaRf & NameMC Extras.

Florida Katılım Kasım 2024
228 Takip Edilen1.3K Takipçiler
Faav
Faav@efaav·
Been grinding out on HackerOne and I beat @rez0__ somehow, not sure how long this'll last though... 😅 (USA Leaderboard)
Faav tweet media
English
7
0
117
11.7K
Faav
Faav@efaav·
@brutecat You are fucking insaneeeeeeeee 🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥🔥
English
0
0
2
678
Faav retweetledi
Lupin
Lupin@0xLupin·
I managed to RCE Fortune 500 companies and made over $50,000 with this technique. A new npm supply chain technique we just disclosed. The trick is dumb-simple. We call it npx Confusion. 🧵
Lupin tweet media
English
9
35
326
19.7K
DaviMatsuyama
DaviMatsuyama@davi1337_·
lately i keep thinking about how ai killed the fun of learning. solving hard things used to feel rewarding, now everything feels easier but emptier. ai made weak people stronger and strong people unstoppable, but also created this illusion that we’re learning when maybe we’re not
English
6
0
9
371
Faav retweetledi
phsi
phsi@phsiiii·
A few months ago I found an SSTI on a large media company's bug bounty program. I got duped on the original report by four minutes, but came back a few months later and found a bypass that ended up being writeup worthy. phsi.se/posts/chaining…
English
5
15
140
6.5K
Faav
Faav@efaav·
This month has been my best month in bug bounty so far and I got my first testimonial!
Faav tweet media
English
6
1
95
3.7K
Faav
Faav@efaav·
For the upside down one you just watch a Minecraft Twitch stream for a few minutes. The upright one you have to go to Twitchcon in person and: Pickup Your Inventory Ribbon. Receive an empty Inventory Ribbon at the Swag Bag kiosk near badge pickup. One (1) Inventory Ribbon per person. Collect Emeralds when you engage with Minecraft content. Collect Emerald Stickers by attending qualifying sessions, attending Minecraft Arena Meet & Greets, and/or completing certain activities. You'll get one sticker per qualifying session/activity. Place a sticker in an empty Inventory slot. When you collect 3 Emerald Stickers, you are ready to redeem for a cape code. Redeem for your cape code. Redeem your completed Inventory Ribbon at the Cape Trader in the Minecraft Village (located in the Minecraft Arena) to receive your Cape Card with a unique in-game code! Staff will scan your wristband prior to receiving the Cape Code, as the redemption is tied to your TwitchCon registration
English
2
0
6
451
Faav retweetledi
TrendAI Zero Day Initiative
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
TrendAI Zero Day Initiative tweet media
English
29
184
1.5K
259.9K
shubs
shubs@infosec_au·
cPanel's latest patch (11.134.0.26) for the pre-auth arbitrary file read issue (CVE-2026-29205) is incomplete. We made the call to not publish our research until a working patch is released. We are in touch with WebPro's security team.
English
2
21
171
23.8K
Faav retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai…
Aikido Security@AikidoSecurity

🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.

English
76
486
2.6K
2.4M