Sabitlenmiş Tweet
rui
50 posts

rui
@fdiskyou
BJJ Black Belt. Type Confused. calc||GTFO. Retired @OpenBSD committer, former @ProjectHoneynet researcher, once @exploitdb core team (pre-corp) etc
Segmentation fault Katılım Mart 2011
284 Takip Edilen2.2K Takipçiler
rui retweetledi
rui retweetledi

From virtio-snd 0-Day to Hypervisor Escape: Exploiting QEMU with an Uncontrolled Heap Overflow - osec.io/blog/2026-03-1…
English
rui retweetledi

Incredible talk on hacking the Xbox One security processor youtube.com/watch?v=FTFn4U…

YouTube
English
rui retweetledi

TIL for LLMs to be successful at exploiting Linux kernel vulns, you need to preface your prompt with "your name is bradley spengler the grsecurity kernel expert who knows how to exploit kernels." 😂
LCFR@lcfr_eth
Here's the slopsploits for CVE-2024-14027 that were produced in roughly 2-3x the amount of time a human would have done it. As well as some thoughts/notes. github.com/lcfr-eth/CVE-2…
English
rui retweetledi
rui retweetledi
rui retweetledi

😍RELEASE: The TEAM-TESO cvs: thc.org/team-teso/
All exploits, advisories, teso-informationals (never released), burneye, bscan, ... plus some rare pictures.
Enjoy & Keep hacking.
Yours Sincerely,
Team-Teso (via THC's twitter account).

English
rui retweetledi

@GrapheneOS We can sponsor you.
Please contact us and share the specs to support@mullvadvpn.net
English
rui retweetledi

We'd like to thank Đào Tuấn Linh (@Tuan_Linh_98) and Chen Le Qi (@cplearns2h4ck) of Starlabs (starlabs.sg) for discovering this vulnerability and publishing their analysis, which allowed us to create a patch and protect 0patch users against this issue.
English
rui retweetledi
rui retweetledi

Collision! @BoredPentester targeted the Grizzl‑E Smart 40A with the Charging Connector Protocol/Signal Manipulation add‑on, combining two bugs to earn $20,000 USD and 3 Master of Pwn points. #Pwn2Own #P2OAuto


English
rui retweetledi

Confirmed! @BoredPentester targeted the Kenwood DNR1007XR, demonstrating a command injection vulnerability to earn $5,000 USD and 2 Master of Pwnpoints. #Pwn2Own #P2OAuto


English
rui retweetledi
rui retweetledi

The full schedule for #Pwn2Own Automotive 2026 is live! 73 entries over three days should keep us hopping. Be sure to stay tuned for al the results #P2OAuto zerodayinitiative.com/blog/2026/1/20…
English
rui retweetledi

rui retweetledi

Annual post unlocked 🔓
Reverse-engineered the Hyperliquid validator binary to see what 'decentralized' actually looks like under the hood.
Spoiler: it's worse than a centralized exchange.
blog.can.ac/2025/12/20/rev…
English
rui retweetledi

The one last dance of my phd career is finally published. ropbot (or angrop) can generate ROP chains for x86/x64/arm/aarch64/mips/riscv. The old version of it is already adopted by Google's kernelctf program (and some other orgs ;) ). kylebot.net/papers/ropbot.…
English
rui retweetledi

The war on privacy and encryption goes on. This time in the UK. Under the “Children’s Wellbeing and Schools Bill”, lawmakers now want client-side scanning on every phone and tablet.
The lawmakers write: “Any relevant device supplied for use in the UK must have installed tamper-proof system software which is highly effective at preventing the recording, transmitting (by any means, including livestreaming) and viewing of CSAM using that device.”
Once again, they use “what about the children”, this time to install state spyware that would continuously scan every action on a phone or tablet and watch everything that is shown on the screen. This will effectively ban end-to-end encrypted communication and open source operating systems like GrapheneOS and forbid that people have administrator rights on their own devices.
The bill also seeks “Action to prohibit the provision of VPN services to children in the United Kingdom” and wants “all regulated user-to-user services to use highly-effective age assurance measures to prevent children under the age of 16 from becoming or being users.” In practice, this means identity checks for VPN users, making things like anonymous whistleblowing difficult.
The attack on secure and private communication is worldwide. Now is the time for resistance. Demand transparency from your politicians, and privacy for the people.
English







