hungtt28

662 posts

hungtt28

hungtt28

@hungtt28

Independent bug hunter

Katılım Ocak 2015
819 Takip Edilen1.1K Takipçiler
hungtt28 retweetledi
Jack Ren
Jack Ren@bjrjk·
A carefully structured, tiered root cause analysis for CVE-2025-43529 (JSC UAF). Spent quite some time refining the structure to make the reasoning explicit and readable. Shoutout to @jir4vv1t for his detailed analysis and exploit. github.com/bjrjk/CVE-2025…
English
2
32
133
11.6K
hungtt28 retweetledi
jir4vv1t
jir4vv1t@jir4vv1t·
iOS 26.1 Safari StoreBarrierInsertionPhase missing Upsilon escape to uaf proof-of-concept github.com/jir4vv1t/CVE-2…
English
2
18
66
4.9K
hungtt28 retweetledi
littlelailo
littlelailo@littlelailo·
Had a lot of fun reversing Coruna over the last couple weeks and decided it would be worth to write it all up before I forget - so enjoy :) littlelailo.github.io/writeups/corun…
English
4
89
271
45.6K
hungtt28 retweetledi
starlabs
starlabs@starlabs_sg·
Our newest team member @streypaws just dropped his first blog post! He peered into CVE-2026-0899, from patch to arbitrary r/w primitives No, it is not April Fool's joke from us starlabs.sg/blog/2026/04-c…
English
3
33
167
10.8K
hungtt28 retweetledi
SpecterOps
SpecterOps@SpecterOps·
Stop asking LLMs to “find vulns.” Start using them to understand code. @Sw4mp_f0x walks through using Claude Code as a force multiplier in app assessments - faster analysis, fewer false positives, better outcomes. Check it out: ghst.ly/4rA3uJd
English
4
167
830
50.8K
hungtt28 retweetledi
Dmitry Vyukov
Dmitry Vyukov@dvyukov·
syzkaller/syzbot now has AI agentic framework for kernel bug fix generation, bug assessment, security triage, POC generation, etc: groups.google.com/g/syzkaller/c/… Includes set of tools to build kernels, navigate/edit source, test reproducers, etc. Contributions/research are welcome.
English
1
39
126
11.2K
hungtt28 retweetledi
Security Bug Aggregator
Security Bug Aggregator@BugsAggregator·
[452605804][reward: $20000] V8 Sandbox Bypass: Wasm streaming compilation cache confusion via "double streaming" crbug.com/452605804
English
1
5
49
3.6K
hungtt28 retweetledi
Security Bug Aggregator
Security Bug Aggregator@BugsAggregator·
[454485895][reward: $50000] Incorrect Optimization of ArrayConstructor by Maglev Leads to Creation of Malformed JSArray Objects crbug.com/454485895
English
0
10
83
5.1K
hungtt28 retweetledi
Boris Cherny
Boris Cherny@bcherny·
I'm Boris and I created Claude Code. I wanted to quickly share a few tips for using Claude Code, sourced directly from the Claude Code team. The way the team uses Claude is different than how I use it. Remember: there is no one right way to use Claude Code -- everyones' setup is different. You should experiment to see what works for you!
English
925
5.9K
50.9K
9.2M
hungtt28 retweetledi
Xion
Xion@0x10n·
The most elegant V8 Wasm Turboshaft typer exploit that I've reported. This primitive converts **any** Wasm type confusion in **any type hierarchy** into fully controlled arbitrary type confusion - e.g. what happens if you type `null : ref extern`? RCE :) crbug.com/372269618
English
3
46
203
20.2K
hungtt28 retweetledi
Faith 🇧🇩🇦🇺
Faith 🇧🇩🇦🇺@farazsth98·
After reading @streypaws blog post on CVE-2025-38352, I ended up writing my own PoC for it. I also wrote a blog post on my approach to analyzing and recreating the PoC. Hopefully it is useful to others! See link in the reply tweet below!
Faith 🇧🇩🇦🇺 tweet media
English
2
34
184
37.1K