ll

30 posts

ll

ll

@llfamsec

Red Team & Linux

Katılım Eylül 2023
375 Takip Edilen101 Takipçiler
ll retweetledi
Minions
Minions@Minions·
here's looking at you, buddies. See Minions & Monsters, only in theaters July 1.
Minions tweet media
English
21
431
2.2K
77.2K
ll
ll@llfamsec·
It’s not easy to keep grinding on a side project after work🫠
English
0
0
0
75
ll retweetledi
Qualys
Qualys@qualys·
Qualys Threat Research Unit (TRU) discovered CrackArmor: 9 AppArmor flaws impacting 12M+ Linux systems since 2017. These enable root access & container breakouts. Patch your kernels now! Details: bit.ly/4s2c3O4 #Linux #Cybersecurity #CrackArmor"
Qualys tweet media
English
3
20
35
7.4K
ll retweetledi
Azrael
Azrael@azraelxuemo·
RCE video demo of cve-2026-24747
English
0
8
46
3.8K
ll retweetledi
V4bel
V4bel@v4bel·
@_qwerty_po and I exploited a VSock 1-day in Google kernelCTF back in *February*, securing $71,337 🥳 (CVE-2025-21756, exp237/exp249) And I’ve just published the write-up: github.com/google/securit… A kernel developer reviewing a patch for a separate VSock bug I submitted accidentally discovered this vulnerability, and we were the first to exploit it. PoC 💻: root on Ubuntu 24.04
English
2
49
209
15.7K
ll retweetledi
h0mbre
h0mbre@h0mbre_·
this is so insane. kCTF has a first-come-first-serve policy when it comes to 0day bounties when an instance releases. this team hand crafted a proof of work solver with avx-512 instructions to beat everyone else with an 0day to the flag: anemato.de/blog/kctf-vdf
English
2
49
233
14K
Hussein Daher
Hussein Daher@HusseiN98D·
I spoke at @phdays – what a great event! Thanks for having me Moscow, see you next time. I'll publish the slides of my talk next week, stay tuned.
Hussein Daher tweet media
English
4
1
93
4.5K
ll retweetledi
Sean Heelan
Sean Heelan@seanhn·
I wrote-up how I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Link to the blog post below 👇
English
23
181
911
98.9K
ll retweetledi
sam4k
sam4k@sam4k1·
with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓 sam4k.com/page-table-ker…
English
5
79
296
16.7K
ll retweetledi
Sean Heelan
Sean Heelan@seanhn·
Bug 3 github.com/torvalds/linux… Fun fact: I found this one using o3 as a backend when evaluating if it was able to find a previous bug I had found. In ~100 runs it showed up twice. Afterwards I checked if Sonnet 3.7 could find it, and it can, but with 2.5x more false positives.
Sean Heelan@seanhn

Week 2 bug 2 was another remote UAF in ksmbd. This one is post-auth, although guest accounts can hit it. It's a straightforward "You forgot to null the reference" in the kerberos auth path. See commit message for details. github.com/smfrench/smb3-…

English
1
12
66
14.1K