makelaris

5.2K posts

makelaris banner
makelaris

makelaris

@makelariss

Building worlds where hackers play. 🏴 Head of CTFs @hackthebox_eu | Global cyber competitions + enterprise training | he/him

Thessaloniki, Greece Katılım Temmuz 2016
2.6K Takip Edilen1.2K Takipçiler
makelaris retweetledi
Xclow3n
Xclow3n@xclow3n·
Spent a week testing AI for vulnerability research. 14 confirmed bugs in 20 min on one target. 5% hit rate on a hardened one. Same AI, same setup. 4 approaches, what worked, what failed, why target selection matters more than model sophistication. xclow3n.github.io/post/7
Xclow3n tweet media
English
5
85
434
33.3K
makelaris retweetledi
Mr.Z
Mr.Z@zux0x3a·
I am releasing a new toolkit I built for IIS-based lateral movement and code execution within IIS worker pool process's memory. Phantom ASPX Loader & PhantomLink -- a two-part toolkit for reflectively loading native DLLs into IIS w3wp.exe worker processes via ASPX. github.com/zux0x3a/Phanto…
GIF
English
4
78
246
16.9K
makelaris retweetledi
Xclow3n
Xclow3n@xclow3n·
Discovered 3 HTTP request smuggling vulnerabilities and 1 cache poisoning vulnerability in Cloudflare’s Pingora reverse proxy, all exploitable under the default configuration. These issues resulted in 2 Critical CVEs and 1 High-severity CVE. xclow3n.github.io/post/6
English
3
45
207
37.7K
makelaris retweetledi
pashov
pashov@pashov·
🚨Ethereum Developers: you can now install your first AI Auditor in 1 minute - fully autonomous, available 24/7, with multiple sub-agent helpers. Open Source. FREE to use (with your AI model) and already finding vulnerabilities in smart contracts. Link below🫡
pashov tweet media
English
178
263
1.5K
212.6K
makelaris retweetledi
Ruben Groenewoud
Ruben Groenewoud@RFGroenewoud·
New blog: Hooked on Linux — Rootkit Taxonomy, Hooking Techniques and Tradecraft Part 1 of our Linux rootkit series exploring kernel & userland rootkits and the hooking techniques they use (syscall/function hooks, ftrace, eBPF, inline patching). 🔗elastic.co/security-labs/…
English
0
27
74
8.4K
makelaris retweetledi
Tim Blazytko
Tim Blazytko@mr_phrazer·
Recently my RE workflow moved into sandboxed VMs where agents have full control over the environment. I needed an MCP server that runs headless in the same sandbox and exposes way more of the #BinaryNinja API than others. Here's the release: github.com/mrphrazer/bina…
English
3
50
269
37.2K
makelaris retweetledi
Devansh (⚡, 🥷)
Devansh (⚡, 🥷)@0xAsm0d3us·
A bunch of security issues I reported to better-hub. Disclosing as these should have been fixed now. Thanks for quick fixes @bekacru
Devansh (⚡, 🥷) tweet media
English
3
10
108
8.3K
makelaris retweetledi
Icare
Icare@Icare1337·
Apache FOP + Ghostscript = 💥 Bypassed PostScript escaping using non-breaking spaces (\xa0) to inject commands. Chained with CVE-2025-46646 for Windows RCE. @truffzor Apache won't fix it - just updating the docs 🤷 Full technical details @sigabrt9 offsec.almond.consulting/bypassing-apac…
English
1
3
37
2.4K
makelaris retweetledi
Devansh (⚡, 🥷)
Devansh (⚡, 🥷)@0xAsm0d3us·
New write-up! Bypassing egress filtering in BullFrog GitHub Action (using query pipelining feature of DNS over TCP) (link in comment)
Devansh (⚡, 🥷) tweet media
English
1
23
77
4.2K
makelaris retweetledi
Yotam Perkal
Yotam Perkal@pyotam2·
We disclosed a critical unauthenticated RCE chain in mcp-atlassian (4M+ downloads). CVE-2026-27826 - SSRF via Atlassian URL headers CVE-2026-27825 - Arbitrary file write → RCE Fixed in 0.17.0. Full breakdown 👇 blog.pluto.security/p/mcpwnfluence…
English
1
31
130
7K
makelaris retweetledi
quarkslab
quarkslab@quarkslab·
Why macOS AVs shouldn’t trust PIDs 😄🍏 - new post by @Coiffeur0x90 Intego X9: XPC validation falls back to PID → PID reuse + posix_spawn() shenanigans 😏 ⇒ confused deputy / privileged methods abused 🤡🧨 Lesson: PID ≠ identity. blog.quarkslab.com/intego_lpe_mac…
quarkslab tweet media
English
1
13
53
4.5K
makelaris retweetledi
Jorian
Jorian@J0R1AN·
Just a few days later, there's the next blog post for @AikidoSecurity! Another framework-level vulnerability this time affecting Astro, resulting in SSRF if an unvalidated connection can be made to the webserver. Read the details here: aikido.dev/blog/astro-ful…
English
0
16
87
3.8K
makelaris retweetledi
shubs
shubs@infosec_au·
Sometimes you spot a sink and know it's vulnerable, but proving it is a challenge. @SLCyberSec's team broke through layers of crypto to reach a pre-auth deserialization sink in OpenText Directory Services. Breaking the encryption was a journey. slcyber.io/research-cente…
shubs tweet media
English
1
68
242
17.7K
makelaris retweetledi
Martin Mielke
Martin Mielke@xct_de·
I was looking a bit onto why OPENROWSET is able to read privileged files (like the root flag on Signed @hackthebox_eu) when using Silver tickets on MSSQL. Turns out you can get SYSTEM access without potatoes by recovering the full token. vuln.dev/silver-ticket-…
English
1
35
119
7.9K