sUb

96 posts

sUb banner
sUb

sUb

@sUb_c0ol

security enthusiast

Katılım Ocak 2026
270 Takip Edilen5 Takipçiler
sUb retweetledi
MERICA MEMED
MERICA MEMED@Mericamemed·
The representation of “minding my business, I don’t get paid enough for this “ 🤣
English
427
1.2K
42.3K
10.6M
sUb retweetledi
Satan
Satan@s8n·
Satan tweet media
ZXX
7
410
3.7K
45.6K
sUb retweetledi
hard.jpg
hard.jpg@hard__jpg·
hard.jpg tweet media
ZXX
8
112
790
13K
sUb retweetledi
ADHD Memes
ADHD Memes@ADHDForReal·
ADHD Memes tweet media
ZXX
8
308
2.1K
26.2K
sUb retweetledi
vx-underground
vx-underground@vxunderground·
Gamers when they see the word "kernel" but they don't understand that you can go deeper than kernel mode with blumber schlumpkie mode (enabled in the BIOS)
English
80
124
2.7K
76.2K
sUb
sUb@sUb_c0ol·
@notdan @djjackalope Showed up getting my daily DnB in and then stream ended quickly 🥲
English
1
0
1
17
sUb retweetledi
vx-underground
vx-underground@vxunderground·
I was notified just now that two nerds are having an actual fight in a pub tonight for the domain rights to Phrack-dot-org Like, they're going to put down Jui Jitsu mats and actually fight-fight Nerds have lost their mind bro
vx-underground tweet media
English
27
37
890
27.1K
sUb
sUb@sUb_c0ol·
@dominos @RobMckenzie71 Yeah they still cheap out on the driver's depends on franchise or corporate but yes their drivers get paid very little and hope to get tips which is never a guarantee but thats the way it goes I guess although I dont agree with it
English
2
0
0
11
sUb retweetledi
vx-underground
vx-underground@vxunderground·
Big news for Blue Team nerds That nerd who released those Microsoft 0days has created two new repos on GitHub with spooky sounding names indicating they will be releasing two new Windows 0days. Very cool github.com/Nightmare-Ecli…
English
35
209
1.8K
72.3K
sUb retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
31
382
1.5K
411.2K
sUb retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
139
954
6.4K
1.5M
sUb retweetledi
payloadartist
payloadartist@payloadartist·
Writeup by @0xAsm0d3us on the correct approach to utilise LLMs to find bugs. Can't agree more with what he said. You can't just go ask LLMs to find everything they can. Need to be brutally specific and start with something like known bug classes. #my-own-methodology" target="_blank" rel="nofollow noopener">devansh.bearblog.dev/needle-in-the-…
payloadartist tweet media
English
0
30
175
10.3K