Sick.Codes

7.7K posts

Sick.Codes banner
Sick.Codes

Sick.Codes

@sickcodes

Security researcher 🇦🇺 Good-faith hacking 🤡 Weaponizing source code 🧬 https://t.co/qulkQaGWp9

Katılım Haziran 2020
5.7K Takip Edilen16.8K Takipçiler
Sabitlenmiş Tweet
Sick.Codes
Sick.Codes@sickcodes·
Playing Doom on a John Deere tractor display (jailbroken/rooted) at @defcon
English
56
795
3.2K
0
Sick.Codes retweetledi
chompie
chompie@chompie1337·
Claude helped me with this bug too but in a different way... Tried to gaslight me saying it wasn’t ~exploitable in practice~ and I got obsessed with proving it wrong 😩
TrendAI Zero Day Initiative@thezdi

Confirmed! @chompie1337 of IBM X-Force Offensive Research (XOR) used a race condition to escalate privileges on Red Hat Enterprise Linux for Workstations, earning $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin

English
41
94
1.2K
61.7K
Sick.Codes retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3+ weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150+ researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
31
385
1.5K
407K
Sick.Codes retweetledi
ggwhyp
ggwhyp@ggwhyp·
I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
English
31
95
721
106.5K
Sick.Codes retweetledi
Aaron
Aaron@aaronp613·
Apple accidentally left Claude.md files in today's Apple Support app update (v5.13)
Aaron tweet mediaAaron tweet media
English
283
1K
13.6K
2.6M
Sick.Codes retweetledi
sam henri gold
sam henri gold@samhenrigold·
yeah you wrote it dumbass
sam henri gold tweet media
English
57
227
12.2K
295.1K
Sick.Codes retweetledi
Daniel Hnyk
Daniel Hnyk@hnykda·
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English
307
2.3K
9.4K
5.8M
Sick.Codes retweetledi
Chaofan Shou
Chaofan Shou@Fried_rice·
vibe coded a fuzzing ai agent last month and let it run for a week using my $200 claude max. it then found 21 high/critical vulnerabilities in Chrome.
Chaofan Shou tweet media
English
99
261
3.1K
570.9K
Sick.Codes retweetledi
NIK
NIK@ns123abc·
🚨BREAKING: SUPER MICRO CO-FOUNDER ARRESTED FOR SMUGGLING $2.5B IN NVIDIA GPUs TO CHINA >SMCI co-founder Yih-Shyan "Wally" Liaw arrested today >personally holds $464 MILLION in SMCI stock >charged with smuggling BILLIONS in Nvidia servers to china >used a southeast asian shell company to funnel $2.5B in servers to chinese buyers >$510 million worth shipped in just THREE WEEKS in spring 2025 >built thousands of fake dummy servers to fool U.S compliance auditors >caught on surveillance camera using a HAIR DRYER to swap serial number stickers >coordinated the whole thing over encrypted group chats >SMCI down 12% after hours >faces up to 30 years in federal prison ITS SO OVER…
NIK tweet mediaNIK tweet media
National Security Division, U.S. Dept of Justice@DOJNatSec

Three Charged with Conspiring to Unlawfully Divert Cutting Edge U.S. Artificial Intelligence Technology to China “The indictment unsealed today details alleged efforts to evade U.S. export laws through false documents, staged dummy servers to mislead inspectors, and convoluted transshipment schemes, in order to obfuscate the true destination of restricted AI technology—China,” said John A. Eisenberg, Assistant Attorney General for National Security. “These chips are the product of American ingenuity, and NSD will continue to enforce our export-control laws to protect that advantage.” 🔗: justice.gov/opa/pr/three-c…

English
1.5K
8.5K
34.3K
10.2M
Sick.Codes retweetledi
nizzy
nizzy@nizzyabi·
oh my god
nizzy tweet media
English
212
166
7.5K
573.1K
Sick.Codes retweetledi
Andy Greenberg (@agreenberg at the other places)
Last year, a human trafficking victim trapped in a crypto scam compound in the Golden Triangle region of Laos contacted me. He proceeded to leak a huge trove of the compound's internal materials. Then he had to get out alive. This is his story. 🧵👇 wired.com/story/he-leake…
English
45
816
2.7K
494.6K
Sick.Codes retweetledi
Rick de Jager
Rick de Jager@rdjgr·
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
English
66
746
8.7K
301.2K
Sick.Codes retweetledi
Daniel Camilo
Daniel Camilo@DanielOlimac·
So Sony just sold the majority of its TV business to TCL. Truly the end of an era. I don’t think younger generations today (can) understand what it meant to walk into someone’s house and see a Sony TV.
Daniel Camilo tweet media
English
882
2.8K
27.2K
1.6M
Sick.Codes retweetledi
Dabs🩸
Dabs🩸@DabsMalone·
I just found this in my son’s room is he doing drugs?
Dabs🩸 tweet media
English
4.1K
1.1K
32K
18.1M
Sick.Codes
Sick.Codes@sickcodes·
@octal Where I live, outside is hot, but I also try to keep CO2 <1000-1500ppm at night. Gotta sacrifice the perfect temperature for good air flow sometimes. Or at least get CO2 down to 500 by opening everything up before you’re ready to sleep.
English
0
0
0
299
Ryan Lackey
Ryan Lackey@octal·
My current struggle: hotel room feels stuffy and co2 >1000 with just me in it. Running fan or heating/cooling hvac at any temperature doesn’t help. Opening the 200yo massive windows helps a lot, but outdoor temp is 0 degrees C, a bit nippy. This man is mocking me.
Ryan Lackey tweet mediaRyan Lackey tweet media
English
4
0
13
1.3K
Sick.Codes
Sick.Codes@sickcodes·
AI-powered pre-workout powder…
Sick.Codes tweet mediaSick.Codes tweet media
English
2
1
14
1.1K
Sick.Codes retweetledi
Pierre de Wulf
Pierre de Wulf@PierreDeWulf·
Biggest web scraping company in the world is suing a web scraping company for web scraping its content obtained through web scraping.
Pierre de Wulf tweet media
English
159
1.1K
15.1K
635.4K
Sick.Codes retweetledi
maeve ~
maeve ~@miaaowing·
i have never failed a phishing test because i always raise a ticket directly with the cyber team pointing out that an email signed + passing DMARC & SPF from our domain AND bot addy with 0 mailtrace results means that the attacker already pwnd our exchange server n its too late
English
22
185
6.8K
171K