sshell

6.2K posts

sshell banner
sshell

sshell

@sshell_

AI offensive security at @RunSybil (prev. @BishopFox). security research. ccdc red team. tummy ache survivor.

Virginia, USA Katılım Haziran 2013
1.5K Takip Edilen10.4K Takipçiler
sshell retweetledi
shubs
shubs@infosec_au·
we're hiring two full stack engineers at @assetnote - tight knit team that's extremely passionate and capable, scanning millions of assets hourly for security issues. need to be located in australia, but fully remote. if you're interested, apply: searchlight.bamboohr.com/careers/238?so…
English
1
5
36
4.7K
sshell retweetledi
hashkitten
hashkitten@hash_kitten·
Seems that wp2shell PoCs are now floating around the internet, so we've published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself - slcyber.io/research-cente…
English
13
176
609
51.2K
sshell retweetledi
xEHLE
xEHLE@xEHLE_·
Props to the @assetnote team and especially @hash_kitten for this one. Even with lots of steering 5.6 it took quite a few hours to nail the full chain
English
0
3
45
5K
sshell retweetledi
hashkitten
hashkitten@hash_kitten·
I reported a pre auth RCE in Wordpress - it can be exploited with no preconditions, patch your instances! slcyber.io/research-cente…
English
31
229
1K
189.9K
sshell retweetledi
Joseph Thacker
Joseph Thacker@rez0__·
OKAY YALL! LAUNCH TWO! 🚀 rez0srascals.com I built an entire elearning platform... from scratch. 750+ lessons. 11 subjects. an AI tutor. a full AI dashboard for the parents. It can be used for home school, summer school, or just supplementally. 14 days free so go look!
Joseph Thacker tweet media
Joseph Thacker@rez0__

ALRIGHT, LAUNCH ONE!🚀 aisafetyforparents.com As a father of 3 kids who works in AI and Security, I'm always getting tons of questions about AI from other parents. So, I put all the answers in one place. It's a simple 10 day email-based course that "bottles up" everything you need to know about AI safety as a parent. I think you'll love it 😊 For the next 24 hours, you can use code LAUNCH to get 25% off as well! It would mean a lot to me if you shared this with someone you know who might need it or like it!

English
2
6
56
8.8K
sshell retweetledi
Assetnote
Assetnote@assetnote·
Our research team discovered a critical pre-authentication RCE inside ServiceNow by bypassing their scripting sandbox (CVE-2026-6875). You can read more here: slcyber.io/research-cente…
English
1
45
148
9.2K
sshell retweetledi
Sybil
Sybil@runsybil·
hottest day in 13 years and sybil happens to be in times square? coincidence? we think not
Sybil tweet mediaSybil tweet mediaSybil tweet media
English
1
4
13
767
sshell retweetledi
Ian Carroll
Ian Carroll@iangcarroll·
A fun SQL injection in 2026 with a bit of help from Claude! It is pretty crazy that simple unauthenticated vulnerabilities can still exist in core production systems like this. Technical details: ian.sh/fgt
Andy Greenberg (@agreenberg at the other places)@a_greenberg

Security researcher @iangcarroll found Claude could independently code an exploit to hack into Front Gate Tickets, the ticketing platform for almost every major US music festival from Lollapalooza to Bonnaroo. He could then issue any tickets at will. wired.com/story/claude-h…

English
4
26
168
23.3K
sshell retweetledi
Sybil
Sybil@runsybil·
.@DARPA gave 7 teams $135k to build custom AI systems that find and patch vulnerabilities. we achieved the same results with today's AI models and $600
English
1
5
15
7.5K
Brendan Dolan-Gavitt
Brendan Dolan-Gavitt@moyix·
I almost forgot to tell people we were doing this! Come hang out and retvrn to the better days of (extremely vulnerable) computing with @kallsyms and me this year and @SummerC0n :D We'll be popping calc on systems older than you are
Brendan Dolan-Gavitt tweet media
Julien Vanegue@jvanegue

Tickets for @SummerC0n surely are more expensive now that @moyix is a speaker! As is the tradition, I just got a bunch for the Bloomberg research team & interns. See you all soon at @littlefieldnyc

English
6
4
34
6.6K
sshell retweetledi
Patrik Grobshäuser
Patrik Grobshäuser@ITSecurityguard·
new research out! 🚢 We took apart CargoWise Webtracker, the customer portal in one of the most widely deployed logistics platforms in the world. Hardcoded keys, forged sessions, and a path all the way to pre-auth RCE. full writeup below. 👇🏻 slcyber.io/research-cente…
English
1
10
54
4K
sshell retweetledi
cje
cje@caseyjohnellis·
another @HillHackers in the books!
cje tweet mediacje tweet mediacje tweet mediacje tweet media
English
7
3
33
3.5K
cje
cje@caseyjohnellis·
@sshell_ @ufc oh so your flight got blinky lights, fireworks, and a B1 🥲
English
1
0
2
1.4K
sshell
sshell@sshell_·
watching the @ufc fight at the white house from the plane rn
sshell tweet media
English
1
0
9
1.4K