Matheus Vrech

382 posts

Matheus Vrech banner
Matheus Vrech

Matheus Vrech

@vrechson

CTFs, security, and whatever broke today

Katılım Şubat 2019
419 Takip Edilen773 Takipçiler
Sabitlenmiş Tweet
Matheus Vrech
Matheus Vrech@vrechson·
Found a full-blown CSP bypass on the current version of Firefox (69). Not working on the beta version. PoC: abrasax.club/?payload=<object data="javascript:alert(1)"></object> #bugbounty
English
3
42
96
0
Matheus Vrech retweetledi
TRAMOIA
TRAMOIA@tramoia_sh·
@caueobici @girorme1 Historias que seu avo nunca lhe contou sobre firebase - @vrechson & @Highustavo Imagens sao dificeis - Thumbor 0days - @caioluders SunCodeQL - Resolvendo a Complexidade do Frontend com SAST - m4z4r0p3 m4qu1n4 d0 mund0.ANS - gld
Português
0
3
11
974
Matheus Vrech retweetledi
All day Astronomy
All day Astronomy@forallcurious·
🚨: This is Tatiana Sampaio, a Brazilian scientist who restored movement in six paraplegic patients.
All day Astronomy tweet mediaAll day Astronomy tweet media
English
233
8.6K
56.1K
2.3M
Matheus Vrech retweetledi
Hacktron AI
Hacktron AI@HacktronAI·
We found a RCE in Google's AI code editor Antigravity - $10000 Bounty Link to the blog in comments:
Hacktron AI tweet media
English
17
97
567
66.6K
Matheus Vrech retweetledi
Luan Herrera
Luan Herrera@lbherrera_·
I began looking into browser security issues again in 2026 and while reviewing extension permission APIs, I noticed that the default declarativeNetRequest API (which only requires permission to block content on all pages) can be leveraged into a side-channel attack. This permission ends up allowing an extension to infer the full URL of open tabs without requesting the chrome.tabs permission, and it can also leak the full URL of cross-origin redirects. Unfortunately, fixing this issue has been deemed unrealistic by Chrome, and the risk has been accepted, so it is worth keeping this in mind when granting content-blocking permissions to browser extensions. The complete public report can be found at issues.chromium.org/issues/4792584….
English
9
13
105
8.1K
Matheus Vrech retweetledi
Alex Moshkov
Alex Moshkov@amoshkov·
🟥 Positive Hack Talks → São Paulo 🇧🇷 Dec 10th, 2025 🗣️ Speakers — submit papers (flights/hotel covered). CFP link in thread 👇 💻 Cybersecurity community — join our most community-driven event. ➡️ phtalks.ptsecurity.com/saopaulo Free · 8 talks · limited spots #PHTalks
Alex Moshkov tweet media
English
3
34
87
17.7K
Matheus Vrech
Matheus Vrech@vrechson·
@sanseverini amiga se precisar de ajuda para recuperar o insta posso tentar ver oq ta rolando
Português
1
0
0
32
ex miss bumbum de Salesópolis
Consegui bloquear quase todas as contas (as que as senhas poderiam estar comprometidas) e consegui trocar as senhas dos e-mails. Ainda não recuperei o Instagram, apesar de ter conseguido trocar a senha também. O app do governo: nem sei pra que tinha, não serviu pra nada.
Português
2
0
2
260
ex miss bumbum de Salesópolis
Aproveitar que tô esperando atendimento da @TIMBrasil no shopping pra contar o que aconteceu: Ontem tava indo no show de amigos, lá pelas 21h30, subindo a Belmiro Braga sentido Casa Rockambole. Tava no celular com um amigo, o Rafa. Eu tinha ligado pra ele de fone, mas a (1)
Português
1
0
3
1K
Matheus Vrech retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Securing @gumroad with Hacktron AI Three months ago, Hacktron was still early. @HacktronAI and @rootxharsh were finding 0-days targeting specific vulnerabilities on OSS software. Then we ran a full pentest-style scan on a big open-source project. The results were insane. 🧵
English
5
19
205
30.3K
Matheus Vrech
Matheus Vrech@vrechson·
@skaesun eu tbm fiz isso kkkk depois fiquei meio triste quando comecei o original pq a qualidade da gravação é pior mas o final é mtooooo melhor
Português
1
0
0
49
paola
paola@skaesun·
eu assisti steins gate errado eu assisti só o steins;gate 0 ACHANDO QUE TINHA ACABADO POR ALI E QUE ERA ISSO eu quero me churrascar QUEM FAZ ISSO mas tô feliz q tenho mais pra assistir mas pqp culpa da crunchyroll fds
GIF
Português
2
0
8
715
Matheus Vrech retweetledi
Luan Herrera
Luan Herrera@lbherrera_·
Seeing paulosyibelo.com/2024/12/double… in PortSwigger's top 10 made me remember a trick I found a few years ago, where if a button has an ID attribute, you can trick users into submitting it by holding enter (or space). Guess lots of places are affected 😅 PoC: lbherrera.me
English
3
12
91
13.3K
Matheus Vrech retweetledi
RedTeamVillage
RedTeamVillage@RedTeamVillage_·
We're thrilled to share that we'll be joining @h2hconference this December in Brazil, and we want YOU to be a part of it! 🎉 Our Call for Papers is officially open! sessionize.com/rtv-hackers-2-… We can't wait to see what you've got and to connect with all of you in person. See you there for an unforgettable time! 🙌✨ #H2HConference
RedTeamVillage tweet media
English
2
29
81
9.2K
Matheus Vrech
Matheus Vrech@vrechson·
Hope to find a growing infosec community in blue sky, I would honestly be happier if I could move to another social network forever
English
0
0
0
171
Matheus Vrech retweetledi
Luan Herrera
Luan Herrera@lbherrera_·
Seeing that Pwn2Win isn't happening this year, here's an unreleased beginner-level XSS challenge I created for it (shouldn't be too difficult). lbherrera.me/challenge
English
3
13
47
4.9K