Mohammad Kaif

2K posts

Mohammad Kaif banner
Mohammad Kaif

Mohammad Kaif

@_mkahmad

Android | API | Web Security Researcher

เข้าร่วม Kasım 2018
1.6K กำลังติดตาม1.8K ผู้ติดตาม
Mohammad Kaif
Mohammad Kaif@_mkahmad·
"Bounty awards are determined and paid based on what is demonstrated in the report, not on claims made in the report but not proven with evidence or proof of concept." - Apple Security Team The POC:
English
0
0
6
328
Mohammad Kaif รีทวีตแล้ว
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
>use a security tool in CI get pwnd >update your dependencies get pwnd >do nothing, ignore security win
English
36
138
2.2K
54.8K
Mohammad Kaif รีทวีตแล้ว
Calif
Calif@calif_io·
Reverse engineering Apple’s silent security fixes, by @blacktop__ We grabbed the latest iOS update, and diffed it with ipsw. The diff reveals at least two security-relevant changes that were shipped quietly. open.substack.com/pub/calif/p/re…
English
1
47
264
63.4K
Mohammad Kaif รีทวีตแล้ว
Bugscale
Bugscale@bugscale·
If you missed the talk at @1ns0mn1h4ck , our latest blog post is now available for you to explore. In this post, researchers @Hacker_Chai and @SachaKozma detail their journey to a 1-click RCE exploit on the Samsung S25 phone. Check it out here: bugscale.ch/blog/shoot-for…
English
1
33
100
10.1K
Mohammad Kaif รีทวีตแล้ว
Mandiant (part of Google Cloud)
Google Threat Intelligence Group has identified DarkSword, a new iOS exploit chain leveraging six zero-day vulnerabilities. Multiple threat actors are actively using it to deploy malware payloads. Update your devices or enable Lockdown Mode. 👉 bit.ly/4bRveEz
Mandiant (part of Google Cloud) tweet media
English
4
69
207
20.6K
Lupin
Lupin@0xLupin·
WE DID IT ! WE RAISED $5.9M PRE-SEED 🥳🎉🎉
English
77
39
419
38.1K
Mohammad Kaif
Mohammad Kaif@_mkahmad·
Looking for xss or open redirect on *[.]apple|icloud[.]com
English
1
0
11
4.6K
Mohammad Kaif รีทวีตแล้ว
Google VRP (Google Bug Hunters)
📢 Interested in AI and agent security at Google🛡️? This post looks at how we mitigated the risk of URL-based data exfiltration through provenance checks and sanitization – effectively blocking a prompt injection-based exploitation vector. bughunters.google.com/blog/mitigatin…
English
4
17
107
19.4K
Mohammad Kaif
Mohammad Kaif@_mkahmad·
@ITSecurityguard Sure! I will try and let you know! Btw I have to pull reports from OPPO and Tecno SRC , I have worked on them for several years, haha!
English
0
0
0
90
Patrik Grobshäuser
Patrik Grobshäuser@ITSecurityguard·
New series on using Claude for bug bounty 👀. sync your hackerone reports, cross-referencing past findings against new targets etc. The actual workflow, not the LinkedIn fantasy. Feedback from AI-maxers always welcome ❤️ clawd.it/posts/11-teach…
English
4
27
182
10.3K