vessial

353 posts

vessial

vessial

@vessial

Just security research,AI Infra Security/drones/baseband/vehicle hacking for fun.

China เข้าร่วม Mart 2009
493 กำลังติดตาม2.2K ผู้ติดตาม
vessial รีทวีตแล้ว
EXPMON
EXPMON@EXPMON_·
EXPMON has been updated to v20260202! This is a Detection Logic update, to provide decisive Detection Result against the ongoing Microsoft Office zero-day exploits CVE-2026-21509. For example, below are two real, in-the-wild samples of the Office 0day which were just disclosed today: pub.expmon.com/analysis/31163… pub.expmon.com/analysis/31163… Previously, these samples were detected only via the Indicators (see x.com/HaifeiLi/statu…). Since this update, they will now be classified/shown as "Malicious - potential exploit CVE-2026-21509", easier for users to identify the threat. Enjoy the hunting!:) #expmon #CVE-2026-21509 #office #zeroday #0day #threatintel
EXPMON tweet media
English
0
7
24
7K
Tesla
Tesla@Tesla·
We pay for outstanding performance – not for promises. In 2018, shareholders approved a groundbreaking CEO Performance Award that delivered extraordinary value. At our Annual Meeting on November 6, Tesla shareholders can vote on a pay-for-performance plan designed to drive our next era of transformational growth and value creation. Seven years ago, @ElonMusk had to deliver billions to shareholders – now it’s trillions. This plan creates a path for Elon to secure voting rights and will retain him as a leader of the company for many years to come. But as explained below, Elon only receives voting rights after he has delivered economic value to you. Your vote matters. Vote “FOR” Proposal 4! For instructions on how to vote, please refer to your proxy materials or visit votetesla.com
English
635
1.9K
12.4K
1.2M
vessial
vessial@vessial·
Open source stm8 idapython disassembly plugin at github.com/vessial/stm8 , first version, you can update opcode parser if you needed
English
0
0
0
669
Oleg Kutkov 🇺🇦
Oleg Kutkov 🇺🇦@olegkutkov·
@__tim @noop_dev This requires complete disassembly of the ICE computer and a complex operation. I'm not ready for such experiments on the new expensive car.
English
1
0
2
258
Oleg Kutkov 🇺🇦
Oleg Kutkov 🇺🇦@olegkutkov·
The Ukrainian hacking community is kinda unique. I hate this, but I reached a dead end and had to ask for help (not free). For $300, they hacked my new car, installed proper navigation data with Ukraine, and locked the auto-update of this data so that Tesla would not be able to update it and break it again. The navi is working like a charm. Of course, they refused to share any technical details. But for me, it's an interesting technical challenge. I noticed that they accessed only the diagnostic Ethernet, used some custom software or script on the MacBook, and presumably performed a power cycle of the car (I had to exit the service area).
Oleg Kutkov 🇺🇦@olegkutkov

Making some fun with Tesla. Today's session was half-successful. I configured one crucial thing, but I can't roll back navigation data yet (from the pretty useless 2025 version to the 2019 version).

English
16
33
486
46.6K
vessial
vessial@vessial·
Developed by IDApython, IDA Pro built-in plugin only support 162 opcodes by default. I developed idapython plugin it can be fully supported 397 opcodes, almost 800 instructions statements, just diff with IDA built-in plugin disassembled results, it will open source soon.
English
0
1
1
615
vessial
vessial@vessial·
Now IDA Pro can fully support TI TMS320C28x Series DSP instruction Sets,including C28x assembly language instructions/fpu/fpu64/Viterbi,Complex Math and CRC unit(VCU)/VCRC/VCU-II/Fast Integer Division Unit(FINTDIV)/Trigonometric Math Unit (TMU)/Control Law Accelerator(CLA).
vessial tweet mediavessial tweet mediavessial tweet mediavessial tweet media
English
2
2
1
433
vessial
vessial@vessial·
Qemu fully Tesla model 3 EMMC dump emulation up, this is after 2021 model based on AMD Ryzen APU @greentheonly
vessial tweet mediavessial tweet mediavessial tweet mediavessial tweet media
English
7
23
209
27.2K
vessial
vessial@vessial·
@mikko this reply from Mars 😆
English
0
0
0
165
vessial รีทวีตแล้ว
Boris Larin
Boris Larin@oct0xor·
All the details about this vuln and much more will be revealed tomorrow by us (me, @bzvr_, @kucher1n) during our talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” at #37c3 (14:45 CET). There will also be a live stream. fahrplan.events.ccc.de/congress/2023/…
Boris Larin@oct0xor

Jailbreak and kernel debugging is coming to new iPhones! (Apple A12-A16 SoC’s < iOS 16.6)

English
51
168
841
318.4K
4B5F5F4B
4B5F5F4B@4b5f5f4b·
@vessial @greentheonly Looking forwards to more Tesla eastereggs from your sharing. BTW: Did you buy Tesla IVI from Xianyu platform?
English
1
0
0
458
vessial
vessial@vessial·
#Starlink satellite firmware dumped in nandflash, main component wifi_control developed by golang/google protobuf, go2exe, #spacex
vessial tweet mediavessial tweet mediavessial tweet media
English
2
3
12
0
vessial
vessial@vessial·
@windknown Kodos to you, I still remembered your xcon2008 presentation, I am an audience there and get a lucky gift PSP4, good future to you Hao!
English
0
0
1
0
Hao
Hao@windknown·
My very first tech talk at XCON2008 & last one at MOSEC2020. Time to retire from vulnerability/exploit research work 🫶🏻
Hao tweet mediaHao tweet media
English
6
8
109
0
vessial รีทวีตแล้ว
Taszk Security Labs
Taszk Security Labs@TaszkSecLabs·
RCE in MediaTek basebands: in today's blogpost, we explore more CSN1 parsing bugs, this time in MTK's basebands running on MIPS16e2, and analyze how to exploit heap overflows in this baseband OS! labs.taszk.io/articles/post/…
English
1
111
269
0
Oleg Kutkov 🇺🇦
Oleg Kutkov 🇺🇦@olegkutkov·
Reconstructed block diagram of the #Starlink Dishy CPU. Sure, it might not be 100% correct, but this is how it looks in general.
Oleg Kutkov 🇺🇦 tweet media
English
3
14
96
0