clem1 @_clem1
tail -f internet | grep exploit Joined June 2010-
Tweets860
-
Followers7K
-
Following535
-
Likes9K
We’re thrilled to announce Donncha Ó Cearbhaill (@DonnchaC) as our keynote speaker for HEXACON 2025! 💥 No doubt he has plenty of juicy stories up his sleeve 👾
If you've been keeping track on the Big Sleep bug tracker at goo.gle/bigsleep you might have noticed it lists more bugs now compared to last week. Including a "High impact issue in V8" :)
Exploited ITW (CVE-2025-6558)[427162086]Incorrect validation of untrusted input(transform feedback buffer modification) chromium-review.googlesource.com/c/angle/angle/… chromereleases.googleblog.com/2025/07/stable… Reported by Clément Lecigne(@_clem1) and Vlad Stolyarov(@vladhiewsha)
Leak hole PoC for Chrome in-the-wild vulnerability CVE-2025-6554 published yesterday: github.com/DarkNavySecuri…
After 6 months of responsible disclosure, proud to announce our team discovered 13 (mostly exploitable) vulnerabilities in Samsung Exynos processors! Kudos to @st424204, @n0psledbyte, @Peterpan980927 & @rainbowpigeon_ CVE-2025-23095 to CVE-2025-23107 📍 semiconductor.samsung.com/support/qualit…
Qualcomm June 2025 Security Bulletin docs.qualcomm.com/product/public… "There are indications from Google TAG that CVE-2025-21479, CVE-2025-21480, CVE-2025-27038 may be under limited, targeted exploitation"
This Video Can Exploit Your iPhone (CVE-2025-31200) youtu.be/nTO3TRBW00E?si…
🍏iOS 18.4.1 dropped fixing a CoreAudio memory corruption and PAC bypass stating “that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS.” support.apple.com/en-gb/122282
I found 2 UAF bugs in libxslt with Jackalope, let's find more together! The harness is now included in examples (link below). This also serves as a demo for two not very commonly used modes in Jackalope: grammar mutational fuzzing and sanitizer coverage. github.com/googleprojectz…
🚨 UPDATE YOUR DEVICES 🚨: Amnesty International uncovers sophisticated zero-day exploit affecting billions of Android devices. Cellebrite's Linux USB exploit was used to unlock the phone of a Serbian youth activist, targeted in December 2024 **after** previous reports abuses
I tweeted before about the Apple CoreAudio issues found by Google TAG. Well, the fuzz harness used to find these issues is now included in Jackalope examples, see github.com/googleprojectz… . Happy fuzzing! :)
I tweeted before about the Apple CoreAudio issues found by Google TAG. Well, the fuzz harness used to find these issues is now included in Jackalope examples, see github.com/googleprojectz… . Happy fuzzing! :)
BREAKING | WhatsApp has revealed that nearly 100 journalists and civil society members were targeted by Israeli spyware company Paragon Solutions, which used a “zero-click” method to secretly infect devices. The spyware, Graphite, provides full access to compromised devices,…
The latest Apple security update contains fixes for three CoreAudio issues (CVE-2025-24160, CVE-2025-24161, CVE-2025-24163). These were found by Google Threat Analysis Group using Jackalope fuzzer.
As a New Year resolution, consider applying to Project Zero :)
As a New Year resolution, consider applying to Project Zero :)
🚨 BREAKING: Amnesty’s latest report on digital surveillance in Serbia: new *NoviSpy* spyware discovered; zero days identified and patched; and first evidence showing use of Cellebrite UFED forensic products to unlock phones to then infect with spyware. 🧵
If you've ever wondered if one can determine a vuln from just the kernel panic logs, @__sethJenkins (feat. @tehjh & @benoitsevens) have something to share: googleprojectzero.blogspot.com/2024/12/qualco… Great to collaborate with @amnesty, find vulns and get them fixed: securitylab.amnesty.org/latest/2024/12…
Apple patches two 0days marked as exploited on Intel-based Macs. Also fixed in new iOS 18.1.1 securityweek.com/apple-confirms…
Another big step towards becoming a security boundary: today we’re expanding the VRP for the V8 Sandbox * No longer limited to d8 * Rewards for controlled writes increased to $20k * Any memory corruption outside the sandbox now in scope bughunters.google.com/about/rules/ch… Happy hacking!
The #HEXACON2024 talks have started to trickle in on YouTube, go check them out 🔥: youtube.com/playlist?list=…
🚨New Report🚨 Mythical Beasts and Where to Find Them: Mapping the Global Spyware Market and its Threats to National Security and Human Rights. Explore connections between spyware vendors, suppliers, & supply chains in 42 countries 🌎 Dive deep here: dfrlab.org/2024/09/04/myt…

chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
Shane Huntley @ShaneHuntley
17K Followers 1K Following Security / tech guy. Google Threat Intelligence Group but tweets are my own.
Maddie Stone @maddiestone
61K Followers 804 Following Security Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
Alex Plaskett @alexjplaskett
12K Followers 571 Following Security Researcher | Pwn2Own 2018, 2021, 2022, 2024 | Posts about 0day, OS, mobile and embedded security.
h0mbre @h0mbre_
15K Followers 641 Following # Exploit Reliability Engineer # Developing a full-system snapshot fuzzer: https://t.co/mfVXhwoGYD # Avi: https://t.co/3fsQfVprCf
Ivan Fratric 💙💛 @ifsecure
18K Followers 207 Following Security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own. Backup @[email protected]
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Ptrace Security GmbH @ptracesecurity
59K Followers 867 Following Empowering IT Security Professionals through Hands-On Online Courses.
Richard Johnson @richinseattle
18K Followers 3K Following Computer Security, Reverse Engineering, and Fuzzing; Training & Publications @ https://t.co/mloVP6rPB7; hacking the planet since 1995; Undercurrents BOFH
kmkz @kmkz_security
19K Followers 2K Following Offensive Security, pom-pom girl... Who cares ?? Bourbon Offensive Security Services | BOSS
Alisa Esage Шевч�... @alisaesage
38K Followers 101 Following Independent Hacker & Researcher, Owner of Zero Day Engineering @zerodaytraining • Pronounced ‘is edge’
Samuel Groß @5aelo
24K Followers 501 Following Working on Project Zero, Big Sleep, and V8 Security. Personal account. Also @[email protected] and https://t.co/aVitnPjBie
Will Dormann is on Ma... @wdormann
26K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
Greg Linares (Laughin... @Laughing_Mantis
37K Followers 2K Following 20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
John Hultquist @JohnHultquist
29K Followers 1K Following Chief Analyst, Google Threat Intelligence Group. @CYBERWARCON and @SLEUTHCON founder. Johns Hopkins professor. Army vet.
David Weston (DWIZZZL... @dwizzzleMSFT
25K Followers 2K Following Corporate Vice President, OS Security and Enterprise @Microsoft
Andy Nguyen @theflow0
61K Followers 446 Following The opinions stated here are my own, not those of my company.
Anantkumar Joshi @w1r3sh65rk
317 Followers 2K Following
Jose Perez Alegre @JosePerezAlegre
5 Followers 60 Following Application Security. Strength, conditioning, health & performance. Personal account.
JohanB @JohanBrun__
27 Followers 337 Following
bells @bellafusari1
1K Followers 296 Following An ellie waltman fanpage with a knack for breaking software. @[email protected] + https://t.co/QXhPParXGV. @greynoiseio snuggie owner. TWEETS MY OWN
G. @fredric44554455
2K Followers 2K Following أينبغي لهذا العذاب أن يعذّبنا مادام يمنحنا لذّة أعظم ؟ خرايي على NASA
me @me8483612944451
3 Followers 667 Following
novelcherry @novelcherry
3 Followers 108 Following I like javascript engines LITERALLY just some GUY (She/Her)
Oscar @OscarBataille
156 Followers 612 Following
Nina @Luna_0xFF
0 Followers 226 Following
Leo @Itz_L30
979 Followers 1K Following Security Researcher | Detection Engineering #CTI | #threatintel Progress. Not perfection.
CeeBam @cee_bam4141
0 Followers 91 Following
desnecessario1555 @cinquentaoitoum
0 Followers 716 Following
Shina Mashiro @ShiinaaM
403 Followers 3K Following Microsoft Sentinel Enthusiast | 4n6 Investigator | Cloud Security | 🇮🇩 S.Kom
fittesi @fitteso
1 Followers 538 Following
el_draggo @el_draggo
3 Followers 282 Following
Hugo @Hugo38413820636
0 Followers 2K Following
Luiza One @St5melodNor
2 Followers 34 Following
Oxdine @DINESHPrathi12
233 Followers 7K Following #CybersecurityResearcher #Ethical Hacking #Pentester #IoT #CodeReview #WirelessSecurity #Automotive #NatureEnthusiast
carolena jack @CarolenaJa72890
0 Followers 90 Following
Endless Router Bugs @router_bugs
113 Followers 157 Following Expect better from your router. Sponsored by Supernetworks (https://t.co/esdXjZWwso)
James Ibrahim @JamesIb54140322
55 Followers 3K Following
Majed Refaea @Majed_Refaea
54 Followers 372 Following Those who do not understand true pain can never understand true peace.
Nitesh Surana @_niteshsurana
689 Followers 1K Following Cloud Research w/ Trend Micro | Opinions/retweets are personal reflections | Metalhead | If you can, be kind.
jocker @DavidSpid12189
1 Followers 950 Following
Ashutosh Singh @0xAshutosh
264 Followers 2K Following @Skyhighsecurity ex Quantiphi Software Engineer & Security Researcher exploring new Technologies Passionate Coder 3x GCP AI Enthusiast, #coder
Johnny @Luckyrocky2028
254 Followers 7K Following Stay Hungry, Stay Foolish. 只有自律的人才能得到真正的自由。|No Politics.
Almog @k33p_R3AL
1 Followers 69 Following
Jopraveen @jopraveen18
601 Followers 494 Following { 22 y/o | Security Researcher @zoho | CTFs with @tamilctf | blogs - https://t.co/vbWKogNU2h , https://t.co/wAmKuwC68Q }
popuku @popuku777
0 Followers 21 Following
State of Statecraft C... @what_is_sos
252 Followers 506 Following 🎖️State-Sponsored Threats Conference 🗓️ October 28, 2025 - Brussels, Belgium ⏰ CFP CLOSES SEPTEMBER 1. #what_is_sos
Beaudin Storniolo @S3901xom
6 Followers 162 Following
Slibzz @slibzz
151 Followers 416 Following 23 yo 🇫🇷 | your energetic silly green fluffy boy 🌿 friendly come talk
Ⓜ 🅾 ⓗⓐ... @mohamedelshbly1
9K Followers 2K Following "سنك في البطاقه غير سنك في المرايا ، غير سنك مع حد بتحبه ،غير سنك و أنت فرحان، غير سنك و أنت زعلان، جوا عمرك عمر تاني
Ching-Wei Huang @Terry12341234
13 Followers 182 Following TW / CTF Pwner@Starburst Kiwawa / Languages: English & Chinese / Interest in browser security
一只小菜鸡🐔 @2E61c5lzQaMNIEt
1 Followers 307 Following
Piotr Bazydło @chudyPB
4K Followers 307 Following Principal Vulnerability Researcher at watchTowr | Previously: Zero Day Initiative | @[email protected]
justsec @justsec__
3 Followers 122 Following
Norbert @NB1r0
60 Followers 3K Following
arip petits @AripPetits
5 Followers 1K Following
krypthon77777 @YKadid51805
0 Followers 40 Following
chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
0xor0ne @0xor0ne
81K Followers 514 Following | CyberSecurity | Reverse Engineering | C and Rust | Exploit | Linux kernel | PhD | My Tweets, My Opinions :) |
Trend Zero Day Initia... @thezdi
83K Followers 16 Following Trend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Shane Huntley @ShaneHuntley
17K Followers 1K Following Security / tech guy. Google Threat Intelligence Group but tweets are my own.
Project Zero Bugs @ProjectZeroBugs
35K Followers 0 Following A bot that posts the latest blog posts and disclosures from Google's Project Zero
Maddie Stone @maddiestone
61K Followers 804 Following Security Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
[email protected]... @0xdea
14K Followers 19 Following When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
Alex Plaskett @alexjplaskett
12K Followers 571 Following Security Researcher | Pwn2Own 2018, 2021, 2022, 2024 | Posts about 0day, OS, mobile and embedded security.
lcamtuf @lcamtuf
38K Followers 498 Following Substack: https://t.co/yFvmNisGW3 Homepage: https://t.co/iFAXZxCO5H
Synacktiv @Synacktiv
20K Followers 271 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
Ivan Fratric 💙💛 @ifsecure
18K Followers 207 Following Security researcher at Google Project Zero. Author: Jackalope, TinyInst, WinAFL, Domato. PhD. Tweets are my own. Backup @[email protected]
mdowd @mdowd
32K Followers 747 Following Internet Hacker. Founder of @vigilant_labs. Previously, co-founder of Azimuth Security (now L3Harris Trenchant)
offensivecon @offensive_con
26K Followers 2 Following OffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.
Alisa Esage Шевч�... @alisaesage
38K Followers 101 Following Independent Hacker & Researcher, Owner of Zero Day Engineering @zerodaytraining • Pronounced ‘is edge’
Samuel Groß @5aelo
24K Followers 501 Following Working on Project Zero, Big Sleep, and V8 Security. Personal account. Also @[email protected] and https://t.co/aVitnPjBie
starlabs @starlabs_sg
9K Followers 20 Following A Singapore company that discovers vulnerabilities to help customers mitigate the risks of cyber attacks. Organisers of @offbyoneconf
simo @_simo36
7K Followers 116 Following
watchTowr @watchtowrcyber
9K Followers 13 Following watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.
Endless Router Bugs @router_bugs
113 Followers 157 Following Expect better from your router. Sponsored by Supernetworks (https://t.co/esdXjZWwso)
Piotr Bazydło @chudyPB
4K Followers 307 Following Principal Vulnerability Researcher at watchTowr | Previously: Zero Day Initiative | @[email protected]
Khang Phan @pivik_
382 Followers 160 Following
Khoa Dinh @_l0gg
2K Followers 119 Following
Scott Bauer @ScottyBauer1
3K Followers 594 Following I find 0 days. Android/Linux Kernel/Crap written in C. Will trade 0 days for bottles of DRC
DARKNAVY @DarkNavyOrg
2K Followers 50 Following Cybersecurity enthusiasts from DARKNAVY. Achieve, Analyze, Attack *Oops.
Gabby Roncone 🇺�... @gabby_roncone
5K Followers 1K Following hunting russian apt cyber ops @Mandiant @GoogleCloud. views expressed here are mine, not my employer’s. she/her.
Patrick @dub5p
216 Followers 206 Following Cyber Security Researcher @Google TAG. Tweets are my own. Also: Triathlete, BJJ, speedcubing, 🥦
Chrome Releases Blog @_ChromeReleases
311 Followers 0 Following Feed for the Google Chrome Releases Blog.
Austin Larsen @AustinLarsen_
1K Followers 1K Following Principal Analyst @Google Threat Intelligence Group
1377 High-yield Nukes @buptsb
2K Followers 1K Following
Dan Perez @MrDanPerez
4K Followers 1K Following 🇨🇳Mission TL @Google | #Malware Naming Wizard | #Attribution Connoisseur | All tweets are my own. #ThreatIntel #APT
Andrew Thompson @ImposeCost
39K Followers 1K Following Head of Research and Discovery (RAD) @Google Threat Intelligence Group via @Mandiant acquisition. Posts are attributable to me—not my employer. Former @USMC.
SinSinology @SinSinology
13K Followers 674 Following Pwn2Own 20{22,23,24,24.5,25,25.5}, i look for 0-Days but i find N-Days & i chase oranges 🍊
Calif @calif_io
1K Followers 12 Following Official account of https://t.co/KTEDnC3tKt. We are hiring https://t.co/Kb2bn8lSsP.
sha1lan @sha1lan
232 Followers 2 Following
DistrictCon @DistrictCon
992 Followers 26 Following A new DC hacker conference: Bringing together builders, breakers, and fixers to do cool shit. 🪩 Year 1: January 24-25, 2026 🪩 https://t.co/qYKu4hl0Uj
Omer Benjakob @omerbenj
6K Followers 996 Following Disinfo/cyber reporter @Haaretz @haaretzcom 📰 #TeamJorge #ProjectPegasus ■ Wikipedialogist ■ Covering knowledge in age of disinfo ■ Research fellow @lpiParis_
. @R00tkitSMM
10K Followers 713 Following
Michael Genkin 🇮�... @Drag0nR3b0rn
354 Followers 1K Following An opinionated geek. Believes a better world is a possibility. Not afraid of revolutions. Willing to embrace chaos. A jack of many trades, a master of some.
SSD Secure Disclosure @SecuriTeam_SSD
24K Followers 2 Following SSD provides the support you need to turn your experience uncovering security vulnerabilities into a highly paid career. [email protected]
Tom Ritter @TomRittervg
3K Followers 393 Following Firefox Security. Also: Exploits, Mitigations, Crypto, Privacy, Pseudonymity & Anonymity, Tor https://t.co/77PxWQYyJV
0xTen @_0xTen
1K Followers 843 Following android/linux kernel @vigilant_labs • prev blockchain @osec_io • ctf/pwn @cor_ctf + @eltctfbr
scryh @scryh_
2K Followers 245 Following Cloud Vulnerability Research at Google. Opinions are my own.
Andrey Konovalov @andreyknvl
7K Followers 783 Following Security engineer at https://t.co/027VXUlgOx. Focusing on the Linux kernel. Maintaining @linkersec. Trainings at https://t.co/D5MrxmYimS.
exploits.club @exploitsclub
2K Followers 110 Following A VR, RE, and Exploit Dev weekly newsletter | Join the club Contact: [email protected]
Interrupt Labs @InterruptLabs
3K Followers 86 Following We’re here to provide world-leading vulnerability research and research capabilities. From browsers, mobile, automotive and everything in between.
patate @patateQbool
699 Followers 304 Following
Nasko Oskov @nasko
3K Followers 1K Following Security geek with his own views and opinions. Hacking on Chromium to make it more secure, increasing the cost for attackers. @[email protected]
Jared Semrau @JaredSemrau
172 Followers 42 Following Director, Vulnerability & Exploitation @Mandiant Intelligence Views are my own
Qrious Secure @qriousec
1K Followers 3 Following Debugger is main vehicle to satisfy our boundless Qriousity. A non-profit 🇻🇳 hackers' club driven by passion.
Ben Read @BenSRead
4K Followers 574 Following Director of Cyber-Espionage Analysis: @Mandiant | Adjunct Prof: @GeorgetownCSS | Views my own.