"CVE-2025-32463: sudo local privilege escalation via chroot option"
An attacker can leverage sudo's -R (--chroot) option to run
arbitrary commands as root, even if they are not listed in the sudoers file.
Sudo versions 1.9.14 to 1.9.17 affected.
openwall.com/lists/oss-secu…#infosec
Last year I discovered multiple bugs in virtio-net for VirtualBox (CVE-2023-22098, CVE-2023-22099, CVE-2023-22100) and wrote a 100% reliable VM escape using an out-of-bounds write (with ASLR defeat). Published the exploit code: github.com/google/securit…
"Reverse engineered an ESP32-based smart home device to gain remote control access and integrate it with Home Assistant."
Great write-up. Recommended read.
jmswrnr.com/blog/hacking-a…
"CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive"
Tl;Dr: "/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml" unauthenticated leads to the setup page, allowing you to create a new admin account.
horizon3.ai/cve-2024-0204-…#cve#poc#exploit
Got an ethical pentest for a kiosk-esque environment, but you're stuck in a browser? Have access to websites, but have a need to go deeper?
Look no further! With kiosk.vsim.xyz you have access to tools that enable lateral enum, calculator://, file browsing, and more!
In December, in macOS Sonoma, Apple fixed 15 video decoding vulnerabilities I reported. This is how these issues were found: github.com/googleprojectz…
Supply Chain Security: How the Figma security engineering team leveraged commit signatures and Okta Device Trust certificates to protect GitHub release branches.
figma.com/blog/how-we-en…#supplychain
My first blog post! It's about CVE-2023-4369, a $10,000 bug I found in ChromeOS in July. The bug used a chrome:// URL XSS to allow Chrome extensions to execute privileged code and read/edit downloaded files without user interaction. 👀 0x44.xyz/blog/cve-2023-…
The fact that they developed a complete zero-click to kernel chain, JUST to then force the device to open a web page to trigger the "real" chain, is the most bureaucratic exploit I can imagine 🙈
koeln.ftp.media.ccc.de/congress/2023/…
📯 Announcing the top Chrome VRP researchers for 2023: crbug.com/1509898 📯
Congratulations to everyone on the list! 🥳
Many thanks and much gratitude to our entire Chrome VRP researcher community and helping us make Chrome Browser & Chromium more secure for all users!
TInjA: CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight different programming languages.
github.com/Hackmanit/TInjA#pentest#bugbounty
18 Followers 390 FollowingIIT Bombay EE 2018 भारतीय
अभियंता, Network Security, Red Team, White Hat, Backend developer, Python, Lang-chain, LLM,
Bug Bounty,
DHH, Music production 🎁
2K Followers 4K FollowingAnálisis en tiempo real con IA de flujo y distribución de órdenes en criptoactivos, detectando zonas institucionales, apoyado en volumen y estructura.
5K Followers 3K FollowingLinux and OSS Lover, breaker of distributed systems, OIF II Veteran, Security Engineer, Martial Artist, wannabe chef, and lifelong student. Tech is my passion
819 Followers 212 FollowingA centralised repository of the newest and top-rated infosec tools and content. Get your profile on https://t.co/UevQywW8xO now! 🙏
84 Followers 1K FollowingPwn / ♥️Red Team / OSCP+ / Not affiliated with pwn2own competition / CTF with B33F 50μP & @thehackerscrew1 / opinions are on my own
344 Followers 2K FollowingWe are a #ciso marketplace selling information security services, digital products, and various IT swag items. #IoT #infosec #cybersecurity vCISO and Compliance
386K Followers 622 FollowingLove Linux/Unix, open source, and programming? Into Sysadmin & DevOps? Follow us! Boost your IT career with daily new tools, apps, and humor ⤵️
42K Followers 286 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
413 Followers 193 FollowingWe support blockchain networks with decentralized infrastructure, ecosystem building, and strategic investment.
🧠 Follow us for insights on your fav chains
75K Followers 887 FollowingOptimize your Solana staking. Marinade is a stake automation platform that automatically delegates to 100+ best-performing nodes 🌎 https://t.co/YmgLC1fYql
5K Followers 846 FollowingI like cryptography, long walks on the beach, and novel testing techniques. Engineering Director of the Blockchain team @trailofbits.
43K Followers 79 FollowingAccelerating communication in high-performance distributed systems to Increase Bandwidth, Reduce Latency | X by DoubleZero Foundation
4K Followers 173 Followingtanuki42 | Investigations @zeroshadow_io / @_SEAL_Org
For emergencies: https://t.co/zCN71kMn75
Views on this page are my own.
3K Followers 1K FollowingCEO @asymmetric_re, Web3 Security Force Multiplier, Bug Hunter/Wrangler, FOSS Advocate, and Problem Solver. Simply walked to Mordor.
89K Followers 902 FollowingThe dark web of DeFi — building critical infrastructure for crypto intelligence. TG: https://t.co/EPZjOTVti8 - FR : rektFR https://t.co/yUWfgLsgw9
1.6M Followers 91 FollowingTrade with Intelligence 🔎 | Cryptocurrency Exchange & Blockchain Analytics Platform | Earn up to $100 in rewards for registering.
119K Followers 199 FollowingFiltering out the hype with evidence-based reports on the cryptocurrency space, with a focus on #Bitcoin - https://t.co/pgRGU9CuKE
89K Followers 404 FollowingSlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
10K Followers 155 Following🐴Pwnie Award Winning & Nation State funded psyop featuring 6 AI Anime Waifus and a Pup™ singing about APTs, Grifters, & Snake Oil in InfoSec
🖤🩷💚💙💜🤍
5K Followers 3K FollowingLinux and OSS Lover, breaker of distributed systems, OIF II Veteran, Security Engineer, Martial Artist, wannabe chef, and lifelong student. Tech is my passion
No recent Favorites. New Favorites will appear here.