reversebrain @reversebrain
Penetration Tester | Red Team Operator | Incident Response Operator | CTF player with @mhackeroni reversebrain.github.io /dev/null Joined March 2012-
Tweets595
-
Followers2K
-
Following586
-
Likes2K
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate. Full disclosure: samcurry.net/hacking-kia
Ever heard about cross-queries? 👀 During a recent penetration test, I uncovered the powerful capabilities of cross-queries in PostgreSQL. Discover how this feature can be exploited to dump tables in complex scenarios: reversebrain.github.io/2024/09/19/Cro…
Firmware 1.0 released! 🔥 What’s new: Apps catalog, JavaScript support, New NFC subsystem, 2X faster Bluetooth, External radio module support and more! 🤩 Read the blog post: blog.flipper.net/released-firmw…
Now that we're all back and caught up on sleep it's @defcon CTF @Nautilus_CTF wrap-up time! 🐚🚩 we managed a great 6th place in a tough competition with conventional pwnage, GenAI-powered spaceships, and LiveCTF duels
It's time to take a closer look at CVE-2024-38063 (Windows TCPIP RCE). I usually don't post partial analysis but since most available info is unreliable I'll do my best to try and shed some light. This time I'll focus on my workflow and thought process as we go. 🧵
And that's it for this year @defcon #CTF: your favorite Italian team got 6th place after 3 intense days of !sleeping. Thanks to the organizers @Nautilus_CTF and all the amazing teams that competed with us in this backdoor-sharing event! See you next year! ♥️ #defcon #defcon32
Some of you may already be aware but due to extenuating circumstances we've made an early award! The 2024 Pwnie for Epic Fail goes to @CrowdStrike for the CRWD2K bug! 🦃
I don't do Windows but here are some (initial) details about why the CrowdStrike's CSAgent.sys crashed Faulting inst: mov r9d, [r8] R8: unmapped address ...taken from an array of pointers (held in RAX), index RDX (0x14 * 0x8) holds the invalid memory address @_JohnHammond
Job 1 in repairing CrowdStrike.. get access to computer.
Job 1 in repairing CrowdStrike.. get access to computer. https://t.co/g8tNIK42s4
🔥 XSS on any website with missing charset information? 😳 Attackers may leverage the ISO-2022-JP character encoding to inject arbitrary JavaScript code into a website. Read more in our latest blog post: sonarsource.com/blog/encoding-… #appsec #security #vulnerability
My latest blog about my discovery for Evernote Client All-platform RCE via PDF.js font-injection to preload.js exposed ipcRenderer-BrokerBridge-boron.actions bypassing Electron's nodeIntegration | context-isolation; Enjoy reading! 0reg.dev/blog/evernote-…
JULIAN ASSANGE IS FREE Julian Assange is free. He left Belmarsh maximum security prison on the morning of 24 June, after having spent 1901 days there. He was granted bail by the High Court in London and was released at Stansted airport during the afternoon, where he boarded a…
📢 Calling all Sponsors! Get mhackeroni to the DEF CON 32 CTF finals 🚩🍝 Would you like to be a part of moving the kitchen to Las Vegas this summer & secure a spot for your logo in our highly-demanded t-shirt? Contact us! Your favourite Italian Acheri™️ need your help!
Windows Defender doesn't like it when you name your Hyper-V VM "Invoke-Mimikatz"
The most sophisticated exploit we've ever seen. Thank you to @wdormann for bringing this to our attention. This is basically Stuxnet. 2.0
the xz sshd backdoor rabbithole goes quite a bit deeper. I was just able to trigger some harder to reach functionality of the backdoor. there's still more to explore.. 1/n
This new book has finally arrived. Thank's to @nostarch as well as @billpollock for making it happen as well as @Lee_Holmes as my tech reviewer.
Btw, you don't need a Flipper Zero to "hack" dumb radio protocols. The piece of wire is enough. Check out how to receive and decode 433MHz radio signal just with a PC sound card.

Gabriele @Gabry89
5K Followers 4K Following Read-only account • Follow me on https://t.co/Pnx3zyQtrQ 🦋
Andrea (Drego) Draghe... @AndreaDraghetti
7K Followers 3K Following aka Drego. Head of Cyber Threat Intelligence at @D3LabIT! @PhishingArmy, #meioc is my projects and @backbox_org dev! My passions are #F1 and #Running!
David Puente @DavidPuente
63K Followers 2K Following Fact-checker journalist. Deputy editor @Open_gol @OpenFactCheck (@factchecknet verified signatory) https://t.co/cqolXJidOU
VivienBarrie @D89cTT6Bt23vT63
1 Followers 354 Following
Monica Garcia @MonicaGarc91639
2 Followers 126 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/ZfeIqRW1wH
Look at my homepage @cole_meyer43343
24 Followers 3K Following Virtual currency game platform, deposit and get 50% bonus, recruit agents to earn 100,000 USDT per month, contact us https://t.co/j3jdAz4niL
Chase Fitzgerald @AsymmMeasures
101 Followers 652 Following Research Math | Neuro-Cognitive Warfare | Intelligence https://t.co/fv0KRfwMh0
. @offthewidow
1 Followers 74 Following
Chris Isaias @_call_gate
107 Followers 2K Following Penetration Testing & Reverse Engineering. . . Phd(c), Msc (RHL), ESDC fellow, IEEE snr, FIRST liaison, CISSP, CRTO, PNPT, CRTP
Blawplaw @BlawplawBz7oz
1 Followers 121 Following
Gabriele Biondo @gb700823
154 Followers 637 Following CISSP, CISM, ITIL, OPST, ISO 27 Lead Auditor, and cyberpunk inside. Interested into ICTSecurity, Math, and Sushi.
Axel @antrax090
3 Followers 130 Following
xss0r @xss0r
6K Followers 3K Following xss0r Deploying an alert box in a web app is like having a tiny pop-up comedian shout 'Surprise!' whenever you least expect it! #xss0r #ibrahimXSS #Blindxss0r
Andrea Braschi @AndreaBraschi
146 Followers 1K Following
𝖗𝖔𝖔𝖙. @cariyme
13 Followers 71 Following When there is will, there is a way. ⚡︎ cybersec student 👩💻
Hackviser @hackviserr
2K Followers 3K Following Tailored cybersecurity upskilling platform for all levels, catering to beginners and pros | Best way to boost your #cybersecurity skills
uguxbjf952 @uguxbjf952
3 Followers 70 Following
الله اكبر @joj1996jojo
10 Followers 468 Following
sudomode @0xsudomode
51 Followers 517 Following
j0wzin @j0wzin
6 Followers 74 Following
anonymix @anonymix139841
0 Followers 274 Following
Ogrodut @ogrodutt
23 Followers 303 Following Emotionally charged and introspective storyteller, exploring the complexities of the human experience through personal anecdotes.
ch @chybeta
14K Followers 4K Following open to bug bounty collaboration @HackenProof Security Researcher Just dm https://t.co/VVU1OV5yz6 业余打土狗
Paolo Stagno (VoidSec... @Void_Sec
5K Followers 2K Following Director of Research @Crowdfense. Windows Vulnerability Researcher and Exploit Developer, ex-@XI_Research
Irene @womack_irene36
271 Followers 3K Following
j@ser18 @jser181
19 Followers 88 Following
Tayfun Yelim @TayfunYelim
183 Followers 1K Following 🇹🇷| Hacker | Engineer | Telco Security | @marmara1883 | @METU_ODTU
Frans @frans_initroot
1K Followers 2K Following Security fanatic... COO @ Risk X Opinions are my own and have no affiliation with my employer.
Sergio Mazariego @s3rgiomazari3go
1K Followers 3K Following Security Researcher, I write about Cybersecurity 🛡️, Digital Forensics, Offensive Security and Web 3.0.
︎ ︎ @0xocdsec
4K Followers 7K Following ︎ ︎︎ ︎︎ ︎︎ ︎︎ ︎🏴☠️ ︎︎ ︎︎ ︎︎ ︎︎ ︎🌹︎ ︎︎ ︎︎ ︎︎ ︎︎ ︎ ︎︎🏴☠️︎ ︎︎ ︎︎ ︎︎ ︎︎ ︎💚︎︎ ︎︎ ︎︎ ︎︎ ︎︎ ︎🇺🇦 ︎︎ ︎︎ ︎︎ ︎︎ ︎︎|︎ ︎︎ ︎︎ ︎︎ ︎︎603,628 km² ︎ ︎︎
Lorenzo Leonardini @_lorenzo_leo
130 Followers 187 Following Computer scientist, cybersecurity guy, wannabe musician CTF player with @ZenHackTeam and @aboutblankets
Giorgio Campiotti @giorgiofox
1K Followers 997 Following #linux, #security, #hacking, #sdr, #penetrationtesting DM open
Vulnlab @vulnlab_eu
6K Followers 1K Following Labs & Training by @xct_de | https://t.co/3vRSpRWwJb | You are welcome to join the community @ https://t.co/8tvZ0UZ5ZL
Vincenzo @tanuki_no_neiri
149 Followers 2K Following
ch347 @ciccio_bi_
3 Followers 36 Following
Vxshellew @vxshellew
551 Followers 4K Following
Paolo Viale Marchino @MarchinoPa6436
0 Followers 2 Following
vx-underground @vxunderground
368K Followers 290 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Paolo Attivissimo @Attivissimo_me
399K Followers 0 Following Account segnaposto. ATTENTI A IMITATORI E IMPOSTORI: questo è il mio unico account su X. Autenticazione: https://t.co/SuhmGdcCW3
Matteo G.P. Flora @lastknight
34K Followers 2K Following Narrative #Governance & #AI Safety // Professor Adj, Founder, Investor // On TV and Podcast talking #TechPolicy
cts🌸 @gf_256
61K Followers 819 Following Co-founder and hacker @zellic_io & @pb_ctf | https://t.co/nlNai6iiMP | 24 Intern @egirl_capital slow to reply to DMs
Stefano Zanero @raistolo
19K Followers 2K Following Tinkerer, security geek, recovering entrepreneur, full professor @polimi, frequent flyer, pilot (follow https://t.co/19HknsE6EE). He/him 🏳️🌈
Intigriti @intigriti
193K Followers 658 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
Lercio.it @lercionotizie
959K Followers 31 Following 🚩Lercio. Lo sporco che fa notizia! (crediti immagini sul sito https://t.co/C4inq6HvhA)
Simone Margaritelli @evilsocket
47K Followers 2K Following Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things.
Flipper Zero @flipper_zero
101K Followers 145 Following A portable multi-tool device in a toy-like body for pentesters and hardware geeks. Buy worldwide here ➡️ https://t.co/n09EKVnqri
Gabriele @Gabry89
5K Followers 4K Following Read-only account • Follow me on https://t.co/Pnx3zyQtrQ 🦋
Troy Hunt @troyhunt
241K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
Andrea (Drego) Draghe... @AndreaDraghetti
7K Followers 3K Following aka Drego. Head of Cyber Threat Intelligence at @D3LabIT! @PhishingArmy, #meioc is my projects and @backbox_org dev! My passions are #F1 and #Running!
LiveOverflow 🔴 @LiveOverflow
155K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
MalwareTech @MalwareTechBlog
277K Followers 1 Following Not here anymore. Profiles: https://t.co/sFoOuGmYK2
pwnthem0le @pwnthem0le
1K Followers 35 Following Academic CTF Team - Politecnico di Torino | m0leCon Security Conference & CTF organizers | @aboutblankets
Claudia @signorina37H
6K Followers 361 Following co-founder @ransomnews • OSINT/SOCMINT/HUMINT • #cyberculture • COBOL programmer • nerd • marketing professor • #phackera • 外人
Cronache di un Sistem... @ITSquOd
3K Followers 18 Following Un account per trovarli, un account per controllarli, un account per raccontarli, e nel disagio per sempre fissarli. Cerchiamo adepti, ritwittaci.
Antonio Bianchi @anton00b
2K Followers 43 Following Associate Professor at Purdue. Former DefconCTF organizer. Hiring interns/PhDs/PostDocs in Mobile Security/Authentication/IoT/Trustzone/Binary Analysis
Pwnie Awards @PwnieAwards
12K Followers 24 Following An annual awards ceremony celebrating and making fun of the achievements and failures of security researchers and the wider security community.
Dark Web Informer @DarkWebInformer
129K Followers 60 Following Providing Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
Pwned Labs @PwnedLabs
2K Followers 68 Following Pwned Labs delivers fun and immersive cybersecurity training experiences for individuals and businesses. Join the community: https://t.co/kyG413GZDa
Dark Web Intelligence @DailyDarkWeb
138K Followers 0 Following Daily Dark Web dose from the dark side.
Frost @fr0s7_
5K Followers 1K Following
HackTricks @hacktricks_live
15K Followers 201 Following HackTricks offers free quality hacking resources in 17 languages: https://t.co/O1TVFk5r9q, https://t.co/0RhWRaaPIm Paid certs by HT-Training: https://t.co/2C0w8pkq6v
Tib3rius @0xTib3rius
68K Followers 586 Following High Queen of the Cybers | Educator | Content Creator | UwU-Anointed Wapp King | Ex-Brit | https://t.co/04RRExvxXj (he/him) 🇺🇸 I run gameshows at DEF CON.
Charlie Clark @exploitph
5K Followers 1K Following
NiNi @terrynini38514
2K Followers 583 Following Security Researcher at @d3vc0r3 / Pwn2Own Master of Pwn (Toronto 2022) / CTFer @balsnctf
ACE Responder @ACEResponder
17K Followers 225 Following Practice threat hunting & detection engineering in a real SIEM with real attacks. Join us and become the best.
Pikaso @pikaso_me
940K Followers 19 Following 1️⃣ Follow me 2️⃣ Reply to any tweet 3️⃣ Write "@pikaso_me screenshot this"
j00ru//vx @j00ru
37K Followers 826 Following (Mostly) Windows hacker & vulnerability researcher. Google Project Zero. @DragonSectorCTF
Matteo Rizzo @_MatteoRizzo
3K Followers 589 Following Security engineer, CTF player for @0rganizers. Mastodon: @[email protected]
VIE @vie_pls
2K Followers 235 Following Security Engineer @ Google • @mmm_ctf_team and @maplebaconctf • UBC alum
Andrew @4ndr3w6S
3K Followers 2K Following Detection Engineering @HuntressLabs | Prev. Practice Lead, TAC (Purple Team) @TrustedSec | @SpursOfficial Super Fan - COYS!
Calle Svensson @ DEFC... @ZetaTwo
7K Followers 711 Following Security Engineer @ XTX. MSc in eng. physics & CompSci, dev & gamer. ❤️ music & long distance running. Wanna do a PhD sometime. Same U/N on all other sites
Microsoft Security @msftsecurity
349K Followers 325 Following We are prioritizing security above all else through our Secure Future Initiative (SFI). Explore SFI principles, pillars, and progress here ⬇️
Traceix @usetraceix
17K Followers 417 Following Correlate binaries by behavior | Demo: https://t.co/elkZk1VrrC | Discord: https://t.co/jcZBvfLOic | Product of Revix Labs LLC
Will Schroeder @harmj0y
48K Followers 957 Following Researcher @SpecterOps. Coding towards chaotic good while living on the decision boundary.
Brandon Fisher @Shad0wCntr0ller
217 Followers 244 Following Security Consultant @ Rapid7 Likes/comments/posts from this account does not represent my employers views.
SEKTOR7 Institute @SEKTOR7net
15K Followers 346 Following Homo Aptus. Vincit qui se vincit - Publilius Syrus. Consulting, Training, Technology, Cyber domain, and more... @x33fcon founder.
MalDev Academy @MalDevAcademy
17K Followers 5 Following Providing specialized, module-based security training and resources designed for cyber security professionals
Perri Adams @perribus
7K Followers 993 Following @Dartmouth ISTS Fellow & @SAISHopkins Adjunct Prof., inter alia. Former @DARPA, @DEFCON CTF, etc. @DistrictCon, @hexacon_fr, @LABScon_io is CFP Review Boards
DEF CON A&E @defcon_music
4K Followers 120 Following Official twitter account for @defcon's Arts & Entertainment Team // https://t.co/nLQ35TUMWP We do the official parties!
Natalie Silvanovich @natashenka
45K Followers 2K Following Tamagotchi Hacker. Google Project Zero. She/her.
mpgn @mpgn_x64
18K Followers 230 Following Flibustier du net ̿ ̿̿'̿'\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ Podcast Hack'n Speak @hacknspeak / https://t.co/GyACSFg9mw
RedTeamVillage @RedTeamVillage_
36K Followers 2K Following Red Team Village | Join us on https://t.co/ILZhRFw4Y7 . Check our next events at: https://t.co/fJwIUSTI16
Cristian Assaiante @cristianrichi3
228 Followers 270 Following PhD student in Engineering in CS @DIAGsapienza | CTF player @TheRomanXpl0it/@mhackeroni | Trainer @cyberchallengIT | Guitarist | Compilers | Rock Climber |
Shellphish @shellphish
7K Followers 47 Following Capture the Flag Team from UC Santa Barbara's SECLAB and Arizona State University's SEFCOM. DARPA Cyber Grand Challenge 3rd Place. Phrack author. Let's hack!
Carola Frediani @carolafrediani
16K Followers 4K Following Infosec Technologist @hrw. Former global security @Amnesty. @guerredirete cofounder. Last book: #Cybercrime. @[email protected]
justCatTheFish @justCatTheFish
3K Followers 54 Following Polish ctf team. Captain: @disconnect3d_pl Vice: @haqpl https://t.co/pJy694x44H