0xvm Profile Banner
0乂ᐯ爪 Profile
0乂ᐯ爪

@0xvm

Followers
181
Following
3K
Media
2
Statuses
284

We are all equal before a wave. 🌊 🏄

Joined October 2008
Don't wanna be here? Send us removal request.
@francisco_oca
0ca
13 days
I was human participant no 3 in this research paper. Stanford paid me (and another 9 humans) to hack their network for 10 hours 😎I found 3 critical vulns, 2 high, 1 med and 1 low, 7 in total. Their AI agent did pretty well, 11 total vulns, 9 valid. What is crazy to me is the
2
8
39
@PwnieAwards
Pwnie Awards
5 months
We are very happy to announce the nominees for the 2025 Pwnie Awards! As a reminder, we will be presenting the winners at DEF CON this year. Saturday the 9th, 10:00AM Main Stage. Hope to see you there! https://t.co/hWUu2PcM8B
Tweet card summary image
docs.google.com
Pwnie for Best Crypto Bug X.509DoS Exploiting and Detecting Denial-of-Service Vulnerabilities in Cryptographic Libraries using Crafted X.509 Certificates Bing Shi, Wenchao Li, Yuchen Wang, Xiaolong...
0
48
142
@TheOffensiveX
Offensive X
7 months
The OffensiveX 2025 Agenda Is Live. On June 18–19, we’re bringing the sharpest minds in offensive security to Athens to drop real research, real tools, and real tactics. You’ve seen who’s speaking. Now it’s time to see what they’re dropping. 🔗 Check the full agenda:
0
5
14
@TheOffensiveX
Offensive X
11 months
🚨 The wait is over—CFP for #OffensiveX2025 is NOW OPEN. Got research that challenges assumptions, breaks new ground, or exposes critical security flaws? This is your chance to take the stage at Europe’s most technical offensive security conference. No fluff. No marketing. Just
0
1
3
@FuzzySec
b33f | 🇺🇦✊
1 year
I have posted the slides for the talk @chompie1337 and I gave this past weekend at @h2hconference -> The Kernel Hacker’s Guide to the Galaxy: Automating Exploit Engineering Workflows #H2HC https://t.co/Cl8b58KkAv
18
217
748
@it4sec
Denis Laskov 🇮🇱
1 year
Rooting an Android POS "Smart Terminal" to steal credit card information:✅ Paper "Exploring and Exploiting an Android 'Smart POS' Payment Terminal", by Jacopo Jannone.Paying with a POS will never feel the same for me. PDF: https://t.co/mZqbgoZZyh Video: https://t.co/V98uJ4MH0m
3
213
861
@wiknerj
johannes
1 year
The first ever end-to-end cross-process Spectre exploit? I worked on this during an internship with @grsecurity! An in-depth write-up here: https://t.co/mze3LQkpJR
0
55
124
@trickster012
trickster0
1 year
I just released my C2 I was working on, on my free time. Feel free to play around make your own forks if you like it. It needs a lot of work but it is a fully rust one with small implant and working sleep obfuscation. https://t.co/kSu1KW6IYN
Tweet card summary image
github.com
Nameless C2 - A C2 with all its components written in Rust - trickster0/NamelessC2
7
80
278
@0xor0ne
0xor0ne
1 year
KVM escape CTF challenge (corCTF 2024) solution writeup https://t.co/fSnIXwCESO Credits @zolutal #Linux #cybersecurity
1
66
321
@SinSinology
SinSinology
1 year
🔥💀 Here is the "Real" writeup and exploit for the pre-auth deserialization RCE I reported to Ivanti CVE-2024-29847 Apparently, folks at horizon3 tried to write about my bug before me but they did it wrong https://t.co/Df8lIDYNRH
summoning.team
ivanti just pushed a patch for a Critical CVSS 9.8 Remote Code Execution Vulnerability that I reported on May 1st 2024, impacting Ivanti Endpoint Manager (EPM). in the following blog post I will be...
6
138
402
@_MG_
MG
1 year
The exploding Hezbollah pagers situation is an incredibly impressive supply chain attack by Israel (most likely). I am sure more details will come, but there are already some educated guesses to be made that narrow it down. 🧵1/n
63
641
3K
@grittygrease
Nick Sullivan
1 year
If you’re interested in getting started in cryptography, check out the crypto 101 course by Dr. Alfred Menezes from UWaterloo. https://t.co/cevF3j5OTb He’s planning on publishing the lectures from his Applied Cryptography course, which was my introduction to the field.
Tweet card summary image
cryptography101.ca
Video lectures, notes, and exercises in all areas of applied cryptography
3
125
523
@benjaminjriley
Benjamin Riley
1 year
"Most concerning is the illusion that LLMs are retrieving information rather than constructing word associations. LLM responses are statistically likely rather than factually accurate. Sometimes these things correspond, but often they do not." E. Salvaggio
Tweet card summary image
techpolicy.press
Eryk Salvaggio says we must dispense with myths if we are to think more clearly about what AI actually is and does.
13
238
878
@PwnieAwards
Pwnie Awards
1 year
🚨We are very pleased to announce the nominees for the 2024 Pwnie Awards! Be sure to tag your friends and catch us at Def Con! 🚨 🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇🥳🏇 https://t.co/TxplA2l6X6
Tweet card summary image
docs.google.com
Pwnie for Best Crypto Bug Breach Extraction Attacks The paper describes attacks leveraging leakage from cryptographic protocols and compromised credential-checking services, specifically Cloudflare's...
9
73
208
@GabrielLandau
Gabriel Landau
1 year
Introducing a new Windows vulnerability class: False File Immutability. 👉 Bonus: a kernel exploit to load unsigned drivers. https://t.co/rckAZVs5Lf
Tweet card summary image
elastic.co
This article introduces a previously-unnamed class of Windows vulnerability that demonstrates the dangers of assumption and describes some unintended security consequences.
10
216
555
@tijme
Tijme Gommers
1 year
From Theory to Practice: Kernel Heap Spray Exploitation for Privilege Escalation💥 Part two of the blog series by my colleague Alex: https://t.co/rP2eFoi01t
2
58
175
@_zblurx
Thomas Seigneuret
1 year
One year ago, @T00uF and I did a talk at @_leHACK_ about DPAPI and #DonPAPI. Well, we've completely rewritten it to add a lot of new features. DonPAPI 2.0 available now 🚀 ▶️ https://t.co/3QJzpJcKaw
Tweet card summary image
github.com
Dumping DPAPI credz remotely. Contribute to login-securite/DonPAPI development by creating an account on GitHub.
7
93
237
@0xvm
0乂ᐯ爪
1 year
A very interesting podcast from @SCWpod
@SCWpod
Security Cryptography Whatever
2 years
New episode on zero day markets, featuring @mdowd.
0
2
3