blasty
@bl4sty
Followers
17K
Following
2K
Media
283
Statuses
4K
irresponsible disclosure aficionado
The Netherlands
Joined April 2009
fuck. you will be missed @steaIth
Stealth died 😢 A member of Team-Teso, Phrack staff, and many other groups. A true hacker—perhaps as true as a hacker can ever be. WE MISS YOU. 🩷 More: https://t.co/Jx0JYfrjnG <stealth> we had joy we had fun we had a rootshell on a sun.
1
0
24
TIL the Task Manager Guy™ once dabbled in scareware?
Did i upset the “task manager” guy for pointing out his malicious career after Microsoft? https://t.co/V23100AUYD
6
7
145
question to people who have dealt with receiving bug bounty payments (or any kind of payout for an accomplishment; think everything in the 1k-50k USD range): are regular wire transfers your preferred payment method? would you be opposed to taking stable coin (USDT/USDC/..)
8
1
9
Celebrate gaming’s biggest night with epic deals on award‑winning titles!
0
32
2K
Jia Tan right now: "hold my beer, I'm pretty sure I can hide my shellcode in MOOV atoms and ADTS frame headers"
0
1
39
500+ dusty codecs, 400+ dusty formats, one innocent looking bug report and one curious core dev. EVERYONE GET ON THE FLOOR RIGHT NOW. NOBODY MOVE THIS IS A ROB^H^H^H SUPPLY CHAIN ATTACK.
2
2
40
I feel as an infosec shitposter, I should clarify tavis' lingo a bit. "popped" in this context means popping calc.exe, or possibly a more nefarious payload 🙃. it doesn't mean people get so angry over security bugs in 1990s game codecs (or at least I hope so) they strap up and
12
6
206
These cozy knitted stockings are perfect for keeping your feet warm on chilly winter nights. Whether you’re lounging around the house, watching TV, or wearing slippers or shoes, they add comfort and style to your everyday moments.
0
135
1K
i guess you can still contact a CNA directly etc. but it adds to the hassle that is a disclosure process
2
0
8
kind of funny that bugs that are communicated to vendors in a way they don't appreciate can result in no CVE being allocated for the vuln(s). while i guess it is bureaucratically legit (or is it?) it makes the CVE system an unreliable source of truth (more news at 11)
Sucks, yesterday i've discovered a path traversal in docker compose, but unfortunately it will not be assigned as a CVE. Because i was supposed to send an email instead of opening a public issue in GH😅 anyhow the poc can be found here: https://t.co/BDt5nnrTYA
9
11
69
the most important question I have about this HackingTeam revival that was exposed by @oct0xor and co is if #YourBoySerge is still saving the day when the live demos fail during a sales pitch. or did they find a new Serge? (anyone remember #YourBoySerge? or am I just really
6
1
30
More interposer fun, this time with DDR5 memory. Breaking TDX, SGX, SEV and even Nvidia TEEs. Checkout our work at https://t.co/Jl1dpGnM6J, and get a personally-signed Intel attestation report at @TEEdotFail.
45
84
346
Every #TheSAS2025 participant already knows who the best speakers were this year. However, the world deserves to know too. 🥇 The best cocktail of deep research and lively presentation this year was delivered by none other than Peter Geissler (@bl4sty) himself. His talk on
0
4
23
The HackingTeam is back! New name, new malware, new exploits
securelist.com
Kaspersky researchers discovered previously unidentified commercial Dante spyware developed by Memento Labs (formerly Hacking Team) and linked it to the ForumTroll APT attacks.
5
120
403
TrueType is the gift that keeps on giving (do you remember Triangulation?) and Peter @bl4sty keeps on winning pwn2own thanks to it #TheSAS2025
0
3
37
slides can be found here:
github.com
Contribute to blasty/slides development by creating an account on GitHub.
0
0
8
thanks to everyone who attended my #TheSAS2025 talk "Typographic hit job: when fonts pull the trigger". 🙏 I've written an accompanying blogpost that goes over all the details:
haxx.in
Last year we (PHP HOOLIGANS) competed in Pwn2Own (ireland, 2024) once again. One of our (succesful) entries was against a little pet peeve target of mine, the CANON ImageCLASS printer. In this post...
4
42
137