qkaiser Profile Banner
Quentin Kaiser Profile
Quentin Kaiser

@qkaiser

Followers
2K
Following
5K
Media
247
Statuses
3K

Offensive security / vulnerability finder. security researcher @onekey_sec / @konkretesec founder / @ecoswtf initiator

infosec.exchange/@qkaiser
Joined December 2009
Don't wanna be here? Send us removal request.
@qkaiser
Quentin Kaiser
5 days
Perfection 🤌
Tweet media one
2
1
20
@qkaiser
Quentin Kaiser
10 days
RT @Kevin2600: This is what happenes when you touch the untouchable :(
Tweet media one
Tweet media two
0
13
0
@qkaiser
Quentin Kaiser
29 days
Looks like bug bounty hunters have started using CVE-2025-4009. Evertz still hasn’t released a patch to this day.
@wgujjer11
Muhammad Waseem
1 month
Remote Code Execution via a Base64-Encoded Payload — No Login Needed.I believe in concise points and exact details, so this response is to the point with no extra explanation. WRiteup : #BugBounty #EthicalHacking #CyberSecurity #Infosec #Hacking.
1
0
3
@qkaiser
Quentin Kaiser
29 days
Good stuff !.
@thezdi
Trend Zero Day Initiative
1 month
Extracting Embedded MultiMediaCard (eMMC) contents in-system. ZDI researcher Dmitry Janushkevich details how to interact with an eMMC chip and notes some pitfalls you may encounter on the way.
0
0
3
@qkaiser
Quentin Kaiser
1 month
RT @pedrib1337: We are looking for a junior security researcher 🤠 .No university degree or previous work experience required, but MUST be….
0
93
0
@qkaiser
Quentin Kaiser
1 month
This is CVE-2025-41663
0
0
0
@qkaiser
Quentin Kaiser
1 month
This is CVE-2025-41661 and CVE-2025-41662
1
0
0
@qkaiser
Quentin Kaiser
1 month
It's disclosure day! 2 unauth RCE affecting CGI shell scripts (CVE-2025-41661, CVE-2025-41662) and 1 unauth RCE (CVE-2025-41663) affecting a custom VPN client found in Weidmüller IE-SR-2TX-WL industrial routers. All of them automatically identified by our platform™ 👇.
1
0
5
@qkaiser
Quentin Kaiser
2 months
@n_o_t_h_a_n_k_s look what you made us do.
1
0
1
@qkaiser
Quentin Kaiser
2 months
I’m quite proud of what we achieved since we started working on unblob. What we support internally is now public, check out all the formats at
Tweet media one
docs.onekey.com
A comprehensive list of formats and filesystems ONEKEY can process.
1
0
9
@qkaiser
Quentin Kaiser
2 months
I’m being gaslighted by a vendor about our coordinated disclosure policy. Guess the vendor.
0
0
0
@qkaiser
Quentin Kaiser
2 months
a single schemastore commit broke taplo, which is now failing all CI pipelines doing schema validation. Modern dev infrastructure is 👌.
0
0
0
@qkaiser
Quentin Kaiser
2 months
Note: fourth advisory has been postponed to end of June. See u then :).
0
0
0
@qkaiser
Quentin Kaiser
2 months
Here's our third security advisory for vulnerabilities identified by our bash static analyzer. This is also our second full disclosure after 90 days since Diviotec didn't answer any of our requests. Have a read, it's a nice demonstration of platform capabilities 👇.
1
0
0
@qkaiser
Quentin Kaiser
2 months
We continue publishing advisories on issues identified by our platform using bash static analysis. Today we look at CVE-2025-4010 affecting Netcomm (aka Lantronix) NTC-6200 and NWL series. We're still waiting for a proper patch. Link below 👇
Tweet media one
1
1
4
@qkaiser
Quentin Kaiser
2 months
RT @onekey_rl: One of our own identified a buffer overflow in an industrial Bluetooth stack, details are now available at .
0
2
0