Moritz Sanft
@stdoutput
Followers
1K
Following
3K
Media
193
Statuses
1K
1/3✅
Day 1 at https://t.co/pr7GC5vpg2 didn’t come to play 😈 New vulns dropped in Grafana, Linux Kernel, 3 Redis, and 2 PostgreSQL - and every. single. one. worked 🤯 100% success rate for day one. Let’s see what we find tomorrow 👀
0
0
7
Together with @stdoutput I'm trying my luck on Grafana, Postgres, and Ollama! Good luck to the other participants, I hope your exploits weren't affected by last minute code changes 🥴
https://t.co/7lPHSpoEEn 2025 kicks off TOMORROW! 💻 London, brace yourself - IDEs open. Exploits cooking. 13 zero-days are on the line 💣 Don't miss it. Here's the schedule ahead ⬎
2
1
19
Off to London✈️ Looking forward to see the other entries, but also very excited to kick off our own exploits😎 Best of luck everyone🐞🐰
https://t.co/7lPHSpoEEn 2025 kicks off TOMORROW! 💻 London, brace yourself - IDEs open. Exploits cooking. 13 zero-days are on the line 💣 Don't miss it. Here's the schedule ahead ⬎
1
0
11
Full RCE PoC is now live @ https://t.co/VFu7NxJ3TQ Credit goes to @maple3142. Great job! Brilliant idea for the root reference. Felt like a CTF challenge indeed. Writing the full breakdown now.
github.com
Explanation and full RCE PoC for CVE-2025-55182. Contribute to msanft/CVE-2025-55182 development by creating an account on GitHub.
Since I started to analyze CVE-2025-55182 (React, NextJS RCE) at work today, I decided to publish my analysis findings so far, given all the fuzz about the vulnerability: https://t.co/VFu7NxJ3TQ Feel free to contribute to the search for a proper RCE sink!
10
77
420
Since I started to analyze CVE-2025-55182 (React, NextJS RCE) at work today, I decided to publish my analysis findings so far, given all the fuzz about the vulnerability: https://t.co/VFu7NxJ3TQ Feel free to contribute to the search for a proper RCE sink!
github.com
Explanation and full RCE PoC for CVE-2025-55182. Contribute to msanft/CVE-2025-55182 development by creating an account on GitHub.
4
71
353
From bit flip to RCE in Ollama! 🦙 Our latest blog post explains how a file parsing bug led to an interesting out-of-bounds write primitive. Learn how it could have been exploited in Ollama, a tool to run LLMs locally: https://t.co/aHQO69XpaE
#security #vulnerability #llm #ai
sonarsource.com
Our Vulnerability Researchers uncovered vulnerabilities in the code of Ollama, a popular tool to run LLMs locally. Dive into the details of how LLMs are implemented and what can go wrong.
0
34
109
What are these white things hanging from the ceiling for? Light diffusion? I’ve seen them in multiple offices before, and wonder what they do
1
0
2
Thanks to our sponsors @zellic_io , @Burp_Suite, @vector35, @Binary_Gecko, @hackthebox_eu, and @Hetzner_Online for the awesome infra.
0
2
8
..and even uses some ✨novel techniques✨. I had the pleasure of test-solving the challenge during the CTF preparations and you can now read my write-up here: https://t.co/l1eyLzGAAp
0
0
0
Interested in #GitHub Actions #security?🎬🛡️ Paul, a teammate of mine in the FluxFingers team, created an awesome challenge for this year's https://t.co/qe8myrPIN8
#CTF, which demonstrates the intricacies of running GitHub Actions workflows in public repositories..⬇️
1
0
3
Shops were open this weekend, and we spent $4298 finishing 🥈! Congrats to @fluxfingers for an amazing event.
0
8
24
Finished 🥈 in https://t.co/AyuGCwzKsY CTF w/ @justCatTheFish Some cool challenges as always and with my teammates we managed to clear all web challenges yet again!
1
3
57
Hacklu CTF has started, our furniture store has opened for business! In the next 48 hours, you can buy as many products as you can and try to win nice prizes from our sponsors!
2
6
14
Hej! We are thrilled to announce @hack_lu CTF 2025 starts on Friday, October 17. Top teams can win prizes from our sponsors: OffensiveCon, Zellic, PortSwigger, Binary Ninja, and HackTheBox. All information on https://t.co/7RrfeQKgHV
0
7
23
Hack.lu CTF registration is open! Win great prizes from our sponsors: 🎯 3x OffensiveCon tickets by @Binary_Gecko 🕵️♂️ 6x @Burp_Suite 🥷 6x Binary Ninja by @vector35 📦 80 months @hackthebox_eu VIP+ 💸 $1000 by @zellic_io 🇩🇪 @DHM_ctf quals https://t.co/rbPY4FAEo3
1
1
13
🪟 Calling all Windows experts! Hack.lu CTF 2025 ( https://t.co/e8nHgLE8B8) has a great Windows kernel exploitation challenge, sponsored by @Binary_Gecko. And the best thing about it? Solving it can earn you a ticket for @offensive_con 2026! 🧵⬇️
1
11
36