New post: @RelayProtocol’s contracts trusted Ed25519 verification without validating offsets, opening the door to forged allocator signatures and potential double-spends.
@_fel1x details the bug, the risks it posed to cross-chain liquidity, and how the issue was addressed.
Threat Contained: marginfi Flash Loan Vulnerability by @_fel1x
A new instruction broke the flash loan logic, creating a way to borrow without repaying and putting $160M at risk.
We explain the vulnerability, potential impact, and how it was fixed. Full post below ↓
"The NPM account of the popular developer qix was compromised, leading to malicious versions being published for dozens of packages, including chalk, strip-ansi, and color-convert."
Recommended read. Interesting payload.
jdstaerk.substack.com/p/we-just-foun…#SupplyChain
"CVE-2025-32463: sudo local privilege escalation via chroot option"
An attacker can leverage sudo's -R (--chroot) option to run
arbitrary commands as root, even if they are not listed in the sudoers file.
Sudo versions 1.9.14 to 1.9.17 affected.
openwall.com/lists/oss-secu…#infosec
Last year I discovered multiple bugs in virtio-net for VirtualBox (CVE-2023-22098, CVE-2023-22099, CVE-2023-22100) and wrote a 100% reliable VM escape using an out-of-bounds write (with ASLR defeat). Published the exploit code: github.com/google/securit…
"Reverse engineered an ESP32-based smart home device to gain remote control access and integrate it with Home Assistant."
Great write-up. Recommended read.
jmswrnr.com/blog/hacking-a…
"CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive"
Tl;Dr: "/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml" unauthenticated leads to the setup page, allowing you to create a new admin account.
horizon3.ai/cve-2024-0204-…#cve#poc#exploit
Got an ethical pentest for a kiosk-esque environment, but you're stuck in a browser? Have access to websites, but have a need to go deeper?
Look no further! With kiosk.vsim.xyz you have access to tools that enable lateral enum, calculator://, file browsing, and more!
In December, in macOS Sonoma, Apple fixed 15 video decoding vulnerabilities I reported. This is how these issues were found: github.com/googleprojectz…
Supply Chain Security: How the Figma security engineering team leveraged commit signatures and Okta Device Trust certificates to protect GitHub release branches.
figma.com/blog/how-we-en…#supplychain
My first blog post! It's about CVE-2023-4369, a $10,000 bug I found in ChromeOS in July. The bug used a chrome:// URL XSS to allow Chrome extensions to execute privileged code and read/edit downloaded files without user interaction. 👀 0x44.xyz/blog/cve-2023-…
19 Followers 418 FollowingIIT Bombay EE 2018 भारतीय
अभियंता, Network Security, Red Team, White Hat, Backend developer, Python, Lang-chain, LLM,
Bug Bounty,
DHH, Music production 🎁
5K Followers 3K FollowingLinux and OSS Lover, breaker of distributed systems, OIF II Veteran, Security Engineer, Martial Artist, wannabe chef, and lifelong student. Tech is my passion
822 Followers 211 FollowingA centralised repository of the newest and top-rated infosec tools and content. Get your profile on https://t.co/UevQywW8xO now! 🙏
83 Followers 1K FollowingPwn / ♥️Red Team / OSCP+ / Not affiliated with pwn2own competition / CTF with B33F 50μP & @thehackerscrew1 / opinions are on my own
340 Followers 2K FollowingWe are a #ciso marketplace selling information security services, digital products, and various IT swag items. #IoT #infosec #cybersecurity vCISO and Compliance
386K Followers 622 FollowingLove Linux/Unix, open source, and programming? Into Sysadmin & DevOps? Follow us! Boost your IT career with daily new tools, apps, and humor ⤵️
43K Followers 284 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
8K Followers 851 FollowingSolana Dev | Live Looper | Video Blogger
supporting @solana_devs | co-founder of @sol_recovery | member of @superteamDE
https://t.co/unYtcmvz4Y
434 Followers 194 Following💪 Supporting chains with infra, ecosystem building, and investment, since 2022.
🛠️ Incubating @RevTec_fi
🧠 Follow us for insights, or send a DM
76K Followers 898 FollowingOptimize your Solana staking. Marinade is a stake automation platform that automatically delegates to 100+ best-performing nodes 🌎 https://t.co/YmgLC1fYql
5K Followers 847 FollowingI like cryptography, long walks on the beach, and novel testing techniques. Engineering Director of the Blockchain team @trailofbits.
50K Followers 81 FollowingAccelerating communication in high-performance distributed systems to Increase Bandwidth, Reduce Latency | X by DoubleZero Foundation
4K Followers 195 Followingtanuki42 | Investigations @zeroshadow_io / @_SEAL_Org
For emergencies: https://t.co/zCN71kMn75
Views on this page are my own.
3K Followers 1K FollowingCEO @asymmetric_re, Web3 Security Force Multiplier, Bug Hunter/Wrangler, FOSS Advocate, and Problem Solver. Simply walked to Mordor.
1.6M Followers 92 FollowingTrade with Intelligence 🔎 | Cryptocurrency Exchange & Blockchain Analytics Platform | Earn up to $100 in rewards for registering.
119K Followers 199 FollowingFiltering out the hype with evidence-based reports on the cryptocurrency space, with a focus on #Bitcoin - https://t.co/pgRGU9CuKE