Andreas Schmidt @_znow
Security Researcher, Author of WATOBO siberas.de Germany Joined December 2009-
Tweets1K
-
Followers636
-
Following930
-
Likes3K
THE ANNOUNCEMENT: We’re going to make the prophecy of The Year of Linux on the Desktop come true. All the pieces are now in place. Time to go all in! omarchy.org/news/2026/08/o…
Microsoft’s signed Windows Defender Boot-Time Removal driver (BTR.sys) is a one-shot kernel component that decrypts an RC4-encrypted transaction list from an Alternate Data Stream and performs Ring-0 operations. An attacker with SeLoadDriverPrivilege can craft a valid encrypted config and load it early via a transient “Boot Bus Extender” service, abusing it as a trusted kernel primitive to bypass Tamper Protection, delete EDR/AV components before they start, drop malicious drivers, and gain persistence, without any vulnerability or BYOVD. No in-the-wild abuse has been observed. research.checkpoint.com/2026/btr-refor…
Agents on Rails: We ran 8 models against 21 atomic tasks to see which were best at writing Rails code. 3 runs each: a bug report, a security finding, a feature request. The first benchmark report with findings is now live. So: what did we discover? As of August 2026: - Most accurate: @claudeai Opus 5 by @AnthropicAI (by a hair). Solved 92% of runs (58 of 63). (But for a little more than half the cost, you get almost the same accuracy with @Kimi_Moonshot.) - Cheapest: @OpenAI GPT-5.6 Luna. 73% of runs solved at default medium reasoning effort, and all 63 of its runs cost 90 cents combined. - Fastest: Luna again, at a median of 3.3 minutes per run task. - Best combination of all three: @OpenAI GPT-5.6 Sol. 84% accuracy, costing $0.52 and 5 minutes per run. Read all the findings in the first full benchmark report from @evilmartians here: rubyonrails.org/2026/8/13/agen…
💥 Introducing "Januscape" (CVE-2026-53359) A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU. Triggerable on both Intel and AMD hosts. Threatens x86 public clouds (GCP, AWS) that expose nested virtualization. "16 years" latent. Successfully used as a 0-day exploit in "Google kvmCTF". To the best of public knowledge, the first KVM exploit research triggerable on both Intel and AMD. Details: januscape.io
Ok security twitter, I'm very confused by MS' response to my report. I have a way for an unelevated user to get SYSTEM to run arbitrary code by planting a file in a public folder then waiting for an event that *will* always happen. How does that not qualify for an EoP?
We're mostly an IDA shop at @CellebriteLabs, but I decided to play around with Ghidra. My main motivation was to experiment with agentic reverse engineering techniques. The result is an agent skill for Ghidra, which we are releasing publicly: github.com/cellebrite-lab… >>
This is really good, @AnthropicAI posted a document on how to apply the principles behind Zero Trust to AI Agents: claude.com/blog/zero-trus…
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at github.com/mandiant/flare…. Launched with: - Malware Analysis Crash Course - Go Reversing Reference - Intro to TTD
We got frustrated with dealing with vendor dependencies when reverse engineering large applications. @ITSecurityguard from @SLCyberSec’s Sec Research Team built Hyoktesu to solve this problem forever: github.com/assetnote/hyok… - releasing this today! Blog: slcyber.io/research-cente…
I finally let Claude do my pentest this week. Full 5-day engagement, zero human input. Here's what the client got: 😏 clawd.it/posts/10-repla… #bugbounty #pentesting #AI #cybersecurity #infosec #claudeai
@mattshumer_ The @trailofbits security auditing skills! Teach Claude to be an expert bug hunter: github.com/trailofbits/sk…
Oracle RCE Vulnerability CVSS 10.0 - affecting Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS nvd.nist.gov/vuln/detail/CV… oracle.com/security-alert…
When asked about LLM memory corruption exploit generation in the 2023-era of models I would often say that they were getting better at code generation but lacked understanding of how that code would execute at runtime, and that was a prerequisite for exploit generation. This requires reasoning and observation of code transformations through compilation steps, context and understanding of specific details of modern operating systems, memory allocators, caches, file formats etc. and how they affect program runtime. These are all details exploit developers obsess over with surgical precision out of necessity because you must be right every single time or your exploit just won't work. Since that 2023-era we have seen significant advancements in AI through RL/scaling but also a lot of agentic development. This has allowed the models to not just explore code better but also observe its runtime as it reasons through and builds exploitation primitives. The section on mitigation bypasses in Sean's writeup demonstrates why these capabilities are so hard to achieve without these advancements. They require the ability to reason not just about the code itself, but about how it will behave at runtime, and observe those behaviors as the primitives in the vulnerability, and the state space they create, are explored. A javascript interpreter is really a best case scenario for this kind of experiment because the attacker can run arbitrary code to shape the runtime in a way that is conducive to reliable exploitation. But conversely, a javascript interpreter is complex with many APIs that are reenter the Javascript runtime and lead to things like use-after-free vulnerabilities. This a very exciting time in program analysis and software security. Anyone who doubts this technology as a game changer is not paying attention. github.com/SeanHeelan/ana…
Ruby received a beautiful website redesign 💎 ruby-lang.org/en/
"Shopify is the patron saint of Ruby on Rails. Its infrastructure team is the backbone of our ecosystem, and its continued success the best case study of how far you can take this framework and language. They deserve a gawd damn parade for all they do." world.hey.com/dhh/six-billio…
Big news! We made the basic tier of the OpenHands Cloud FREE! This means that you can call state-of-the-art coding agents from your computer, phone, github, gitlab, slack, etc. for just the price of API credits or hosting your own language model! 🧵👇
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
Ten days left. The warm-up fades. Maultaschen were soft. Bean Beats were dark and burnt. But the beats of #ULMageddon will be brutal! #applyIfYouCan
blog.ret2.io/2025/04/23/pwn… this is so sick. i'm confident if i had the bug i would not have exploited it.
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/3]
Oli (C..1..P.H.Y) @marcolivermunz
2K Followers 457 Following Infosec addicted IT guy 🕵️♂️👨💻 | HTB Guru | Researcher & Pentester 🖊️ | White-Hat 🎩 | Bugs find me 🪲 | Part of the awesome #kaeferjaeger crew 💥
Patrik Grobshäuser @ITSecurityguard
32K Followers 304 Following Security Research @ Assetnote https://t.co/RmFwv6ItrQ https://t.co/qylqwXgc9I
Daniel Hauenstein @dhauenstein
2K Followers 605 Following AppSec Engineer. I also build IT sec teams. I am the Klaus Kinski of IT security. Hacking magician. #kaeferjaeger
c1sc0 @C1sc01
345 Followers 194 Following OSCP, OSEP, OSWE, OSED, OSCE3, OffSec, Pentesting, Hacking Enthusiast, #kaeferjaeger
Ⓒhrstph... @schniggie
3K Followers 1K Following security geek, 🄲🅈🄱🄴🅁, selfhoster, beer lover, Pragmatist https://t.co/itIxG00YGz https://t.co/PsNyHN0Pxr ᴅᴇ-ᴀɴᴏɴʏᴍɪᴢᴇʀ ᴡʜᴏ ᴇɴᴊᴏʏꜱ ᴏᴘꜱᴇᴄ ꜰᴀɪʟꜱ
joernchen @joernchen
8K Followers 518 Following Your mom's favorite hacker. Also at @[email protected]
ΡΛSCΛLSΞC @PascalSec
4K Followers 498 Following 👨💻 Team Lead Sol. Engineering @Intigriti 📺 Hacking Content Creator at @Hacksplained (paused) Views are my own and don't reflect the views of my employer.
Ivo @palaziv
424 Followers 1K Following pentester. oscp, osce, oswe. occasional bug bounty hunter @synackredteam and @Hacker0x01
Damian Strobel @damian_89_
8K Followers 1K Following Into SoftwareEng, IT Security & LLM/AI | https://t.co/QBwOsUeRXZ | https://t.co/L3Juw5scWM | https://t.co/dpYQmu6FxU
ϻг_ϻε @steventseeley
23K Followers 564 Following Artist disguised as a logician. Pwn2Own Winner. Spiritual Alchemy. An adept in the making.
Nicolas Krassas @Dinosn
161K Followers 786 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
@ret2bed is tired af @ret2bed
265 Followers 244 Following Bug Hunter 🪲 | Sharing leet vulns & tricks | Security Research & Hacking | rt != 👌 | only followed by cool people ✌️@[email protected]
Marius Avram @securityshell
16K Followers 1K Following Web Application Security Consultant. Two sons' proud dad! https://t.co/uEjJ0UQkhV
wvu @wvuuuuuuuuuuuuu
6K Followers 1K Following Sentient one-liner grepping the Internet for signs of intelligence.
0x5A1F @Saif_Sherei
5K Followers 1K Following some security stuff, opinions are based on experimental thought patterns resulting in delusional yet fun life choices. @[email protected]
shubs @infosec_au
60K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
Sophia Prescot @SophiaPrescot
31 Followers 143 Following Just a feral watermama. Lived in Dominican... Rep 🇩🇴 Singapore 🇮🇩 Italy 🇮🇹 & Iceland 🇮🇸 ⚓Deck officer.. @Virginvoyages
Satar @satar_nz
674 Followers 7K Following
L-K 🌸🥀_ @6naazp64113
1 Followers 147 Following
L. KELLER 🌻😊�... @ZT0pa662263
1 Followers 143 Following
Nora Jensen @jensen_nor60207
100 Followers 2K Following
Mariana perrons @BLechouchoute
0 Followers 97 Following
Gemma Bert @BP93VoJ8aG7nDTr
121 Followers 4K Following
Anand Hiswankar @HiswankarAnand
10 Followers 44 Following
TMO. @tmo_sh
27 Followers 405 Following root / networks. security. bughunting. everything with IT. Not very talkative here.
nothing is everything @IsEv3ryth1ng
1 Followers 463 Following
Ali BawzeEer @AliBawazeEer
272 Followers 5K Following A man who has been through a lot .. just like you! from insight -- to Hindsight -- to Enlightenment.
Alvlarouxor @Alvlarouxor431
53 Followers 3K Following
Lewis Arnold @Jossy435
30 Followers 92 Following Book Publicist @LitVanta Unlock the full potential of your book self publishing, guidance #book marketing, #book worm, #writing community
🎿 @vggkzt
973 Followers 6K Following
Jill @TautoFTkYrJ
11 Followers 400 Following Put away your cowardice and show your domineering power. When you fall, nobody helps you. It's more like a beast watching your jokes.
Rosemary @SairddiflQhLu
7 Followers 533 Following
RubyGrey @L91c5Nsa898H7A1
92 Followers 7K Following
yuval shitrit @yuvals02
4 Followers 204 Following
Rorsha @Rorsha2_eO
42 Followers 4K Following
nanjin002 @nanjin00272827
12 Followers 4K Following
Bwing @Bwing4for
3 Followers 780 Following
Slater @Slater18947
75 Followers 6K Following
Theata @TheatautKp2Z
14 Followers 1K Following
LillianHalifax @L0Z3I2LvX5Qw3f
68 Followers 7K Following
Laura Bopha Phillips @99cRA3Eibq2bu
11 Followers 333 Following Angel Investors Community has a 1-month free trial for new members. Welcome to join and verify our trading strategy https://t.co/yMXL4TNRqk
vikram251 @vikramtall37015
542 Followers 7K Following Internal Auditor(ITGC) , Security reasearcher, Bug hunter
Lindsay Dubois @LindsayDub72941
1 Followers 32 Following
Abdallah Mahrous @amahrous79
415 Followers 616 Following Fulltime bug hunter | german speaker | just doing my part
Michael Ritter @BigM1ke_oNe
115 Followers 314 Following security guy having fun identifying bugs/misconfigurations that lead to chaos.
Geoffrey Maverick @Geoffre22664233
351 Followers 4K Following is only when we take chances, when our lives improve. The initial and the most difficult risk that we need to take is to become honest.🥰🥰😘
Lauritz @_lauritz_
2K Followers 1K Following IT-Security Researcher, Pentester and Bug Hunter. Passionate about 💻, 🤽♂️, ⚜️, 🎸 and ⚽ (@VfLBochum1848eV ) #Kaeferjaeger + H1 Ambassador
Mohsen Mohari @MohsenMoha45512
0 Followers 84 Following
crawler_cookie_0 @crawler_cookie0
22 Followers 4K Following
Zeroday Co., Ltd. @ZerodayAIAST
327 Followers 4K Following AIAST An advanced interactive application security tool
Julien | MrTuxracer �... @MrTuxracer
40K Followers 441 Following Founder of @rcesecurity | #BugBounty | @Hacker0x01 MVH && H1-Elite | $1,5+ Mio in Bounties | Mobile Hacker | @[email protected]
Oli (C..1..P.H.Y) @marcolivermunz
2K Followers 457 Following Infosec addicted IT guy 🕵️♂️👨💻 | HTB Guru | Researcher & Pentester 🖊️ | White-Hat 🎩 | Bugs find me 🪲 | Part of the awesome #kaeferjaeger crew 💥
Patrik Grobshäuser @ITSecurityguard
32K Followers 304 Following Security Research @ Assetnote https://t.co/RmFwv6ItrQ https://t.co/qylqwXgc9I
Daniel Hauenstein @dhauenstein
2K Followers 605 Following AppSec Engineer. I also build IT sec teams. I am the Klaus Kinski of IT security. Hacking magician. #kaeferjaeger
Valeriy @Krevetk0Valeriy
6K Followers 924 Following Security enthusiast, bug bounty hunter at @Hacker0x01 and @Bugcrowd https://t.co/RjYvPJaXTW https://t.co/dkUfA2vywe
frycos @frycos
4K Followers 521 Following Private account! Red teamer @codewhitesec. @[email protected] @frycos.bsky.social
Intigriti @intigriti
215K Followers 669 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
vx-underground @vxunderground
448K Followers 375 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Sam Curry @samwcyo
102K Followers 1K Following
Florian Roth ⚡️ @cyb3rops
224K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
chompie @chompie1337
90K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
c1sc0 @C1sc01
345 Followers 194 Following OSCP, OSEP, OSWE, OSED, OSCE3, OffSec, Pentesting, Hacking Enthusiast, #kaeferjaeger
Ⓒhrstph... @schniggie
3K Followers 1K Following security geek, 🄲🅈🄱🄴🅁, selfhoster, beer lover, Pragmatist https://t.co/itIxG00YGz https://t.co/PsNyHN0Pxr ᴅᴇ-ᴀɴᴏɴʏᴍɪᴢᴇʀ ᴡʜᴏ ᴇɴᴊᴏʏꜱ ᴏᴘꜱᴇᴄ ꜰᴀɪʟꜱ
joernchen @joernchen
8K Followers 518 Following Your mom's favorite hacker. Also at @[email protected]
Greg Linares (Laughin... @Laughing_Mantis
38K Followers 2K Following 20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
ΡΛSCΛLSΞC @PascalSec
4K Followers 498 Following 👨💻 Team Lead Sol. Engineering @Intigriti 📺 Hacking Content Creator at @Hacksplained (paused) Views are my own and don't reflect the views of my employer.
LiveOverflow 🔴 hex... @LiveOverflow
163K Followers 1K Following wannabe hacker... he/him 🌱 grow your hacking skills @hextreeio
Tobi Weißhaar @_kun_19
1K Followers 83 Following MSc Advanced Computer Science | Pentester | OSCP | OSWE | CRTO | CRTP| Bug Bounty Hunter #kaeferjaeger
Ivo @palaziv
424 Followers 1K Following pentester. oscp, osce, oswe. occasional bug bounty hunter @synackredteam and @Hacker0x01
Brian Armstrong @brian_armstrong
3.9M Followers 835 Following Co-founder & CEO @Coinbase. Creating more economic freedom in the world. Co-founder @researchhub @newlimit. Not investment advice.
Bad Sector Labs @badsectorlabs
9K Followers 529 Following Cybersecurity news, techniques, exploits, and tools every week at https://t.co/UgKmeEEjIV 🐘 @[email protected]
Adam Jacob @adamhjk
20K Followers 1K Following CEO of Swamp Club, Co-Founder of Chef. Sustainable free and open source software communities. Music. He/Him. https://t.co/fyc6yziWBv
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ | RE/VR/ED
kernelstub (Prepakis ... @kernelstub
3K Followers 29 Following founder @ skuntir; offensive security #Pwn2Own
Judit Polgar @GMJuditPolgar
143K Followers 265 Following The greatest female chess player of all time. #ChessConnectsUs #QueenOfChess
bugcrowd @Bugcrowd
203K Followers 6K Following The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
Roan @RohOnChain
71K Followers 405 Following building my life around AI agents, LLMs & quant systems for prediction markets + crypto
IT Unprofessional @it_unprofession
79K Followers 6 Following I am a proud IT Unprofessional with 25+ years of experience turning computers off and on. Did you try blowing on it?
Würth Elektronik Gro... @we_online
6K Followers 1K Following Home of quality services and products such as circuit boards, electronic & electromechanical components & system assemblies ⚡️ #MoreThanYouExpect
Sprocket Security @SprocketSec
1K Followers 204 Following Continuous Security Testing - Reduce exposure time & prevent breaches using proven human-driven testing methodologies.
Sn0rkY @_Sn0rkY
2K Followers 1K Following Red Team for real, Security researcher, VoIP hacker, Ultra-trailer, Ambassador of Happiness and Healthy Living
hashkitten @hash_kitten
4K Followers 190 Following vulnerability research @assetnote // hacking // codegolf // ctf with 🛹🐶
Micah Van Deusen @micahvandeusen
315 Followers 202 Following Offensive Security • Google / Mandiant • @[email protected]
Daniel Streefkerk @egosumdns
558 Followers 989 Following Christian, Husband, Father, IT & Cyber Dabbler. Spent nearly 2 decades in the IT support & ops trenches before moving across to cyber security since 2019.
Khoa Dinh @_l0gg
2K Followers 125 Following
Blaklis @Blaklis_
12K Followers 82 Following Security researcher - my researchs will be on https://t.co/2PnyCvqAIm Mostly inactive, soon replicated from BSKY.
bolt.new @boltdotnew
122K Followers 48 Following Build without boundaries. Create stunning web apps that scale to millions by collaborating with AI.
Ai2 @allen_ai
86K Followers 448 Following Breakthrough AI to solve the world's biggest problems. › Join us: https://t.co/MjUpZpKPXJ › Newsletter: https://t.co/k9gGznstwj
f00fc7c800 @f00fc7c800
2K Followers 7K Following
watchTowr @watchtowrcyber
13K Followers 12 Following watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.
Rohan Paul @rohanpaul_ai
157K Followers 7K Following Compiling in real-time, the race towards AGI. 🗞️ Get my daily AI analysis newsletter to your email 👉 https://t.co/6LBxO81tfN
SpaceXAI @SpaceXAI
2.1M Followers 6 Following
Synacktiv @Synacktiv
21K Followers 274 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
Alex Reibman 🖇️ @AlexReibman
59K Followers 863 Following Hyper Engineering @agentopsai Vibes @cerebral_valley Hack reporter
Jason Scott @textfiles
52K Followers 629 Following Proprietor of https://t.co/sdyjXHCZF7, historian, filmmaker, archivist, storyteller. Works on/for the Internet Archive. Rank Amateur. Pitiful Man.
parzel @parzel2
942 Followers 290 Following Hacker based in Berlin | Working at @mod0 | https://t.co/6MZdC7Pcsk | he/him
Rust Trending @RustTrending
34K Followers 1 Following Automated bot tweeting trending Rust repositories on GitHub. Not an official @github or @rustlang product. Made by @pbzweihander_rs, but not curated by.
The Haag™ @M_haggis
10K Followers 2K Following ⚔️ Prevention Engineering at MagicSword | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer
hextree.io @hextreeio
8K Followers 2 Following 🌱 Grow your cybersecurity skills with concise and well-edited video courses - in early-access, sign-up now! Created by @LiveOverflow and @ghidraninja.
Amir Rajan @amirrajan
5K Followers 699 Following Indie game dev with commercial titles on Switch, iOS, and Android. Compiler/runtime hacker. DragonRuby LLP (Game Toolkit, RubyMotion). :wq
Piotr Bazydło @chudyPB
5K Followers 318 Following Principal Vulnerability Researcher at watchTowr | Previously: Zero Day Initiative | @[email protected]
Carsten Maschmeyer @maschmeyer
36K Followers 337 Following Ich investiere in Gründerinnen und Gründer. Nicht in Businesspläne. 📈 Start-Up Investor & Mentor 🖋️ Autor 🦁 TV-Löwe bei #DHDL @vox 🌹 @VeronicaFerres
Nate Hopkins @hopsoft
6K Followers 2K Following Husband, Dad, Software Writer, Maker. Creator of several Ruby, JavaScript, and (soon) Elixir open source libraries - personal views only.
Garry Kasparov @Kasparov63
1.1M Followers 1K Following Founder of @Renew_Democracy. Co-founder @WLCongress. Activist, speaker, 13th World Chess Champion. Autocracy in America podcast: https://t.co/xemlxTR3IN
Ruby Unconf @RubyUnconfEU
618 Followers 67 Following Next Ruby Unconf on the 8th & 9th of June 2024. Follow this account for news and updates! Also, check out https://t.co/gxMNfDEnUd













































