MrSandman @cmhacks
29a Labs https://t.co/TUHeoJdtam // Security Researcher @ ZDI cmhacks.org 3132372e302e302e31 Joined December 2010-
Tweets3K
-
Followers192
-
Following690
-
Likes2K
👨💻 A hard day’s work for a DPRK IT worker. One of the “developers” hired by a fake DeFi startup works through the assigned project: frontend, backend, upgradeable smart contracts, MetaMask, testnet faucets, and ChatGPT. All recorded in #ANYRUN Sandbox. This footage is from the undercover investigation into the Famous Chollima IT worker scheme — after the fake interviews were over, and real access had been granted. 👀 What they do once onboarded? Read the full story: any.run/cybersecurity-…
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public. github.com/MSNightmare/Sh… The PoC works with the latest August 2026 patch
Decrypt D-Link R95 router firmware: dd if=firmware_image.bin of=enc.bin bs=512 skip=1 openssl aes-256-cbc -d -in enc.bin -out dec.bin -k BE81AE1B6F523AC7164C4FD67B6BD8FD
🚨 This one's nasty. Googled "codex macbook download" — first result is a sponsored ad pointing to chatgpt.com. The real domain. It opens a shared ChatGPT chat with friendly install steps: open Terminal, paste this command. That command hides a base64 string. Decoded 👇 curl to trekmesh15[.]com — a known ClickFix domain dropping MacSync Stealer. Passwords, keychain, crypto wallets. Gone. So the infection chain is: Google Ad → legit chatgpt.com share link → you infect yourself. No exploit. No download. Just trust in a Google ad and a ChatGPT page. Don't ever paste Terminal commands from an ad or a shared chat. Tell your Mac friends.
🇰🇵 We built a fake company. We recruited DPRK IT workers. We recorded everything. 📹 The full story is finally out: hours of footage, IOCs, things we never showed at DEF CON and even a familiar face from Season 1. Smile, You’re on Camera: Episode 2.
A PoC/exploit has been discovered for vulnerability CVE-2026-64561 Vendor: Linux Product: Linux Description: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root after making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately. Link: github.com/V4bel/Zapscape #dbugs_vuln
🚨 PoC released: CVE-2026-27912, a Windows Kerberos privilege escalation vulnerability, now has a public exploit. The flaw affects Windows Server 2012 and allows an authorized attacker to elevate privileges over an adjacent network. PoC: github.com/semperis-commu… #Microsoft #Windows #Kerberos #CVE #PoC #CyberSecurity #ActiveDirectory #Infosec
It's Friday, the best day of the week to drop 0-days. @pwn_ai dropped XSS2Shell WordPress Core preauth XSS → RCE. 🫥
Introducing XSS2Shell ⛓️: WordPress Core preauth XSS→RCE vulnerability affecting 43% of the internet, discovered autonomously by pwn (using open-source models), affecting all WordPress versions. pwn.ai/blog/xss2shell Please patch CVE-2026-64638 as soon as possible!
CVE-2026-34348 exploitation demo from my #BHUSA "Pass-the-Passkey Family of Attacks" talk: WebAuthn assertion from recent YubiKey authentication is extracted from Windows Event Log and replayed against Microsoft Entra ID using Passkey Injector. Whitepaper: specterops.io/passkeys
Lazarus used this as a zero-day. No BYOVD needed. The vulnerable driver is already on every Windows machine. CVE-2024-21338 exploits appid.sys (AppLocker's driver) to call a user-controlled function pointer in kernel mode. The exploit uses ExpProfileDelete as a valid kCFG target to decrement PreviousMode from 1 to 0. Once PreviousMode is flipped, NtWriteVirtualMemory and NtReadVirtualMemory skip all security checks. Full admin-to-kernel LPE with token manipulation. Works on Windows 10 and 11 with HVCI enabled. Full PoC included. If you just read the PreviousMode mitigation post by @yarden_shafir, this is the CVE that forced Microsoft to add it. hakaisecurity.io/cve-2024-21338… github.com/hakaioffsec/CV… Author: @HakaiOffsec #WindowsInternals #ExploitDevelopment #InfoSec
We have published our @rapid7 analysis of CVE-2026-63077, an unauth RCE in JetBrains TeamCity that was disclosed last week and already added to KEV as being exploited in the wild. Check out our full analysis, IOCs, and PoC. This one has a gnarly gadget chain and a polygot SQL/JSP payload: rapid7.com/blog/post/ra-u…
🚨 Linux KVM'de yeni kritik VM Escape açığı duyuruldu ve PoC yayınlandı! Zapscape (CVE-2026-64561) adı verilen yeni güvenlik açığı, duyurulduktan bir kaç gün sonra PoC GitHub'da kamuya açık olarak paylaşıldı. PoC: github.com/V4bel/Zapscape Açık, nested virtualization etkin olan KVM sistemlerinde, guest root yetkisine sahip bir saldırganın sanal makineden çıkarak host üzerinde root yetkisiyle kod çalıştırabilmesine olanak tanıyor. 🔹 CVE: CVE-2026-64561 🔹 Etkilenen: Linux KVM/x86 🔹 PoC: Yayınlandı 🔹 Risk: VM Escape -> Host Root KVM tabanlı sanallaştırma kullanan sistem yöneticileri güvenlik güncellemelerini ve nested virtualization yapılandırmalarını mutlaka gözden geçirmeli.
Over 90 days have passed since I reported the libpng APNG OOB Write 0day. This vulnerability enables memory corruption that can, in some scenarios, lead to code execution (as demonstrated in the video). #0day #AI #LIBPNG arielkoren.com/vulnerabilitie…
Public Exploit Code Released for CVE-2026-50343, a Windows InstallService Flaw That Grants SYSTEM Privileges securityonline.info/cve-2026-50343… 🔥
For internal education, I wrote a code to get SYSTEM shell with service creation method. By specfying local admin credentials, it allows to get SYSTEM shell from non-administrative shell. github.com/daem0nc0re/Pri…
🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability. GitHub: github.com/777erp/CVE-202… The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
CVE-2026-66066 gist.github.com/win3zz/ae02cb1…
⚠️🚨⚠️🚨⚠️🚨⚠️ #brokensec - Ghidra RCE Exploit kit Fully weaponized exploits for **CVE-2026-52751** and **CVE-2026-52750** Based on public research from bikini/exploitarium/ghidra-12.1.2-rce-ace-calc-poc #RCE #security #cybersec #hacking #0days #exploit #antisec #infosec #brokensec #cybernews #ghidra
Full details and technical analysis can be found here: research.jfrog.com/post/sqlite-cr…
CVSS 10.0, but the evidence doesn't add up. CVE-2026-51302 in SQLite claims critical impact, but: ❌The supplied PoC does not reproduce ❌The source code does not match the claims And it's not an isolated case: JFrog found the same issues in 54 of 55 CVEs published by the same
Wrote up a blog for the PipeWire sandbox escape via malicious library loading CVE-2026-5674 Details ⬇️ embracethered.com/blog/posts/202…
吉野@連邦(renpou.... @yoshinokentarou
20K Followers 19K Following 今年で24年目な連邦の人 https://t.co/9JpugGyknD noteにて地下ゲーム考古学話なども書いております https://t.co/vrPnwsdslC
NNN @NullPointer2a
0 Followers 94 Following
Roshan_lea @Roshan_lea
86 Followers 1K Following
Hacker Stickers @HackerStick3rs
3K Followers 7K Following we're just here to spread neat hacking and cybersecurity related stickers. need high quality vinyl stickers made? DM us.
Anderson Nascimento @andersonc0d3
4K Followers 7K Following Director & Security Researcher @alleleintel
Taylor @taylortians
4 Followers 277 Following
Josmell Gallo @JosmellGallo
6 Followers 48 Following Cybersecurity Researcher | OSINT · Leaks · Defacements Founder @GalloTechSec— Latam 🌎 Everything is documented. Nothing is forgotten.
Senn @senn_twt
2K Followers 220 Following English/Português/日本語 Video and audio generalist cat, sound design and also 3D by the side @pngfundofalso ❤️ Partner in Crime
KIUQS @kiuqs
1 Followers 5 Following
NetCloak @NetCloak9487
1 Followers 37 Following
Nikodem B. @BNikodem16052
1 Followers 5 Following
Dan "18pF flip-flop" @dcominottim
2K Followers 6K Following Passionate about computer HW and SW design & architecture. Walking the Way of the Fool.
Johnny @Luckyrocky2028
252 Followers 7K Following Stay Hungry, Stay Foolish. Only those who are self-disciplined can attain true freedom.|No Politics.
DeLuks @0xDeLuks
516 Followers 242 Following
Modular Reaper Imager @ModReaperImager
49 Followers 405 Following Industrial Atmospheric Darkness / Manufactured Nightmare-Filled Mechanized Soundscapes / MUSIC to BURN the WORLD DOWN to
Chungi @chungi_fungi
50 Followers 2K Following
gengarzx @gengarzx
20 Followers 955 Following
Svyatoslav @4luc4rd_vx
0 Followers 10 Following
SIEMtune @jtheadstrong
73 Followers 928 Following 25+ yr InfoSec professional delivering results daily
Enemy Mind @enemyminds
822 Followers 4K Following I believe in my nation and its people. Every citizen of this nation is responsible to one another for its improvement. We must crush those who seek to harm us.
loiute buio @LoiuteB4155
3 Followers 408 Following
Muhmmad Irfan @Muhmmad69953409
20 Followers 2K Following
Felix Zhang @FelixZhang958
23 Followers 93 Following
vx-underground @vxunderground
444K Followers 370 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Jorge D. @JorgeD12102
0 Followers 120 Following
Michael @Elkami @Michaelelkamika
175 Followers 412 Following Computer Security Researcher, Linux & BSD
Edu @EduardoYoloo
512 Followers 3K Following Computer engineering graduate. Interested in tech, politics, strength and health.
Rocío Valdivia @rociovaldi
5K Followers 5K Following Strategic Growth and Partnerships at @automattic. #OpenSource #ComputerEngineer #RemoteWork
fixoulab @fixoulab
620 Followers 2K Following Open Source fan, électronique, hacking et retrogaming. CEO @ FACTORFX & ITSM-NG. @[email protected]
skrappy0x4a @skrappy0x4a
412 Followers 2K Following Lead on Cyber Defense | GWOT | Dad | НОРД | 🏍| ◧◧◧ | 🌲
MignonBryce @9Re048RB6fmy7z
74 Followers 7K Following
Dr. Dave Venable @davevenable
13K Followers 10K Following Focused on building resilience in democracies | Former U.S. intelligence officer | Chair, @ISRSngo | Board director & CISO | @TheCipherBrief @aiinonprofit
Nett0 @nett0eth
9K Followers 2K Following Design • IA • Web3 • Cripto Head of Research @ModularCrypto prev. @arbitrum • @zerion Creator Affiliate @nansen_ai
まゆひらa @riddi0908
2K Followers 399 Following main @Mayu_Hiraizumi // 生成AI等。他の方のキャラを除く #aiart 画像は自己責任でご利用いただけます。 // 🗨️URLから質問箱へ行けます。質問以外のメッセージでも何でもどうぞ(気まぐれ回答)。
Carlo @Italianclownz
7K Followers 4K Following 4GQTV Producer | [email protected] | ByLines: Wired | Aspiring Filmmaker | Pop-Culture Enthusiast | LLM Enthusiast | ROCmFP4 Quant Creator
Stable Diffusion Tuto... @SD_Tutorial
8K Followers 89 Following 👉 Ai models local installation 👉 Comfy Workflows 👉 Tutorials (Image Gen, Video gen) FOLLOW WEBSITE 👇👇
Alok @analogalok
3K Followers 212 Following Mechatronics Engineer AI belongs on your device. • Offline inference • No subscriptions. Teaching you to own your AI Intelligence Stack
Mike Key @1337hero
2K Followers 274 Following Senior Software Engineer going hard on AI. Building local LLMs & AI agents Homelab - 3x AMD R9700 & Strix Halo Shipping code @ https://t.co/4zGfh2iWCf
tonbi @tonbistudio
16K Followers 2K Following No topic is too difficult, it just hasn't been explained well enough yet Teaching AI on https://t.co/cjQgGYSkBG Running https://t.co/pUSf1ypfc2
Unsloth AI @UnslothAI
89K Followers 480 Following Train and run models locally! 🦥 https://t.co/2kXqhhvLsb
Daniel Han @danielhanchen
35K Followers 2K Following Building @UnslothAI • Making open-source LLMs faster, better & more accessible • YC S24 • ex-NVIDIA ML
ɐʞsǝs @akses_0x00
597 Followers 415 Following _flags =_dev | _app_sec | _grc | _leader | _cat_owner | _bounty_hunter; _age = 0xDEAD ^ 0xC135 ; built stuff u use my opinions are not those of my employer(s)
Red Hat AI @RedHat_AI
12K Followers 2K Following Accelerating AI innovation with open platforms and community. The future of AI is open.
NetAskari @NetAskari
12K Followers 138 Following Blog on Chinese cyber operations, online surveillance, always on the hunt for leaked documents : https://t.co/VL2r9IVMh2 | https://t.co/eVXinXmzYd
respaldo pelis comuni... @YugiohArts
21K Followers 2 Following
吉野@連邦(renpou.... @yoshinokentarou
20K Followers 19K Following 今年で24年目な連邦の人 https://t.co/9JpugGyknD noteにて地下ゲーム考古学話なども書いております https://t.co/vrPnwsdslC
CSIC @CSIC
925K Followers 2K Following Consejo Superior de Investigaciones Científicas (CSIC), el mayor organismo público de investigación de España. Spanish National Research Council.
Max Zanoga @zanoga
8K Followers 2K Following AI/ML Engineer | Co-founder https://t.co/XPoYOHa7wv | Building AI infrastructure | 32x RTX 3090 GPU Cluster
Kekius Maximus @Kekius_Sage
129K Followers 698 Following Physics • Math • Cosmos • Nature • Science in all forms. for work DM my telegram @kekius_sage
Fabio Guzman @FGuzmanAI
3K Followers 602 Following On-device ML Engineer | 🤖Passionate about reverse-engineering neural nets | 🚀Optimizing large models for the edge 💻📱
vost @foolibuster
74K Followers 526 Following I lowkey invented Twitter STORE: https://t.co/ORsJoNOaBl please consider support: https://t.co/cT6pAwgloZ https://t.co/VzJ4LzR5MX
vxdb @vxdb
26K Followers 503 Following Journalist | Cybercrime News | Staff @vxunderground | PGP - https://t.co/VWwniNXZtK
Joseph Ravichandran @0xjprx
4K Followers 542 Following PhD Student studying Microarchitectural Security @MIT
Edmund Humenberger @ico_TC
9K Followers 766 Following mostly about open source FPGA tools and chip design tools
Amano @amano_labs
1K Followers 3 Following Building the future of hearing care. Founder of the world's most affordable hearing aid.
V4bel @v4bel
4K Followers 156 Following Independent Vuln. Researcher / Pwn2Own Berlin 2025, 2026 / Google kernelCTF 0-day / Google kvmCTF 0-day / Pwnie Awards 2025, 2026
Yuval Adam @yuvadm
4K Followers 1K Following In the words of Archimedes, give me a long enough lever, and a place to rest it - or I will kill one hostage every hour.
JP Aumasson @veorq
20K Followers 984 Following Serious Cryptographer https://t.co/yOkMDW2B9a BLAKE3 SipHash SLH-DSA codesigner @taurus_hq cofounder+CSO https://t.co/S0OVGwCF2Y
left curve dev @leftcurvedev_
6K Followers 410 Following low iq, high vram — sharing local ai and coding stuff
Seokchan Yoon / 윤�... @_seokchan_yoon
780 Followers 512 Following Security Researcher at @zellic_io / Security Contributor of GitHub, GitLab, Python, Django, FastAPI, Apache Airflow, Ruby, Rails, Spring / speak:🇰🇷🇺🇸🇯🇵
Qrious Secure @qriousec
3K Followers 4 Following Pwn2Owner since 2020 Debugger is main vehicle to satisfy our boundless Qriousity. A non-profit hackers' club driven by passion.
Carlos Coronado @CarlosGameDev
11K Followers 2K Following Indie Dev. 7 juegos multipremiados lanzados en consola! Profe de Unreal Engine. Desarrolla CUALQUIER juego facilmente en UE5 con Ultra Game Template!
Pippo @itz_pippo
4K Followers 83 Following
Doc TB @d0cTB
7K Followers 394 Following Fighting marketing bullshit since 2001! Memtest86+, CPU-Z Validator & Universal Chip Analyzer. Ex-@CPCHardware. Scientiste. 🇧🇪
KIUQS @kiuqs
1 Followers 5 Following
stevibe @stevibe
28K Followers 1K Following LLM. Local AI addict. Building @BenchLocalAI Builds things nobody asked for. Benchmarks things for fun.
GhostBSD Project @ghostbsdproject
4K Followers 82 Following GhostBSD is a simple, elegant, and friendly BSD operating system for desktops and laptops based on the latest FreeBSD STABLE.
XLibre @XLibreDev
5K Followers 39 Following X11 display server. Striving to improve the existing code base while maintaining backward compatibility to make X11 a viable choice for the future.
templar @tplr_ai
13K Followers 4 Following incentivised internet-wide training - an order of @covenant_ai
Rohan makes ASICs �... @always_ff_rohan
6K Followers 506 Following Exploring the ASIC lore, semiconductors and geopolitics. Author of /get in losers we're building an ASIC/
OptiJuegos @OptiJogos
15K Followers 34 Following Hola modifico juegos para computadoras muy negligentes! Tengo el record mundial de pepsiman y una pagina con mis proyectos
Dark Web Informer @DarkWebInformer
224K Followers 84 Following One guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!
HostVDS.com @hostvds
135 Followers 6 Following Instances from $0.99/mo ⚡ 🇺🇸 (CA, TX, MO), 🇳🇱 (Amsterdam), 🇫🇷 (Paris), 🇫🇮 (Helsinki), 🇱🇻 (Riga), 🇭🇰 (Hong Kong)
SidecarTridge @sidecartridge
630 Followers 432 Following Retro computing on Raspberry Pi Pico and RP2040 and RP2350 steroids. Revitalize your vintage computers with our devices, a series of coprocessor boards.










































