Damian Pfammatter @dp__pd
Joined January 2018-
Tweets17
-
Followers38
-
Following139
-
Likes55
Things are getting fun: Teach agents how to find sources/sinks, do static taint analysis with our #Binja plugin #Mole, and triage paths with live/emulated target access to validate findings autonomously. Reported 2 new vulns: remote unauth. stack BOF + auth. OS command injection.
Similar experience with responsible disclosure for #ArgoCD. Reported a blind SSRF vulnerability back in January (clearly less critical than Synacktiv's findings), but so far the only visible action has been assigning the GitHub Advisory a "Triage" label.
CI/CD pwnage with a pre-auth RCE in #ArgoCD by @hugow_vincent 💥 Discover how a single misconfiguration in a Helm chart can lead to a full cluster compromise sprinkled with some CodeQL shenanigans! 🥷 synacktiv.com/en/publication…
Full report: raw.githubusercontent.com/cyber-defence-… Tool: github.com/cyber-defence-…
We analyzed how different LLMs and prompt strategies impact bug triage performance in our #BinaryNinja plugin #Mole. TL;DR: Real-world code is far harder than synthetic benchmarks, false positives dominate, stability varies by model, and prompt tuning is strongly model-dependent.
First two unauthenticated RCE CVEs published - Discovered with the help of our #Binja plugin #Mole! 🔗 Advisory: certvde.com/en/advisories/… 🔗 Mole: github.com/cyber-defence-… More vulnerabilities have been reported - stay tuned for upcoming advisories.
Static pointer tracking is tricky. Just shipped some improvements to my #BinaryNinja plugin #Mole: it now tracks array and struct members more precisely. An example on how Mole does this: github.com/cyber-defence-… Binja's multiple ILs make precise analysis so much more powerful!
Talk is ready - taking off to #BHEU @BlackHatEvents!
#Morion has been accepted for @BlackHatEvents #BHEU and will be presented at #BlackHatArsenal this December in London! blackhat.com/eu-24/arsenal/…
I've written a detailed showcase to highlight some of the tool's features (and current limitations). The showcase illustrates how the tool can, for example, help assess if a bug is exploitable and if so, assist in crafting a functional exploit: github.com/cyber-defence-…
A while back, I wanted to learn about @qb_triton and symbolic execution in general, and to research its challenges when it comes to real-world binaries. What began with a few simple scripts evolved into PoC tool called Morion, which I've just released. #symbex #libtriton #morion
@HatforceSec @cydcampus @IEEE The paper should soon be listed on the conference website: ieeeeurosp.github.io. Give me a DM if you want me to share it directly.
If you are attending #EuroSP22 and are interrested in our work or the @cydcampus in general, let us know. We are happy to discuss!
CI/CD pwnage with a pre-auth RCE in #ArgoCD by @hugow_vincent 💥 Discover how a single misconfiguration in a Helm chart can lead to a full cluster compromise sprinkled with some CodeQL shenanigans! 🥷 synacktiv.com/en/publication…
How to setup network monitoring for your home IP in 4 easy steps using the Shodan CLI: asciinema.org/a/231048
Great audience at my talk and a nice @swisscyberstorm coference in general. Leaving with plenty of new ideas to extend my research...
You missed the interesting @swisscyberstorm talk "Hidden Inbox Rules in Microsoft Exchange" by @dp__pd? All infos about his research and the attack can be found here: blog.compass-security.com/2018/09/hidden… #SCS18
Compass Security Blog: Hidden inbox rules in Microsoft Exchange… or how to secretly steal your messages. Topic presented at this year’s @swisscyberstorm. #DFIR blog.compass-security.com/2018/09/hidden…
Baldanos @Baldanos
751 Followers 109 Following
Sam Thomas @xorpse
707 Followers 641 Following Program analysis. Reverse engineering. Backdoor detection. Head of Research @RevEng_AI. Creator of @VulHuntRE.
Eleanor Clayton @EClayton69853
1 Followers 168 Following Recruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If intereste d, please contact https://t.co/Iw8ZZiNKCg
Yves Bieri @yves_bieri
457 Followers 383 Following Security enthusiast and pentester 👨💻 Pwn2Own 2023-26 👾 CTF with PPP 🖥
Hans Fischer @HansFischer4368
1 Followers 526 Following Infosec, Entrepreneur, Lifestyle Coach, Food Enjoyer, Business Angel, Web Surfer, Air Breather, Author, Philantropist, CEO of Cyber, Artist, Crypto Investor
nine @nine_ch
971 Followers 4K Following Nine Internet Solutions AG is the leading provider of managed platform and infrastructure services in CH. For status information follow @nine_ch_status.
`Ivan @Ivanlef0u
11K Followers 4K Following
Leshe @Leshe520957
63 Followers 5K Following
Stephan Berger @malmoeb
29K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Thang Duong (Dương ... @realDcThang
65 Followers 139 Following
CRITIS 2021 @critis21
112 Followers 200 Following The 16th International Conference on Critical Information Infrastructures Security #CRITIS2021 was held on 27-28-29 Sept, 2021 at #EPFL with the @cydcampus
Anil Kurmus @kurmus
945 Followers 682 Following Systems Security @IBMResearch. Speculative exec, kernels, filesystems, exploitation, mitigations. Opinions are mine only. 0x381A1757. @[email protected]
Mathias Humbert @MathiasOZ
371 Followers 434 Following Associate professor @unil. @EPFL and @UCBerkeley alumnus. Views are my own. He/him
Martin @MasorX
167 Followers 512 Following Mainzer abroad. @openskynetwork. @cydcampus. Alumni @avsecoxford. @[email protected]
Alain Mermoud @alainmermoud
381 Followers 790 Following 👨🏼🔬Head of Technology Monitoring Team @cydcampus 🎓PhD in #InformationSystems @heclausanne; MBA @ege_fr 🏦Previously @CreditSuisse; @BIS_org
Carel van Rooyen @carelvanrooyen
1K Followers 4K Following red & purple team operations,*nix plumber,bass,org-(mode/roam),🇨🇭🇿🇦,🌶 & 🎶 addict. SMI²LE. Herbivore. Opinions my own, not that of my employer
Mike @MySnozzberries
558 Followers 2K Following I Build-Break-Repeat, AWS, Azure, MS, Cisco, InfoSec https://t.co/eN8iK5IMuL
Manuel @0xc0ffee
450 Followers 2K Following Sec dude during the day, beer brewer at night. neutral as a neutron. backout plan: 40 30 78 63 30 66 66 65 65 40 69 6e 66 6f 73 65 63 2e 65 78 63 68 61 6e 67 65Jan-Tilo Kirchhoff ja... @jatiki
398 Followers 1K Following A pathfinder in today's ever changing security landscape.
Nicolas @NicolasHeiniger
396 Followers 192 Following Husband and father, boardgame player, amateur photographer... and red teamer for a living. ⚠️This is a personal account and isn't related to my employer⚠️
Compass Security @compasssecurity
3K Followers 111 Following Penetration Testing, Red Teaming, Incident Response, Bug Bounty, Security Training, Cyber Range
Mathias Vetsch @mvetsch
54 Followers 353 Following
Thierry Viaccoz @viaccoz
97 Followers 76 Following Working in infosec, quite fond of privilege escalation in Active Directory environments.
Thomas Roethlisberger @troethli
403 Followers 434 Following curious infosec guy, red teamer, incident responder, pentester, appsec consultant, former software engineer, troubleshooter | I do not speak for my employer
Mathias Fuchs @mathias_fuchs
3K Followers 949 Following Something with IR and Intelligence @InfoGuardAG, Certified Instructor and author @SANSInstitute (@SANSEMEA), Former Principal IR Consultant @Mandiant
nks0ne @nks0ne
517 Followers 2K Following it security analyst / security engineer - breaking stuff, building stuff, chillin', it security, dfir, dnb, reverse engineering
Cyrill @bcyrill
105 Followers 1K Following
cybrz @cybrz
169 Followers 385 Following
ᴍᴀᴛᴇ @1ultimat3
183 Followers 388 Following
@emanuelduss@infosec.... @emanuelduss
857 Followers 1K Following IT security. Linux & network protocols. Pentesting web applications, networks & AD infrastructures. Mostly technical stuff here. @[email protected]
PagedOut @pagedout_zine
6K Followers 10 Following Paged Out! is a free magazine about programming, hacking, security hacking, retro computers, modern computers, electronics, demoscene, and other amazing topics.
Binary Wizards @BinaryWizards
5K Followers 560 Following Binary Wizards: security, reverse engineering, programming, AI and more.
Gynvael Coldwind @gynvael
39K Followers 1K Following security researcher/programmer/director @ HexArcana Cybersecurity GmbH ⁂ @pagedout_zine ⁂ @DragonSectorCTF ⁂ https://t.co/ShG2c5As1K ⁂ ex-Google ⁂ he/himBaldanos @Baldanos
751 Followers 109 Following
Malware Unicorn @malwareunicorn
166K Followers 6 Following Mostly on @malwareunicorn.bsky.social @Straikerai. Ex-Microsoft. Ex-Meta.
Alex Matrosov @matrosov
20K Followers 2K Following Security REsearch @Anthropicai · Breaking & Fixing AI Failure Modes | Founder @binarly_io · @SBOM_Tools · @REhints | Author “Rootkits & Bootkits" (https://t.co/1wd2dfYHY6)
Sam Thomas @xorpse
707 Followers 641 Following Program analysis. Reverse engineering. Backdoor detection. Head of Research @RevEng_AI. Creator of @VulHuntRE.
Synacktiv @Synacktiv
21K Followers 274 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
James Forshaw @tiraniddo
49K Followers 336 Following Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
Hexacon @hexacon_fr
6K Followers 1 Following Offensive security conference in the heart of Paris. 16-17th October 2026 Join our Discord server! https://t.co/Btl15G8LsI
itszn @itszn13
11K Followers 740 Following Amy | Security researcher @ OpenAI | https://t.co/W1SE7NmCx8 | bsky: https://t.co/JBmOGE4YKO | LLM ART: https://t.co/7FtQ8O8nAW
Samuel Groß @5aelo
25K Followers 524 Following Working on Project Zero, Big Sleep, and V8 Security. Personal account. Also @[email protected] and https://t.co/aVitnPjBie
Tim Blazytko @mr_phrazer
6K Followers 262 Following Binary Security Researcher & Trainer | PT Chief Scientist @ Emproof Also at https://t.co/YBfgAt3kc7
Jordan Wiens @psifertex
6K Followers 1K Following Worst developer among many good ones making https://t.co/XCCx7ED5uf
Manuel @0xc0ffee
450 Followers 2K Following Sec dude during the day, beer brewer at night. neutral as a neutron. backout plan: 40 30 78 63 30 66 66 65 65 40 69 6e 66 6f 73 65 63 2e 65 78 63 68 61 6e 67 65
Peter Goodman @peter_a_goodman
895 Followers 423 Following C++ developer specializing in source and binary program analysis and transformation.
Binary Ninja Devs @BinjaDevs
1K Followers 6 Following Group account for random posts by the Binary Ninja developers
Richard Johnson @richinseattle
19K Followers 3K Following Computer Security, Reverse Engineering, and Fuzzing; Training & Publications @ https://t.co/mloVP6rPB7; hacking the planet since 1995; Undercurrents BOFH
vx-underground @vxunderground
443K Followers 369 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Adrian Herrera @0xadr1an
1K Followers 760 Following Security researcher with a penchant for functional programming. Building fuzzers @InterruptLabs. PhD @ANUComputing + @HexHiveEPFL.
b1ack0wl @b1ack0wl
14K Followers 666 Following 0day Researcher / Baker / 0wl / Founder of @team_h00terz
REcon @reconmtl
18K Followers 708 Following REcon: Annual reverse engineering and security conference held in Montreal.
Vector 35 @vector35
10K Followers 2K Following Makers of the Binary Ninja - Reverse Engineering Platform. https://t.co/opkys50srq Also posting at https://t.co/2HEfgOtSSR
Nicolas Krassas @Dinosn
159K Followers 781 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
RE//verse @REverseConf
4K Followers 30 Following A conference for all things in the reverse engineering universe... https://t.co/X54VHq2eD4
Adnan Khan @adnanthekhan
5K Followers 266 Following Security Engineer | Part Time Security Researcher | Build Pipeline Menace | All thoughts and opinions are my own | 🍉
James Kettle @albinowax
84K Followers 103 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
Analysis Center @jpcert_ac
13K Followers 2 Following JPCERT/CC 分析センター(Analysis Center)の公式アカウントです。 分析センター内の日々の分析業務によって得られた情報や知見などを配信しています。
offensivecon @offensive_con
28K Followers 1 Following OffensiveCon is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #Offensivecon #Tokyo.
Yves Bieri @yves_bieri
457 Followers 383 Following Security enthusiast and pentester 👨💻 Pwn2Own 2023-26 👾 CTF with PPP 🖥
TrendAI Zero Day Init... @thezdi
89K Followers 18 Following TrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Simone Margaritelli @evilsocket
48K Followers 2K Following Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things. Chief Architect @ 🥷
`Ivan @Ivanlef0u
11K Followers 4K Following
Marcel @0ddc0de
247 Followers 300 Following PostDoc @HexhiveEPFL working on mobile security. CTF-Enthusiast @polygl0ts/@0rganizers. Former @shellphish and @fausecteam. Co-founder of @faustctf.
Burp Suite @Burp_Suite
139K Followers 14 Following Burp Suite is the leading software for web security testing.
watchTowr @watchtowrcyber
12K Followers 12 Following watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.
DC4131 - DEFCON CH @defconch
1K Followers 110 Following
WIRED @WIRED
10.0M Followers 379 Following For Future Reference. Sign up for our newsletters: https://t.co/Tl6GImvc8R
ᴅᴀɴɪᴇʟ ᴍɪ... @DanielMiessler
159K Followers 2K Following Building ⇪ Vector: The Business Operating System that helps companies articulate and pursue their ideal state. | https://t.co/D38E5CXwiA | Ex: Apple, Robinhood, HP
The Hacker News @TheHackersNews
2.0M Followers 2K Following The #1 trusted source for cybersecurity news, insights, and analysis — built for defenders and trusted by decision-makers.















