Joined June 2022
1 Photos and videos
78ResearchLab retweeted
Microsoft's June 2026 Patch Tuesday set a record: ~200 CVEs, the biggest list ever. We diffed ~130 of the patched binaries. Even at 200 CVEs, the advisories don't describe everything that changed. Here's what the diffs show that the CVE text doesn't ๐Ÿงต
1
4
6
265
78ResearchLab retweeted
The slickest catch: one feature flag rerouted Kerberos PAC decoding to a new path across THREE binaries - LSASS, Credential Guard (LsaIso), the Kerberos client lib. Kerberos & LSASS did get CVEs this month. The advisories just don't show this cross-binary shape.
1
2
3
122
78ResearchLab retweeted
The lesson: a record ~200 CVEs still isn't the whole picture. The binary diffs carry hardening the advisories never spell out. We read them so you don't have to. ๐Ÿฆ… PatchHawk #PatchTuesday #infosec
2
3
105
78ResearchLab retweeted
These are mainline -rc fixes: Cc: stable, no CVE yet by design. CVEs land later, on backport. We read the merge graph so you see them now, not after the feed catches up. ๐Ÿฆ… PatchHawk #LinuxKernel #infosec
1
2
2
92
78ResearchLab retweeted
Linux mainline quietly shipped a fix for a remote kernel heap overflow in the iSCSI target. It fires during login, before the CHAP password is ever checked. No CVE. The commit just says "validate CHAP_R length before base64 decode." Only watch CVE feeds? You missed it. ๐Ÿงต
1
4
3
223
78ResearchLab retweeted
7-Zip 26.01's changelog lists exactly ONE security fix. We diffed the source, 26.00 -> 26.01. It silently shipped 14 MORE. "Some bugs were fixed" was doing a lot of heavy lifting. ๐Ÿงต
1
5
10
2,659
78ResearchLab retweeted
Takeaway: treat 26.01 as a security release, not a point fix. Upgrade from 26.00 even if you think the NTFS CVE doesn't touch you, because 14 more code paths got safer and the changelog won't say so. ๐Ÿฆ… PatchHawk #7zip #infosec
1
3
4
326
78ResearchLab is excited to announce its membership in the NVIDIA Inception program!
3
6
251
78ResearchLab retweeted
๐Ÿฆ… Silent Patch Watch Vendors often ship real security fixes as "minor bug fixes" โ€” no CVE, no advisory. Every Thursday we diff a release and show the one that actually mattered, so you can update before attackers notice. Follow ๐Ÿ”– for the first issue this week.
3
3
176
Does anyone remember the 'CVE-2026-21509' in January 2026? To learn more about the patching mechanism for CVE-2026-21509, please follow the link below. blog.78researchlab.com/34cdbโ€ฆ Thank you.
4
15
1,024
78ResearchLab retweeted
Collision! @gbdngb12, @pwnstar96, @jeongZero, @sangs00Jeong, and @nonetype_pwn of 78ResearchLab hit a oneโ€‘vulnerability collision against the Alpine iLXโ€‘F511, earning $5,000 USD and 1 Master of Pwn point. #Pwn2Own #P2OAuto
8
24
2,696
78ResearchLab retweeted
As if competing in #Pwn2Own isnโ€™t pressure enough, imagine being on stage in front of your professor as well! The team from 78ResearchLab is doing just that as the successfully target the Phoenix Contact CHARX. Well done! #P2OAuto
8
51
4,338
78ResearchLab retweeted
Another Collision! @gbdngb12, @pwnstar96, @jeongZero, @sangs00Jeong, @nonetype_pwn of 78ResearchLab targeted the Phoenix Contact CHARX SECโ€‘3150, chaining four bugs (two unique and two collisions) to earn $15,000 USD and 3 Master of Pwn points.
7
25
3,371
78ResearchLab retweeted
๐Ÿšจ New talk #ParallelPulse2025: @78_lab breaks down Gunra, a Conti-variant that hit major SK banks. Learn how @78_lab reverse-engineered the malware, found a critical vuln & replicated decryption via a known-plaintext attack. ๐Ÿ‘‰ pulse.nanosec.asia/speakers-โ€ฆ
3
8
521
78ResearchLab retweeted
#ParallelPulse @nanosec_asia 2025 kicks off with our Technical Training series! Welcome back to KL @krNeoTra & Sangsoo Jeong of @78_lab ! The stage is set. ๐Ÿฆธโ€โ™‚๏ธ ๐–ถ๐–พโ€™๐—‹๐–พ ๐—‹๐–พ๐–บ๐–ฝ๐—’! ๐—๐—๐–พ ๐—‹๐–พ๐–บ๐—… ๐—Š๐—Ž๐–พ๐—Œ๐—๐—‚๐—ˆ๐—‡ ๐—‚๐—Œ: ๐– ๐–ฑ๐–ค U?! ๐Ÿ”œ pulse.nanosec.asia/agenda/
5
7
460
78ResearchLab retweeted
โœจ Welcome & TQ #ParallelPulse @ NanoSec.Asia 2025 trainers - Nasi Kandar Style! @krNeoTra Sangsoo Jeong @78_lab , Harry Koh, Rozaili Idris, Kaz Goto @MagnetForensics, Luqman, @dinobitoo & @ammar_aryani Eclogic. Let the learning, hacking, hunting & building begin!
2
9
416
78ResearchLab retweeted
#ParallelPulse wrapped up ๐€๐๐ฏ๐š๐ง๐œ๐ž๐ ๐“๐ก๐ซ๐ž๐š๐ญ ๐‡๐ฎ๐ง๐ญ๐ข๐ง๐  & ๐ˆ๐‘ training with an amazing cohort! Huge ๐Ÿซถ to everyone who dug into the labs & pushed through the challenges. ๐Ÿ™to @krNeoTra & Sangsoo @78_lab for your amazing sharing. Onward we go, stronger & sharper!
2
10
526
78ResearchLab retweeted
๐Ÿ’ฅ What. A. Finish. Sangsoo Jeong from @78_lab wrapped Day 1 with explosive insights in Down to 256 flipping ransomware errors into defender advantage like a pro. Energy = MAXED OUT. #ParallelPulse 2025
3
6
352