Made it to MSRC 2025 Q3 Leaderboard ranking #9 in MSRC Office Scoreboard with #28 ranking overall. Thanks @msftsecresponse
My reports. CVE-2025-59243, CVE-2025-59226, CVE-2025-50165
Zscaler ThreatLabz has discovered CVE-2025-50165 in the Microsoft Windows Graphics Component. With a CVSS score of 9.8, this vulnerability enables attackers to execute arbitrary code using a specially crafted JPEG image that can be triggered by any application that leverages the Windows Graphics library such as Microsoft Office documents. It is critical that Windows users update applications and install the patched versions in a timely manner.
Read the full analysis here: zscaler.com/blogs/security-r…
Four bounties remain unclaimed. We are extending these three for one more week — the first team to open a ticket with the flag wins:
- 6◆ pwn/WIC: $200 for the🩸First Solve
- 6◆ crypto/unfairy-ring : $200 for the🩸First Solve
- 5◆ crypto/unfairy-ring: $100 for the🩸First Solve
19 hours left! We have released the second wave, and bounties are added for unsolved challenges.
I created a pwn challenge 'WIC' and it is still unsolved. Claim 200$ bounty for solving the challenge.
play ctf.sekai.team#SekaiCTF
🎉Happy New Year! Here's our 2024 Wrapped:
- Ranked 10th on CTFtime, won 8 CTFs out of 23 played individually
- Top finishes in multiple onsite finals (2nd in SAS CTF with @r3kapig, 2nd in ISITDTU CTF Finals, 5th in SCAN CTF, 1st in HIT CON Finals with @malta_ctf etc.)
(1/3)
First time I've glitched u-boot by grounding out the flash chip during boot!
Ending up getting a root shell on a TP-Link security camera 😄
youtu.be/F-G-7-qo7Xg#iot#hacking
Today we collab with @ProjectSEKAIctf as P1G SEKAI(project sekai:4,r3kapig:3) and play into #TheSAS2024 CTF then we finally got 2nd place.The second place has exceeded our expectations. All the staff deserve praise for their work.Finally thx for @TheSAScon org nice organization!
I wrote an explained writeup for a windows kernel ctf challenge that came in Sekai Ctf 2024 . The author of the challenge is @bienpnn .
This is a nice challenge for those who want to try windows kernel. I also learnt something new.
Thanks @bienpnn .
nu1lptr0.github.io/2024/10/1…
Registration for SekaiCTF 2024 is now open: ctf.sekai.team
Our prize pool features USD$3,000 in cash and prizes worth over $10,000! Join our Discord to keep up-to-date: discord.gg/6gk7jhCgGX
Huge shoutout to our sponsors. Thank you for your generous support:
- OtterSec (@osec_io)
- Trail of Bits (@trailofbits)
- Hack The Box (@hackthebox_eu)
- Sec3 (@sec3dev)
- Binary Ninja (@vector35)
- Offensive Security (@offsectraining)
- Google Cloud (@googlecloud)
P.S. We’ve also hacked #defcon to promote SekaiCTF for us...
Our team is looking for a web player for Codegate 2024 Finals. CTF happens Aug 29-30 and accomodation is covered for 2 nights from 28-30. Flight is not reimbursed.
If anyone is interested, feel free to shoot a message.
I made some Pwn challenges write ups from WolvCTF some days ago. Thanks to @WolvSec for the challenges. Exploits looks simple and CScript challenge was very interesting!!
4n0nym4u5.github.io/4n0nym4u…