check @FahemSec

Joined January 2016
207 Photos and videos
اصلح نفسك شوية تجميعات لبودكاست وسلاسل لتتعلم منها دينك. facebook.com/FlEx0Geek/posts…
5
45
5,521
راي: متسالش ال ai في الدين وانت مش متعلم عشان هيسوحك وانت مش واخد بالك. (متنبهرش بـ الشكل اللي بيعمله)
3
235
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
Jun 11
أحد المقاطع التي ستحاول إسرائيل حذفها من الإنترنت وبفضل منصات مثل X لن تنجح في ذلك عندما ارتكبت إسرائيل أشد الجرائم وحشيةً على الإطلاق، حين قامت بتجويع شعب بأكمله "أكثر من 2 مليون إنسان" ودفعهم لخوض معركة قاتلة لأجل الحصول على رغيف خبز .. حيث قُتل الآلاف جوعاً لن ننسى أبداً
562
14,177
24,544
451,930
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
Jun 12
حاولت اسرائيل خداع العالم وإظهار أن الطبيب حسام أبو صفية بصحة جيدة عبر حلاقة وتصفيف شعره ولكن ولسوء حظهم تم كشف الحقيقة أثار التعذيب الوحشي والضرب واضحة بشدة على جسده فضح هذا الإرهاب واجب على كل حر حول العالم
626
19,171
33,110
676,925
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
Got my first full VM escape
5
33
568
31,354
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
Fresh off winning Master of Pwn at #P2OBerlin 2026, we're launching OPSR: Offensive Product Security Research. We hunt high-risk attack surfaces, validate real exploit paths, and quantify business impact with a hacker's mindset. Learn more: devco.re/en/services/opsr/
3
10
126
8,719
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
Jun 6
Israel did this.
11
184
605
15,679
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
1/ My first MSRC experience, documented. I reported a 1-click account takeover in Microsoft Bing for Android steal a signed-in user's OAuth tokens and leak all private files. They closed it "Not a Vulnerability" twice, and silently shipped the fix twice.
2
2
7
1,639
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
بريطانيا : تم تبرئة محمد فاهر أماز من تهمة الاعتداء المزعوم على ضباط شرطة في مطار مانشستر فشلت هيئتا محلفين في الوصول إلى حكم، ولن تجرى محاكمة إضافية وكان أماز قد دافع عن والدته التي تعرضت لإساءة من الشرطة في المطار ، وقد نشرنا قصته سابقا
78
927
5,423
489,265
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
New research disclosed فريق Dexpose و Darkatlas قدرنا نعمل identity reveal ل Quellostanco عضو في Int3x اللي كان بيتارجت الجامعات والحكومات المصرية We successfully conducted a full identity reveal on Quellostanco, an active member of the Int3x group, who was systematically targeting Egyptian universities and government entities. dexpose.io/unmasking-quellos…
3
13
60
5,430
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
رحمه الله وغفر له وجعل عمله في ميزان حسناته. الأخ أمين حارس مسجد في سان دييجو، اسْتَشْهَدَ في إطلاق نار بينه وبين مسلحين عشان يمنعهم يأذوا حد في المسجد أو يوصلوا للأطفال في جريمة من جرائم الكره والتطرف، أخونا أمين رحمه الله بطل. قبل الاستشهاد بكام يوم نزل البوست دا، لعله كان صادقاً فيما تمنى، سبحان الله. إِنَّ اللَّهَ اشْتَرَىٰ مِنَ الْمُؤْمِنِينَ أَنفُسَهُمْ وَأَمْوَالَهُم بِأَنَّ لَهُمُ الْجَنَّةَ ۚ يُقَاتِلُونَ فِي سَبِيلِ اللَّهِ فَيَقْتُلُونَ وَيُقْتَلُونَ ۖ
Amin Abdullah was the guard at the mosque in San Diego for years. He was key in stopping the shooters from reaching the children today. This was his final post on Facebook.
1
47
278
9,967
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
May 18
No quotes No spaces No Parentheses No Semicolons Still SQLi.... Collab with @or4nge16hehe medium.com/@r9.mody/sql-inje… #bugbounty
May 14
SQL Injection without these special chars [' "()\/%*&\`] possible? Yep, me and @or4nge16hehe did it. Using only: [ a-z, 0-9, dot, @ - ] Write-up soon #BugBounty #infosec
14
73
356
42,485
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
[2]After our failed competition, we headed to Apple Store and bought the mbp m5 and spent less than half an hour to set it up and found a fixed offset is changed 1 bit on it, so we just change 1 bit on our exp and it worked with a 100% success rate. Yes just 1 bit change, 1 to 2.
Unfortunately, Tao Yan & Edouard Bochin of Palo Alto Networks could not get their exploit of Apple Safari – Renderer Only working within the time allotted. #Pwn2Own #P2OBerlin
14
38
569
103,548
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
And this one is human insight w/ LLM-assisted research. Took about one week to finish everything. The AI really rescued me from a lot of tedious work — excluding the part where it changed the Domain Admin password, locked me out, and claimed it got RCE 🤦
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
45
153
1,651
121,981
مش طبيعي
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
2
25
3,647
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
"ممنوع تدخل الجنة"! ردا على المشككين في إسلام #بتول_علوش والمهتدين عموماً. لاحظنا ان الكلمة الماضية "دعم وتأييد لبتول علوش" أثارت غير وقهر الشبيحة، فالحمد لله على ذلك. موتوا بغيظكم.
54
230
1,404
38,334
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
😓 Pwn2Own 2026
7
27
351
19,007
الفكرة دي (لها مراحل اصعب سيكا) لكن خدت مني تقريبا ٧ شهور بدور فيها بالتجربة (علي فترات طبعا مش كل يوم يعني): fahemsec.com/blog/oneshot-we…
40
2,410
Mohamed Sayed - مُحَمَّد 🇵🇸 retweeted
War criminals
❗️🚨 BREAKING: Microsoft has fired the top leadership of its Israeli subsidiary following an internal investigation into Azure use by Israel's Ministry of Defense. Country General Manager Alon Haimovich is out, along with several managers from the governance department. The probe found Israeli defense units were using Azure servers in Europe in ways that violated Microsoft's terms and exposed the company to EU legal risk. Microsoft Israel's management withheld this from headquarters. Microsoft had already cut ties with IDF Unit 8200 in September 2025. The investigation found that was only part of the problem. Microsoft Israel now reports to Microsoft France. The Ministry of Defense contract renewal is due by the end of 2026.
5
3
65
6,833

‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3 weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150 researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
5
37
3,279