Security researcher @MicrosoftEdge

Joined August 2008
321 Photos and videos
Abdulrahman Alqabandi retweeted
Multiple, serious security vulnerabilities found in the Rust clone of Sudo — which shipped with Ubuntu 25.10 (the most recent release). Not little vulnerabilities: We’re talking about the disclosure of passwords and total bypassing of authentication. In fact, we’re getting new reports of showstopper grade issues every few days on the Rust-based clones (like sudo, du, date, and others) which were forced to ship in Ubuntu before they were fully tested. Which is, of course, *exactly* what was predicted. But, never fear! At least these Rust clones are memory safe! PHEW!
212
408
3,209
554,488
Abdulrahman Alqabandi retweeted
Buckle up folks, evidence of the acceleration of capabilities of hackers with agents is becoming a weekly event.
Our fuzzer generated entirely by Vibing just found it first ( confirmed! ) 0day in Firefox. CVE and details soon!
6
32
320
44,203
Abdulrahman Alqabandi retweeted
6 Nov 2025
I bypassed user approvals and achieved RCE in VS Code Copilot by flipping 4 bits. Find out how: jro.sg/CVEs/copilot/ Thanks to @msftsecresponse for rapidly triaging and patching this vulnerability.
11
93
897
67,369
Abdulrahman Alqabandi retweeted
Meta is replacing WhatsApp's full-fledged native Windows 11 app with a Chromium-based web wrapper that loads WhatsApp web in a container. This is likely due to recent layoffs. Meta won't directly admit that it's killing off the original WhatsApp app for Windows 11, but a new alert within the app warns everyone will be logged out starting November 5. The warning says a few new features like Communities will be added, and an advanced Status page will be introduced. WhatsApp Web supports Communities and an advanced Status page, while UWP/WinUI native WhatsApp for Windows 11 does not support these features. WhatsApp for Windows 11 was one of the best native apps, and Meta had invested a lot in migrating the original web wrapper to native code. Now, it's going back to Chromium.
104
114
1,705
162,070
Abdulrahman Alqabandi retweeted
The sandbox escape vulnerability described by Kaspersky here is quite interesting. Especially in that the technical root cause of the issue bit both Chromium and FireFox developers. Other Windows apps along with OS components might well have similar vulnerabilities.
The Hacking Team is back/Operation ForumTroll Phishing link → WebGPU decrypt → Shellcode injection → COM hijack for persistence. Deploys Dante spyware (successor to RCS(Hacking Team), now Memento Labs) custom LeetAgent for keylogging, file theft. Exploits: Zero-days CVE-2025-2783 (Chrome sandbox escape) & Phishing link → WebGPU decrypt → Shellcode injection → COM hijack for persistence. securelist.com/forumtroll-ap…
4
39
194
48,724
Abdulrahman Alqabandi retweeted
LLMs are injective and invertible. In our new paper, we show that different prompts always map to different embeddings, and this property can be used to recover input tokens from individual embeddings in latent space. (1/6)
279
1,298
11,058
5,119,800
Abdulrahman Alqabandi retweeted
Your AI browser is here, whether you use a Mac or PC. Live now: microsoft.com/edge/copilot-m…
It’s time to question your browser.​ Meet Copilot Mode in Edge. Turning your browser into a dynamic and intelligent companion with the latest AI innovations. Available on Windows and Mac. ​ Try now: msft.it/6010shbaY
27
28
286
41,796
Abdulrahman Alqabandi retweeted
23
41
415
250,302
Abdulrahman Alqabandi retweeted
16 Oct 2025
Arguably the most brilliant engineer in FFmpeg left because of this. He reverse engineered dozens of codecs by hand as a volunteer. Then security "researchers" and corporate employees came along repeatedly insisted "critical" security issues were fixed immediately waving their CVEs. This was hugely demotivating to the fun and enjoyment of reverse engineering.
15 Oct 2025
Replying to @FFmpeg
The maintainer of libxml2 put it very well
154
692
8,822
843,328
Abdulrahman Alqabandi retweeted
🎉 New Course Alert Giveaway! 🎉 I'm excited to announce a brand-new course on Rana Khalil's Academy - OAuth 2.0 Vulnerabilities. This course includes: 📚 A technical deep dive into OAuth 2.0 and OpenID Connect: what they are, how they work, the common pitfalls in implementation, the vulnerabilities that can arise, and best practices to keep your applications secure. 🧪 6 hands-on labs 📃 Subtitles in 6 languages for all the videos in this course 👉 Course Link: academy.ranakhalil.com/p/oau… 🎁 To celebrate the launch, I’m giving away 5 FREE 30-day All-Access Memberships to the Academy. To enter the giveaway: 1️⃣ Follow @RanaKhalilAcad. 2️⃣ Comment on and retweet this tweet. Winners will be announced on the 13th of September. Good luck! 🧡
216
240
686
63,040
Abdulrahman Alqabandi retweeted
14 Aug 2025
Securing @gumroad with Hacktron AI Three months ago, Hacktron was still early. @HacktronAI and @rootxharsh were finding 0-days targeting specific vulnerabilities on OSS software. Then we ran a full pentest-style scan on a big open-source project. The results were insane. 🧵
5
19
205
30,502
Abdulrahman Alqabandi retweeted
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com/
19
241
749
86,366
Abdulrahman Alqabandi retweeted
30 Jul 2025
حياكم الله في فعالية اكسبو للالعاب الالكترونية في الافنيوز .. من تاريخ 2025-8-1 لغاية 2025-8-3 شاركت بلعبة ثعلوب للاطفال . ( ستكون في الفتره الصباحيه من 10ص لغاية 12م ) يوم السبت والاحد وايضا شاركت بلعبة المفتاح المفقود . ( في الفتره المسائية من الساعه 8م ) طوال ايام الفعاليه. @kw_nccal @OoredooKuwait
13
19
56
3,984
Abdulrahman Alqabandi retweeted
24 Jun 2025
XBOW automatically runs expert-level attacks across all webapps, giving security teams unprecedented scale. @XBOW reported 1092 vulnerabilities on HackerOne in just a few months, including RCE, XXE, SQLi, SSRF, exposed secrets, and XSS.
6
13
107
110,180
Abdulrahman Alqabandi retweeted
15 Apr 2025
Blind CSS exfiltration attacks recently got a lot easier! Full details in this thread:
15 Apr 2025
I think many people are familiar with the topic of blind CSS exfiltration, especially after the post by @garethheyes However, an important update has occurred since then, which I wrote below ->
3
35
209
15,970
Abdulrahman Alqabandi retweeted
8 Apr 2025
واخيرا تم الانتهاء من تطوير لعبة ثعلوب للاطفال .. كانت رحلة مليئة بالتحدي والتعليم , والان اكتملت الرحلة وهذه هي اللعبة بين ايديكم على متاجر اجهزة الجوال . اللعبة مجانية بالكامل ولا تحتوي على اي اعلان , فهي امنة جدا للاطفال . اتمنى دعمكم بالنشر , هذا الشي يجعلني استطيع ان استمر في التطوير والبرمجة . روابط التحميل قوقل بلاي play.google.com/store/apps/d… ابل ستور apps.apple.com/us/app/thaloo… #تطوير_الالعاب #الالعاب_العربية

الان وبعد طول انتظار 🦊 تم اطلاق لعبة ثعلوب للاطفال لعبة مصممة خصيصًا للأطفال من عمر 4 إلى 7 سنوات لتعليم الأرقام والحروف العربية وبعض الكلمات المهمة من خلال انشطة شيقة ومراحل مليئة بالتحديات الممتعة. للتحميل Apple apps.apple.com/us/app/thaloo… Google Play play.google.com/store/apps/d…
21
92
245
81,204
Abdulrahman Alqabandi retweeted
"This blog post aims to provide a detailed blueprint for how Google has created and deployed a high-assurance web framework that almost completely eliminates exploitable web vulnerabilities." bughunters.google.com/blog/6…
1
17
38
7,644
Abdulrahman Alqabandi retweeted
23 Jan 2025
Edge Security may have an exciting opportunity to work in our Barcelona #VulnerabilityResearch team. DM for details.
1
9
20
3,923