Full-time Nerd 🥸 | Mobile Security Enthusiast 📱🕵🏻‍♂️👾

Joined February 2010
67 Photos and videos
Excited to be attending @reconmtl in Montreal 🇨🇦 this week— the world’s largest known reverse engineering conference! Looking forward to the training and a fantastic lineup of talks and events. If you’re attending as well, let’s meetup and connect! #reCON
2
69
Rolf retweeted
Jun 13
Recon badge has arrived!!! Thanks to electronic cats electroniccats.com/
1
9
48
2,340
Rolf retweeted
Epic OPSEC fail by NSO Group. @whatsapp recently caught the notorious spyware company hacking across their platform. (NSO is forbidden from doing this by a US court!) In their testing, NSO was sending a test image of a soup cup...on a desktop mat with the NSO Group logo. Making it worse, the image was user-reported to WhatsApp. Cleanest attribution I've seen in a long time.
30
159
1,384
135,981
Rolf retweeted
I have added another 250,000 malwares to the malware collection. Please download the malware here: vx-underground.org Thank you.
43
73
1,575
44,706
Rolf retweeted
🎂 IDA Turns 35. From DOS-era disassembler to one of the most widely used reverse engineering platforms in the world... To celebrate, we’re launching: • 35% off new licenses (see eligibility requirements) • Limited-edition swag giveaway • “35 Ways to Use IDA” as told by you • Stories from the past and a few for the future Read all about it here: hex-rays.com/blog/ida-turns-…
7
37
224
24,636
Rolf retweeted
We're finally ready to talk about Flipper One — a project we've been grinding on for years and have rebuilt from scratch several times. Read blog post >> blog.flipper.net/flipper-one…
113
547
4,007
566,542
Rolf retweeted
We obtained root privilege on the S26 (Exynos 2600 Chipset), the latest flagship smartphone from Samsung. To our knowledge, this is the first root exploit for Exynos S26 since Samsung removed bootloader unlocking option in One UI 8. It is exploitable from APP context, so we make a cmd wrapper app for demo👇(1/n)
15
65
335
32,120
Rolf retweeted
With the low barrier to entry for vulnerability research due to AI, that used to require advanced and niche skills, I'm seeing that exploit mitigation bypasses are still difficult for AI. Weaponizing vulnerabilities still requires advanced knowledge. Disclosure != Skill...
8
14
138
14,690
Rolf retweeted
Opening up LightSaber iOS 18.0-18.3 beta testing to anyone who wants to help out. Meet BrokenBlade. Automatically collects logs (anon, open src) to help debug. Have already made some progress with private testers, now opening up bc more logs the merrier. zeroxjf.github.io/BrokenBlad…
2
5
40
5,047
Rolf retweeted
May the fourth be with you

ALT May The Fourth Be With You GIF

2,938
51,281
219,920
7,164,976
Rolf retweeted
In case you were curious, copy.fail doesn't generally affect @Android devices, as Pixel devices (with GKI kernels) don't have CONFIG_CRYPTO_USER_API_AEAD compiled in, and it'd be unusual for OEMs to include that interface to apps / usermode. Citations via @claudeai
Patch your Linux boxes! Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. Found by the teams at @theori_io and @xint_official More details below xint.io/blog/copy-fail-linux…
5
12
70
11,307
Rolf retweeted
Hello JEB friends, why haven’t you published themes you use in JEB, not cool 😆! Maybe you are using the default themes, but worry not, I have published 22 themes for your viewing pleasure: github.com/FuzzySecurity/JEB…
2
6
41
4,701
Rolf retweeted
Back in the 90s and early 2000s, Tamagotchis had crazy lore. Most were completely false (but some were true!) These rumors ranged from saying that they were aliens escaping a drunk planet to being able to unlock Bill Clinton on a Tamagotchi. This rumor is actually...completely true! If you followed very specific steps (including initial neglect and then suddenly perfect care) on the standard English Generation 1 (P1) Tamagotchi, your pet would eventually evolve into Bill Clinton and live a very long time. The most popular rumor when I was growing up was that repeatedly feeding your pet would eventually make them explode. Of course, I tried my hardest to prove this right, but no, this one turned out to be completely false.
38
70
1,351
82,558
Rolf retweeted
Reminder: Don't solely use AI for your research. Especially if you do big mistakes by not verifying .... I really like the "disable AES key fuse read-lock" idea .... looking forward to how this would work in reality ... cypherbyte.io/blog/mediatek-…
3
24
2,298
Rolf retweeted
[3/4] To counter this, we're open-sourcing Malfixer, presented today at @Botconf 2026. Built over 2 years, it detects and surgically repairs all three malformation categories, rebuilding clean APKs ready for standard pipelines, without altering the payload.
1
5
8
587
Rolf retweeted
My Qualcomm drivers research is still in its beginning/not published yet. But I posted my setup in case anyone is interested: pwner.gg/blog/2026-04-03-and…
1
32
155
11,258
Rolf retweeted
⚠️ cifrat - a new mobile remote acess trojan found‼️ The malware spreads by impersonating Booking and then... A vast technical analysis prepared by CERT Polska available here: 🔗 cert.pl/en/posts/2026/04/cif…
1
8
20
2,499