android kernel 0-days/exploits @ @vigilant_labs / ctfs @cor_ctf and @eltctfbr / prev @osec_io

Joined August 2020
13 Photos and videos
Pinned Tweet
25 Nov 2022
1
8
70
May 28
1
22
532
0xTen retweeted
"Dad, what was it like playing CTFs before AI?"
22
245
1,533
120,477
May 24
defcon? what is that? i am at dubrovnik
defcon? what is that? i am at cambridge
1
31
2,552
0xTen retweeted
We had a blast this weekend at @offensive_con 🔥- thank you to @Binary_Gecko for the awesome conference! Congrats to our teammates @caueobici for his pwn2own success and @ryaagard for his talk on a 1-click Minecraft 0day😎
4
65
2,678
0xTen retweeted
Security researchers become trapped into an identity that they can’t escape, life seems purposeless, reality shifts and they realize they can’t bend like a tree in the wind. It turns out that intelligence isn’t the key to happiness. For those that know. Chop wood, carry water.
May 7
0days doesn't seem cool enough anymore. what should real hackers be doing now?
7
26
293
24,677
May 5
👀
The Unprompted.au CFP is officially OPEN! If you are doing cool stuff with AI in offense, defense, or working on core AI tech (from frontier models to open source LLMs), we'd love to hear from you! Submit here: unprompted.au/
5
835
May 1
Lmfao
Apr 30
RIP to the Chrome VRP
1
1
37
4,152
0xTen retweeted
There's few people that are more OG than @mdowd.
Replying to @ryanaraine
Full show (with timestamps) youtu.be/NEDlOKHG8nY?si=Ajcv…
1
11
58
9,833
0xTen retweeted
this year's pwn2own isn't just interesting because there will be lots of entries with AI human. it is also interesting because a) anthropic burned a ton of tokens on firefox, basically running claude in a loop until it found something for a month, probably exhausting whatever claude can one shot. b) if someone submits full chain without much use of ai, it tells you one shotting plateaus and these models are bit like fuzzers than seasoned security reseachers. c) even if they used an llm to find the bug, this tells us scaffolding/harnesss design, prompting, and the operator matters a lot.
10
34
330
62,629
Mar 20
bet p2o collisions this year will be wild
3
4
68
4,597
0xTen retweeted
The way I look at it is: 1. Short term: as a VR expert you can understand model capabilities better than the labs themselves with a 'reasonable' spend. That's fun. 2. Medium term: you *will* have an edge vs teams spending huge amounts. You just need to find it. That's also fun.
1
11
34
9,425
0xTen retweeted
2,110
16,308
89,728
3,715,732
0xTen retweeted
12 Nov 2025
Our research team achieved client RCE on Minecraft Bedrock Edition via a heap overflow to bypass ASLR and sidestep CFG. Writeup to come.
60
271
2,979
225,114
0xTen retweeted
at a conference where you don’t have to present

86
859
15,354
676,193
0xTen retweeted
We at CoR ( @u1f383) had a great experience at @hexacon_fr this weekend Met many skilled VR people, the venue was amazing, and the speaker gifts were simply🔥 Best offensive security conference we have seen so far - thanks again to the organizers for the opportunity!
1
54
9,452
0xTen retweeted
17 Sep 2025
📢 An RbTree Family Drama: Exploiting a Linux Kernel 0-day Through Red-Black Tree Transformations by William Liu & Savino Dicanosa
3
40
6,773
0xTen retweeted
Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130) willsroot.io/2025/09/ksmbd-0… Cheers to @u1f383 for finding these CVEs the OffensiveCon talk from gteissier & @laomaiweng for inspiration!
11
199
753
81,692
0xTen retweeted
7 Jun 2024
Hey, for anyone who wanted to see this slide deck, it was a keynote about the 0day market, but it commented on public research vs saleable products. I have put it here: github.com/mdowd79/presentat… // cc @chompie1337 @bsdaemon
6 Jun 2024
Replying to @chompie1337
Yeah. I touched on this in a talk I gave at blue hat last year. It isn't publicly available though
10
128
403
102,057
0xTen retweeted
9 Aug 2025
Our CVE-2024-50264 with @_qwerty_po has won the Best Privilege Escalation category at the 2025 Pwnie Awards. Thank you, @PwnieAwards!!
8
12
133
16,184