Penetration Tester at Positive Technologies, likes to share what I learn with others | @ptswarm

Joined September 2015
25 Photos and videos
Arseniy Sharoglazov retweeted
👨🏻‍💻 Did you know that it’s possible to perform RCE in Internet Explorer via clickjacking? Igor Sak-Sakovsky's (@Psych0tr1a) new article will explain how! swarm.ptsecurity.com/the-cli…
16
28
2,371
Arseniy Sharoglazov retweeted
🧑‍🚒 Our researcher Mikhail Sukhov shares his knowledge and experience in analyzing FreeIPA environments. He also introduces his new tool, IPAHound 💪 Go ’n see the details ➡️ swarm.ptsecurity.com/thinkin…
1
44
144
8,978
Arseniy Sharoglazov retweeted
🔥 Read the new article by our researcher Timofey Duditsky. The write-up dives into the AMD Platform Configuration Blobs mechanism, shows how it works, and reveals the vulnerability CVE-2025-54502. swarm.ptsecurity.com/slowbur…
12
30
3,621
Arseniy Sharoglazov retweeted
Two bugs. One chain. Full RCE. New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise. Read the full writeup! swarm.ptsecurity.com/busines…
1
80
345
25,123
Arseniy Sharoglazov retweeted
🐘 Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service. Our researcher Aleksey Solovev discovered the vulnerability CVE-2025-12818, which may cause a product using the libpq PostgreSQL library to crash. swarm.ptsecurity.com/attack-…
11
28
3,881
Arseniy Sharoglazov retweeted
🚨 Our researcher Alexander Zhurnakov identified two vulnerabilities in Dell Wyse Management Suite prior to version 5.5. In certain configurations, they can be chained to achieve unauthenticated remote code execution. Upgrade now → dell.com/support/kbdoc/en-us…
1
32
93
9,935
Arseniy Sharoglazov retweeted
📞 Microsoft fixed an authenticated RCE in Windows Telephony Service (CVE-2026-20931), discovered by our researcher Sergey Bliznyuk @justbronzebee Read the write-up: swarm.ptsecurity.com/whos-on…
4
113
389
34,401
Arseniy Sharoglazov retweeted
29 Dec 2025
📑 A new article from our researchers Aleksey Solovev, Nikita Sveshnikov and Vladimir Razov — "Blind trust: what is hidden behind the process of creating your PDF file?". swarm.ptsecurity.com/blind-t…
28
104
11,865
Arseniy Sharoglazov retweeted
14 Nov 2025
📱 New article by our researcher @Fi5t: Injection for an athlete. Read about a vulnerability discovered in the Garmin Connect mobile application: swarm.ptsecurity.com/injecti…
11
24
3,355
Arseniy Sharoglazov retweeted
20 Oct 2025
🌎 Positive Hack Talks lands in Brazil 🇧🇷! 📍 São Paulo 🗓️ Dec 10, 2025 REMINDER: PHT is a fun and free cybersec event, see last pics: phtalks.ptsecurity.com/saopa… ⬆️ Register to attend or speak. Vamos!
4
10
2,926
Arseniy Sharoglazov retweeted
2 Sep 2025
New article by @a13xp0p0v: "Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel." Alexander used his pet project kernel-hack-drill to exploit a hard race condition that received the Pwnie Award 2025. swarm.ptsecurity.com/kernel-…
1
22
43
6,855
Arseniy Sharoglazov retweeted
24 Jul 2025
🚨 We've launched dbugs.ptsecurity.com, a new home for vulnerabilities. More than CVEs. More than MITRE. ✅ Trends & Insights ✅ AI-generated, multi-source vulnerability descriptions ✅ Researcher credits ✅ [drop your own tip in the comments] Follow the project: @ptdbugs
10
27
5,391
Arseniy Sharoglazov retweeted
22 Jul 2025
👑 Our researcher has discovered LPE in VMWare Tools (CVE-2025-22230 & CVE-2025-22247) via VGAuth! Write-up by the one who broke it: Sergey Bliznyuk (@justbronzebee) swarm.ptsecurity.com/the-gue…
1
42
110
9,991
Arseniy Sharoglazov retweeted
17 Jul 2025
😈 Read the new article "Daemon Ex Plist: LPE via MacOS Daemons" by our researcher Egor Filatov. This research reveals a vulnerability affecting popular apps like Mozilla VPN, Tunnelblick & more. swarm.ptsecurity.com/daemon-…
31
61
7,885
Arseniy Sharoglazov retweeted
9 Jul 2025
🧠 Our researcher Sergey Tarasov discovered a vulnerability (CVE-2025-49689) in NTFS on MS Windows. The article dives into the exploitation path, file system internals, VHD format, and more. 🔗 Read the article: swarm.ptsecurity.com/buried-…
20
56
4,447
Arseniy Sharoglazov retweeted
27 Jun 2025
🦊 Mozilla Foundation fixed CVE-2025-6430, discovered by our researcher Daniil Satyaev! This vulnerability allows the Content-Disposition: attachment header to be ignored if the page is opened using <embed> or <object>, resulting in files being displayed instead of downloaded.
3
43
239
21,445
Arseniy Sharoglazov retweeted
26 Jun 2025
⚡️ FreeIPA fixed critical CVE-2025-4404, discovered by our researcher Mikhail Sukhov! This vulnerability allows an authenticated attacker to escalate privileges from host to domain admin. 🔗 Advisory: freeipa.org/release-notes/4-…
31
79
7,185
Arseniy Sharoglazov retweeted
23 Jun 2025
📢 Positive Hack Talks is heading to Indonesia 🇮🇩! 📍 Jakarta 🗓 July 23, 2025 Join us for a free in-person hacker event — everyone’s welcome! CFP & attendee registration now open ⬇️ phtalks.ptsecurity.com/jakar… phtalks.ptsecurity.com/jakar…
7
19
3,048
Arseniy Sharoglazov retweeted
17 Jun 2025
🔥 Microsoft fixed CVE-2025-47955, discovered by our researcher Sergey Bliznyuk! This vulnerability allows a locally authenticated attacker to elevate privileges to SYSTEM via the Windows RasMan service. 🔗 Advisory: msrc.microsoft.com/update-gu…
47
146
13,352
Arseniy Sharoglazov retweeted
3 Jun 2025
⚠️ We’ve reproduced CVE-2025-49113 in Roundcube. This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization. If you're running Roundcube — update immediately!
7
113
511
49,946