Joined October 2021
18 Photos and videos
regne retweeted
[1/3] It's common to get a ParcelFileDescriptor pointing to a directory through an Android ContentProvider. But can you actually turn that into a directory listing?
1
2
26
2,748
regne retweeted
"Dad, what was it like playing CTFs before AI?"
22
245
1,534
120,417
May 22
They grow up so fast, happy eighteen nginx RCE 🥹
⚡ An 18-year-old flaw in NGINX can let unauthenticated attackers run code or crash servers using crafted HTTP requests. Tracked as CVE-2026-42945 and named NGINX Rift, the bug affects NGINX Plus and Open Source. Patch details and mitigation steps: thehackernews.com/2026/05/18…
1
173
May 22
Hacking with AI is quite boring and I confess that I missed some fun of hacking recently, but building things with AI is incredible fun I feel that I have never learned so much about Software Engineering/Architecture before, even without writing a single line of code
1
44
regne retweeted
this is me in a few days ago
3
15
165
9,654
May 16
btw, some of these vulnerabilities stemmed from specific research into React Native apps. Uncovered some interesting techniques to escalate impact by abusing common mistakes in hybrid app implementations. Full technical writeup once the disclosure window closes.
May 16
Officially a Security Contributor of @ProtonPrivacy, very happy to help secure the ecosystem that I use every day. proton.me/blog/protonmail-se…
73
May 16
Officially a Security Contributor of @ProtonPrivacy, very happy to help secure the ecosystem that I use every day. proton.me/blog/protonmail-se…
1
137
regne retweeted
everyone, i need your help, anyone can hook us up with the "ESXi version 9.1.0.0"? your RT is really appreciated, this is Urgent AF.

ALT Scream Cat GIF

3
19
43
12,950
regne retweeted
Because we train LLMs on lots of movies and books about AI uprising, or articles and tweets about dystopian fears of AI, we might be causing the threat ourselves 🤔
8
10
204
33,036
regne retweeted
Our second blog post is out here: bugscale.ch/blog/here-we-go-… ! We managed to install arbitrary APKs on the Samsung Galaxy S25 from an app without install permissions. For this, @SachaKozma did most of the work, but it was great looking into Samsung's cloud gaming component with him
1
28
98
13,819
Apr 29
do it :)
OH GOD THEYRE GOING TO VIBE CODE A MOBILE OS SAM DONT DO IT
71
Apr 22
RT @8kSec: 🌍 Earth Day Giveaway - Learn Mobile or AI Security, On Us One beautiful planet we all share. Let's patch it together. 🌱 To cel…
69
regne retweeted
I am talking about mobile... AI can speed up / help with BB (reports, PoCs).... but for finding real vulns, it’s mostly low-hanging fruit so far. So...don’t abandon a target just because Claude says so :)
2
1
48
2,371
regne retweeted
There are no words.
7,773
85,742
646,601
39,025,979
Apr 3
Me: Reported 1 Click ATO Triager: User interaction? P4
43
regne retweeted
This... this is art. Submitting a PR to the Claude Code repo to add the actual Claude Code source code.
93
231
4,937
356,845
regne retweeted
Mar 31
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
541
4,024
16,163
12,405,329
regne retweeted
If you missed the talk at @1ns0mn1h4ck , our latest blog post is now available for you to explore. In this post, researchers @Hacker_Chai and @SachaKozma detail their journey to a 1-click RCE exploit on the Samsung S25 phone. Check it out here: bugscale.ch/blog/shoot-for-t…
1
33
100
10,462
regne retweeted
Interested in exploiting browsers? Join me as I go over the free section of @ret2wargames "Fundamentals of Browser Exploitation" course. This is a course delivered by real #Pwn2Own winners! So, you're learning from the best! This first video is very beginner friendly so check it out even if you're just curios🧐. Video link below: youtu.be/5ArMYqwCmD4
1
38
214
12,695
regne retweeted
Mar 14
For anyone dealing with RASP protected apps, frida-strace is now your first step. Trace the syscalls, find what the app checks, hook those specific functions, bypass. No more guessing. Frida 17.8.0 , kernel 6.1 required. #Frida #MobileSecurity #AppSec
Mar 14
Frida 17.8.0 dropped with frida-strace syscall tracing on Android & iOS, no jailbreak. Thank you @fridadotre #Frida #MobileSecurity #AppSec
4
70
413
44,727