Joined April 2020
3 Photos and videos
breno_css retweeted
Publiquei minha pesquisa sobre uma vulnerabilidade de RCE em visualizadores PDF Linux como Atril, Evince e Xreader, resultando na CVE-2026-46529. Abrindo o PDF, e clicando qualquer parte da pagina um comando arbitrário é executado no sistema O artigo: medeiros.zip/posts/CVE-2026-…
6
21
87
8,241
breno_css retweeted
Dialed in! Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) & Bruno Halltari (@BrunoModificato) of OtterSec used a Code Injection bug to exploit LM Studio in the second round, earning $20,000 and 4 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
2
14
57
10,720
breno_css retweeted
That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
112
366
2,565
212,115
breno_css retweeted
CVSS' Attack Complexity metric is the bane of bug bounty hunters: "you tried really hard to find that bug, so we'll pay you less".
18
16
316
26,634
breno_css retweeted
Mar 18
CVE-2025-6554: in-the-wild V8 the_hole based vulnerability analysis and exploit Bug analysis by @r3tr074: retr0.zip/blog/cve-2025-6554… PoC by @mistymntncop: github.com/mistymntncop/CVE-… #infosec
25
125
7,154
breno_css retweeted
TRAMOIA 0x2 tramoia.sh/trm2
8
40
161
8,641
breno_css retweeted
14 Nov 2025
A comunidade de Bug Bounty Brasileira está fazendo um evento GRATUITO e trazendo gringo para palestrar. Você de São Paulo ou q pode está nessa data em SP simplesmente VÁ nesse evento. #Bolhasec Maiores detalhes aqui neste tweet.
15 Oct 2025
🟥 Positive Hack Talks → São Paulo 🇧🇷 Dec 10th, 2025 🗣️ Speakers — submit papers (flights/hotel covered). CFP link in thread 👇 💻 Cybersecurity community — join our most community-driven event. ➡️ phtalks.ptsecurity.com/saopa… Free · 8 talks · limited spots #PHTalks
7
70
6,196
breno_css retweeted
🚀 Orgulho nacional! 🇧🇷 Parabenizamos todos os envolvidos por essa conquista histórica! Vocês levaram o nome do Brasil ao topo e mostraram que nossa comunidade de CTF está cada vez mais forte e preparada para desafios globais! 🔗 Assista o vídeo em youtube.com/watch?v=5Yt3HGNd…
2
7
41
1,442
breno_css retweeted
youtube.com/watch?v=5Yt3HGNd… Obrigado @mentebinaria ! Não foi dessa vez mas DEFCON que nos espere ano que vem! Até lá, como todos devem fazer sempre, estudaremos! Obrigado novamente ao @hackaflag por nos receber!
1
10
432
breno_css retweeted
Brazil made history last weekend, and of course, ELT was a part of it! Thanks @GaneshICMC , @boitatech , @gris_ufrj and #hawksec_unifei for partnership! We got 17th place, the best brazilian result, at #DEFCONCTF Quals as "pwn de queijo"! Thanks @hackaflag for hosting us!
8
35
4,733
breno_css retweeted
19 Dec 2024
Where there’s bug bounty, there’s #Bugcrowd. 😉✨ We’re honored to have supported the @BugBountyBr at H2HC in #Brazil, big thanks to @bsysop! Seeing the hacker community come together with such passion was nothing short of amazing (as always). 🥲 Huge thanks to the organizers, sponsors, and everyone who joined—you made it unforgettable! 🎉💚
11
32
5,779
breno_css retweeted
28 Nov 2024
NEW blog post: Netfilter Universal Root 1-day Our latest blog dives deep into the state of Linux kernel security and the open-source patch-gap, exploring how we monitored new bug fixes and achieved 0day-like capabilities by exploiting a 1-day vulnerability. Read more here →
28 Nov 2024
Earlier this year, I used a 1day to exploit the kernelCTF VRP LTS instance. I then used the same bug to write a universal exploit that worked against up-to-date mainstream distros for approximately 2 months. osec.io/blog/2024-11-25-netf…
1
8
48
5,328
breno_css retweeted
Seeing that Pwn2Win isn't happening this year, here's an unreleased beginner-level XSS challenge I created for it (shouldn't be too difficult). lbherrera.me/challenge

3
13
47
4,954
breno_css retweeted
30 Jul 2024
The results are in!🥇 Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup! 🙌 The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here. bit.ly/3SwGbkV
44
53
302
186,626
breno_css retweeted
Today at #Troopers24 we released Certiception – the ADCS honeypot we always wanted to have. Blog: srlabs.de/blog-post/certicep… Source code: github.com/srlabs/Certicepti… Slide deck, including our guide to deception strategy: github.com/srlabs/Certicepti…

2
158
398
32,797
breno_css retweeted
Decided to give my childhood game a try now that they relaunched Habbo's 2005 version back again, oops! (It was already reported and fixed).
9
13
202
47,226
breno_css retweeted
"Additionally we set Attack Complexity to High because the attack depends on the victim being authenticated in their default browser" - Shopify
6
2
46
7,393
breno_css retweeted
7 Jun 2024
casual CSS injection on github using the math mode
158
389
5,789
803,213