Joined August 2017
211 Photos and videos
Pinned Tweet
13 Apr 2024
19.4.13 - 24.4.13
1
12
16,523
Jun 8
CVE-2026-8054 DotCMS pre auth SQL Injection
2
12
181
14,806
ch retweeted
That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
112
366
2,566
211,932
ch retweeted
New post: We tested the Mythos showcase vulnerabilities with open models. They recovered similar scoped analysis! 8/8 models found the flagship FreeBSD zero-day, including a 3B model. Rankings reshuffle completely across tasks => the AI cybersecurity frontier is super jagged!
46
152
1,043
407,597
ch retweeted
New on the Anthropic Engineering Blog: How we use a multi-agent harness to push Claude further in frontend design and long-running autonomous software engineering. Read more: anthropic.com/engineering/ha…
314
919
6,695
1,788,121
ch retweeted
#CVE-2025-67303 ComfyUI-Manager Remote Code Execution 突然想起来我还有推特昨晚用我的Agent 10分钟分析的,之后的RCE就是CVE-2024-21574利用的复活
2
7
83
9,998
7 Sep 2025
“看看 etherscan都要收费”😂
万万没想到我们第一时间出手帮忙 Venus 大户 @KuanSun1990 跟进调查被盗事件,第一时间就给其指明了 Venus 风控必要性,风控后,然后我们协助他把被黑根本原因调查出来,他却在自己的群聊里全面诋毁我们“毫无作用,纯坑,看看 etherscan 都要收费,还有脸要赏金要致谢”。 现在的伦敦时间你 @KuanSun1990 可能还没醒,你醒了,来给个交代,否则我们会让大家知道什么是现实版的农夫与蛇,什么是两面三刀(你看看你和我私聊的嘴脸吧,你是如何诋毁其他帮你的角色的)。就你这样的人,以后谁还敢出手帮你。 本来我已经和你说了这次可以不要赏金,既然你如此踩我们(但这几天推文又都又在公开致谢我们…包括你历史上第一次被盗,你写的真的是声泪俱下,感动了很多人,包括我),这次的赏金我肯定要,你受益于我们,为什么我不能要赏金?我给谁做公益,也不可能给你这种人做公益。
5
4,122
ch retweeted
5 Aug 2025
gpt-oss is out! we made an open model that performs at the level of o4-mini and runs on a high-end laptop (WTF!!) (and a smaller one that runs on a phone). super proud of the team; big triumph of technology.
1,618
3,749
44,994
4,288,158
ch retweeted
17 Jul 2025
1/4 dbugs LIVE dbugs.ptsecurity.com — vulnerabilities’ home See trends, discover more, read AI summaries, have all references at hand, and your profile with all your CVEs and CVSS score on a leaderboard. ⬇️ See thread: what’s live what’s next ⬇️
3
43
126
49,408
ch retweeted
30 Jun 2025
After 9 months of cranking, cursing, and cursoring, and drawing on over 20 years experience running #HITB's Call for Papers, I bring you CFP Directory - a single system to make it easier for speakers to submit and organizers to connect and curate talks: cfp.directory/
6
36
71
19,757
ch retweeted
很好,这次我也是受害者了...被 @getAlby 偷走 0.00174788 BTC($191.96)。能偷是因为这是 Alby 的托管账号。我是很震惊的,因为这鬼协议我必然是不知情的... 我猜是不是会给我发邮件通知,果然 2025/5/1 给我发了个: Updates to our Terms of Service – Please Review 我在邮件正文底部发现了这个“偷窃协议”: An inactivity fee will apply to legacy Alby Accounts with a shared wallet created in 2023 or earlier, if there has been no account activity for 12 consecutive months. 然后我这笔 BTC 在 2025/5/26 被偷走了... 开眼界了...🤯😵‍💫😱
去中心化新定义:你的钱包不活跃,我就让钱离你而去了哦
165
47
336
320,967
4 May 2025
1
53
4,383
2 May 2025
SSRF Cache Poisoning Stored XSS = Account Takeover
13
12
338
18,491
ch retweeted
17 Mar 2025
#vulhub #CyberSecurity #opensource #infosec Announcing some exciting news from the Vulhub project! We've been busy making big improvements: 1⃣. Completely rebuilt our website from the ground up! Check it out: vulhub.org
1
7
37
9,229
14 Mar 2025
thanks @Bugcrowd P1 warrior hoodie
2
103
6,461
12 Mar 2025
Great collaborations with @haxor31337 find a cool account-takeover vulnerability
1
25
3,230
10 Mar 2025
1. find a JavaMelody Unauth Access in hxxp://xxx/monitoring 2. explore and find /monitoring?part=processes java -Dsendgrid=SG.xxxxxxx org.apache.catalina.startup.Bootstrap start 3. test sendgrid API key GET /v3/scopes Host: api.sendgrid.com Authorization: xx

52
4,266
3 Mar 2025
search to download Chrome
Which Edge feature do you find yourself using the most?
1
31
4,283
ch retweeted
21 Feb 2025
Bybit detected unauthorized activity involving one of our ETH cold wallets. The incident occurred when our ETH multisig cold wallet executed a transfer to our warm wallet. Unfortunately, this transaction was manipulated through a sophisticated attack that masked the signing interface, displaying the correct address while altering the underlying smart contract logic. As a result, the attacker was able to gain control of the affected ETH cold wallet and transfer its holdings to an unidentified address. Our security team, alongside leading blockchain forensic experts and partners, is actively investigating the incident. Any teams with expertise in blockchain analytics and fund recovery who can assist in tracing these assets are welcome to collaborate with us. We want to assure our users and partners that all other Bybit cold wallets remain fully secure. All client funds are safe, and our operations continue as usual without any disruption. Transparency and security remain our top priorities, and we will provide updates asap
2,778
2,258
11,491
4,436,522