Just another web warrior ⚔️ Security Researcher ۞ Principal Security Engineer @Verichains ۞ Pwn2Own 2023 ۞@vnsec squad ۞ 💰hackerone.com/ducnt_ ۞ nano 💻

Joined February 2017
63 Photos and videos
Pinned Tweet
So, here is another gift for you about Imagemagick RCE 0-day that afftceted to GhostScript-9.50 😀 github.com/duc-nt/RCE-0-day-… #RCE #imagemagick #ghostscript
14
312
788
Nguyen The Duc retweeted
gnosis pay exploit root cause: a taint of revert data gnosisscan.io/tx/0x5ea42911c…
5
11
156
13,881
Nguyen The Duc retweeted
Jun 1
We reported a critical loss of funds bug to @Thorchain (32M TVL, 150M FDV) They silently patched it and told us their bug bounty program is permanently retired. We have more Thorchain chain halt DoS vulns. We intend to release them (open disclosure) in the coming few days
97
128
1,330
397,146
Nguyen The Duc retweeted
Así es como se ve un lanzamiento de cohete desde 400 km sobre la Tierra a bordo de la ISS. @StarSnap_1 #MateriaOscura
13
129
953
49,234
Nguyen The Duc retweeted
Engineering is magic
981
7,260
79,385
3,327,211
Nguyen The Duc retweeted
security research now has this weird incentive where finding the bug is only half the game. the other half is packaging the story as "claude/codex found it" because that’s where all the attention is right now. model providers, with their big accounts and distribution, will push the story for you. it looks win-win. weirdly, the human taste, target selection, hand holding, all get compressed into "the model found it". frontier model companies happily push that narrative, while the researcher slowly gets devalued.
6
10
150
32,614
Nguyen The Duc retweeted
May 14
Never stop selling
436
1,075
22,683
1,279,775
Nguyen The Duc retweeted
That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
112
366
2,568
211,649
Nguyen The Duc retweeted
NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at depthfirst.com/nginx-rift
23
295
1,084
205,211
Nguyen The Duc retweeted
Proud of the team. They went after a corner of the Linux kernel that nobody had bothered to look at, found a bug that had been sitting there for 14 years, and quietly got on with it. No fuss. Just good work. If any vendors looking for extra pair of eyes, let me know.
We're likely 1st to publicly exploit crypto: af_alg as a new attack surface in kernelCTF. Our members @n0psledbyte & @st424204 started poking it in Sep 2025, finding a 0-day container escape unnoticed since 2011. @AnthropicAI @OpenAI: interested in collaborations? We are all ears
14
111
13,627
Nguyen The Duc retweeted
PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak. github.com/striga-ai/CVE-202… github.com/striga-ai/CVE-202…
4
184
739
93,630
Nguyen The Duc retweeted
Microsoft $MSFT developers watching Claude integrate better than Copilot in their own software
Claude for Excel, PowerPoint, and Word are now generally available, and Claude for Outlook is in public beta. As Claude moves between your Microsoft apps, it carries the full context of your conversation.
109
1,163
19,027
1,294,068
Nguyen The Duc retweeted
Patch your Linux boxes! Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms. Found by the teams at @theori_io and @xint_official More details below xint.io/blog/copy-fail-linux…
24
363
982
250,185
Nguyen The Duc retweeted
🚨: A civilization 2,000 light-years away pointing a powerful enough telescope at Earth right now would see the Roman Empire. They'd see Jesus alive.
1,126
2,048
29,037
2,957,754
Nguyen The Duc retweeted
Apr 28
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push The flaw in @github allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
97
990
4,451
553,837
Nguyen The Duc retweeted
Centralization exposed inside Tron USDT 🚨 Here’s what is happening: Tether just executed the largest freeze in its history. More than $344,000,000 in USDT (TRC-20) blocked on Tron. By Tether itself. - Coordinated with OFAC and US law enforcement - Executed directly through the USDT smart contract - Funds are now visible but completely unusable This is how it works: - Tether has admin control over USDT contracts - Can blacklist any address - Can freeze balances instantly - Can permanently destroy funds Functions used: - addBlackList(address) - removeBlackList(address) - destroyBlackFunds(address) Now here’s where it gets interesting Timeline April 20 - Arbitrum freezes ~$71M linked to hackers April 21 - Justin Sun tweets: “the most decentralized blockchain in the world is Tron” April 23 - Tether freezes $344M on Tron No response from Justin Sun so far The irony writes itself Stay safe.
304
239
1,398
167,662
Nguyen The Duc retweeted
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing
1,986
6,647
44,013
31,422,158
Nguyen The Duc retweeted
NASA Artemis passing close to the Moon

21,498
115,769
1,288,473
139,688,097
Nguyen The Duc retweeted
CTF in 2026
27
208
1,929
110,116
Nguyen The Duc retweeted

657
690
3,677
6,540,920