Im just a normal guy.

Joined February 2024
8 Photos and videos
Khadafi Gans retweeted
Jun 3
They literally just removed the "Get Support" button from the Front-end so normal users can't see it. #meta #instagram #ai
9
16
377
33,248
Khadafi Gans retweeted
1
1
52
We will see the era of Whitehats turn into Blackhat or Grayhat because of Microslop
1
22
Khadafi Gans retweeted
responsible disclosure takes advantage of researchers more than they pay them out
2
24
192
4,341
Khadafi Gans retweeted
lol 🀣
5
27
243
8,071
Here is what they're trying to get from the Campaign. Regex B64 decode -> PRIVATE KEY-----|(?:AWS_SECRET_ACCESS_KEY|GITHUB_TOKEN|GITLAB_TOKEN|SLACK_TOKEN|DATABASE_URL|PRIVATE_KEY|SECRET_KEY|API_KEY|AUTH_TOKEN
🚨 The "π™ΌπšŽπšπšŠπš•πš˜πšπš˜πš—" Campaign is live... 𝟻,𝟽𝟷𝟾 malicious commits to 𝟻,𝟻𝟼𝟷 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected π™Άπš’πšπ™·πšžπš‹ π™°πšŒπšπš’πš˜πš—πšœ workflows containing πš‹πšŠπšœπšŽπŸΌπŸΊ-πšŽπš—πšŒπš˜πšπšŽπš bash payloads that exfiltrate: - CI secrets, - cloud credentials - SSH keys - OIDC tokens - source code secrets Check your repo / Technical details: safedep.io/megalodon-mass-gi…
2
101
Khadafi Gans retweeted
May 13
another day, another universal linux LPE
May 9
0e78b6737119a3141e466464ee2748eb84a61750958d0cb5824febbdadd875be poc.c
40
344
2,549
536,008
Khadafi Gans retweeted
Meet β€œDirty Frag” a new universal Linux LPE chaining flaws in xfrm-ESP and RxRPC. Fully deterministic, no race conditions, no kernel panic on failure. Silent for nearly 9 years. Ubuntu, RHEL, Fedora, openSUSE, CentOS, AlmaLinux and more impacted. github.com/V4bel/dirtyfrag
5
17
2,288
Khadafi Gans retweeted
HackerOne just got a company breached. ClickUp's April 27th data leak? Directly caused by HackerOne's triage failure. They closed a critical report (893 exposed emails a live API token) as a "duplicate" twice. Their AI or analysts auto-close valid findings as "informative" while real vulnerabilities fester. This wasn't a one-off. HackerOne did it to ClickUp at least three times. If you run a bug bounty on HackerOne, your security is in the hands of broken triage. Don't wait for a public shaming to find out they buried your next breach. Ditch HackerOne. clickup.com/blog/april-27th-…
25
34
371
64,320
Khadafi Gans retweeted
>Hacking is illegal and for nerds >"Uhm, actually, hacking isn't illegal. Hac....." SILENCE NORMIE
24
39
955
20,783
28
323
8,055
256,505
Khadafi Gans retweeted
‼️ Advanced Magento 2.x exploitation tool for unauthenticated RCE via polyglot file upload through REST API. Tests 45 PHP extensions with multi-header support (PNG/GIF) for maximum exploitation coverage. GitHub: github.com/khadafigans/Magen…
1
13
42
7,959
I just uploaded Magento Polyshell RCE on my github you can actually grab it now and its completely free and open source. github.com/khadafigans/Magen… #Exploit #RCE
6
1,256
Khadafi Gans retweeted
A man went to adopt a cat, but it refused to be separated from its companion, so he ended up taking them both home.

90
510
5,847
180,087
Khadafi Gans retweeted
March 20th: 15 TONS of gummy candy stolen from semi-trailer in Germany March 29th: 12 TONS of KitKat bars stolen from Truck leaving Italy en-route to Poland Who are you people?
135
208
3,350
73,957
Khadafi Gans retweeted
Biggest cyber attack of 2026
41
751
10,790
122,815
I got my first Triaged on @intigriti :)
1
8
439