Infosec

Joined September 2020
172 Photos and videos
Pinned Tweet
30 Jan 2023
Just popped on @msftsecresponse Q4 Security Researcher Leaderboard!
13 Jan 2023
🥳🥳🥳
3
26
9,891
1
22
136
3,707
May 28
blog post about a nice trick I found to escalate a postgres SQLi to RCE this week the filewrite primitive was widely documented but I've not seen the .so one online yet so we though it might be interesting to publish it, if anyone already knew about it, i'm interested to know :)
🔓 On an asset under our continuous monitoring, our pentester @nol_tech turned a SELECT-only PostgreSQL SQLi in Drupal (CVE-2026-9082) into a full RCE when DB role is superuser. Details below 👇 📝 blog.lexfo.fr/drupal-postgre… 🛠️ github.com/ambionics/cve-202… #Drupal #PostgreSQL #RCE #SQLi
1
2
22
3,232
May 28
seems like i'm actually two years late lol x.com/m1ke_n1/status/2060040…

Replying to @ambionics @nol_tech
Did I understand correctly that you used the same technique described in the Phrack article to escalate the SQLi to RCE? Link: phrack.org/issues/71/8
1
1
277
May 28
MSRC finally gets the PR shitshow they should have had a long time ago Btw; they still haven't patched the .NET command injection I reported years ago, even tough I provided a full POC demonstrating the impact
‼️ After the MSRC blog post about Nightmare-Eclipse, researchers are coming forward with their own MSRC horror stories. The response from the security community isn't going Microsoft's way. As they’re not backing Microsoft. Gabriel Landau, a well-known Windows security researcher, says he reported a Device Guard bypass with a 90-day window. MSRC told him it met their bar and they'd fix it, then asked him to hold disclosure for extra months. He agreed on the condition they issue a CVE. They patched it silently, decided after the fact it "didn't meet the bar," and never issued the CVE. In his words: "MSRC strung me along for a few extra months to keep me quiet, then broke their word." Another researcher, rootsecdev, says he responsibly disclosed a legacy-auth flaw that allowed password spraying while avoiding smart lockout. Five months later, MSRC replied that it "doesn't meet the bar for servicing," silently fixed it, and closed the case. Microsoft's post was meant to defend their coordinated disclosure policy. Instead it became a thread of researchers explaining why they've stopped trusting their process.
2
27
157
7,010
May 27
This is my talk :D
🇬🇧 EN WSO2 products run banking, insurance and government infra worldwide. Ambionics Security researchers found 12 critical 0-days and chained 7 N-days into a single unauthenticated request for RCE. Live demo included. Friday 16:15 #leHACK billetweb.fr/lehack-2026-bra…
3
15
953
nol retweeted
You may have noticed I've been a bit quiet on social media recently, this is why...I'm going to present at @BlackHatEvents #BHUSA
14
25
183
32,213
nol retweeted
you thought that was a uniform address space you were accessing?
1
5
85
2,992
nol retweeted
May 15
today we are releasing a qemu escape
May 14
0e11c4aa285dffe95d2d7e90d974ad0e72336549b0dd2161dec606ba4955e2e1 qemu.c
25
270
1,785
326,163
nol retweeted
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
29
183
1,548
268,897
nol retweeted
That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
112
366
2,568
211,701
nol retweeted
We used to go to a special website, ask strangers for help with programming, and get humiliated in return
305
3,461
39,290
880,381
nol retweeted
4 Aug 2025
guy who cant tell the difference between mp4 and exe
161
754
24,187
1,366,468
May 10
i saw a mouse with an X-shaped battery compartment. first thought: this is stupid - who designed it? 5 seconds later: oh. 10 seconds later: OHHH! the X slot fits an AA or an AAA battery - whichever you've got lying around. the part most people miss is that the shape also makes it physically impossible to load both at once. there is no warning label, no instructions and no way to screw it up. the geometry does the thinking for you. japanese has a word for this. poka-yoke = "mistake-proofing." the product refuses your stupidity before you can offer it. i wish more things worked like this.
67
nol retweeted
New Anthropic research: Natural Language Autoencoders. Models like Claude talk in words but think in numbers. The numbers—called activations—encode Claude’s thoughts, but not in a language we can read. Here, we train Claude to translate its activations into human-readable text.
593
1,704
16,550
2,488,556
nol retweeted
You either die a frontend library or you live long enough to become a full-stack framework with server-side vulnerabilities
Multiple security vulnerabilities affecting React Server Components and Next.js have been disclosed. We strongly recommend updating your applications immediately. Cloudflare WAF managed rules already mitigate the disclosed denial-of-service vulnerabilities, and we are investigating additional coverage for several other CVEs. developers.cloudflare.com/ch…
11
61
1,201
122,201
nol retweeted
Great now OpenAI is going to run out of compute trying to fix their code base
Fortinet is part of @OpenAI’s Trusted Access for Cyber program, helping explore how frontier #AI models can be safely and effectively applied to cybersecurity workflows. As cyber threats become more sophisticated, #Fortinet continues to integrate AI into security testing and analysis in a governed, structured manner. OpenAI’s newly released model represents an advancement in cyber reasoning, supporting agentic workflows that can help strengthen defensive capabilities while maintaining rigorous human oversight. Read more: ftnt.net/6013BBYn9F
7
7
77
6,967
nol retweeted
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
175
269
1,876
292,457
It's live! (Contains @hawkinsw patch for this new `_Generic` feature.) Kick the tires on it, let us know how it goes! godbolt.org/z/71f3xxcYh
2
1
25
2,137