I like to break stuff | Web Vuln Research & CTF @ARESxCTF @aboutblankets

Joined February 2022
4 Photos and videos
sebsrt retweeted
We published a new research article on the Chromium 146 Renderer Process! In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE. Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research! Check out the PoC! Full article: research.rewritelab.org/2026…
1
35
165
11,261
sebsrt retweeted
Shellcode execution as a service! To exploit an argument injection in Jellyfin, we searched and found a gadget in the .NET runtime to turn file writes into code execution. Learn about the bug and this new technique: sonarsource.com/blog/jellyfi… #appsec #security #vulnerability

1
31
100
17,298
sebsrt retweeted
🐘 PHP JPEG bugs: how image parsing leads to memory corruption. Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed. swarm.ptsecurity.com/hack-th…
22
74
8,477
sebsrt retweeted
Big slay! maitai (@MaitaiThe) of Doyensec was able to exploit OpenAI Codex! If confirmed, they win $40,000 and 4 Master of Pwn points. They're off to the disclosure room for the deep dive. #Pwn2Own #P2OBerlin
2
10
51
5,011
sebsrt retweeted
NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at depthfirst.com/nginx-rift
23
295
1,082
205,453
Running a Figma plugin is enough to land cross-platform zero-click RCE on Figma Desktop... Read the writeup on the Critical Research Lab lab.ctbb.show/research/figma… And thanks @Dav3nn for the incredible post, what an amazing chain! =)
1
32
155
16,574
sebsrt retweeted
MAD Bugs: Finding and Exploiting a 21-Year-Old Vulnerability in PHP @i0n1c was "the PHP security guy" twenty years ago, so we thought it'd be fun to welcome him with a fresh unserialize UAF. open.substack.com/pub/calif/…
2
46
229
40,000
sebsrt retweeted
And this makes sense given how many CTFs are held per year. However, the ideal CTF challenge, in my opinion, should follow this formula: "The author conducted a mini-research project and instead of publishing it, turned it into a challenge."
3
15
128
14,383
Feb 18
See you in Japan!
🔥SECCON CTF 14 International Finalists🔥 Intrnational Final round: Feb 28-Mar 1, 2026 (JST). See image for finalists. We look forward to welcoming all the teams in person. See you in Japan!🇯🇵 #SECCON
1
17
782
sebsrt retweeted
Hello! We’ve just launched a new wargame site called damn vulnerable web! It consists only of web challenges, primarily designed for intermediate to advanced players rather than beginners. We hope this wargame helps more people gain deeper and broader knowledge in web hacking :) For now, we’re planning to accept only 300 users initially for open beta testing and capacity checks. Starting from this tweet, we’ll gradually increase the number of allowed sign-ups each week. Your interest and support will be a huge help to our future activities We’ll do our best to deliver even better work going forward. Thank you! Wargame site: wargame.rewritelab.org Join our Discord: discord.gg/wYAm2n4M4J
6
92
526
28,222
25 Oct 2025
TR.MRG HTTP Request Smuggling? author writeup for Trailing Danger - m0lecon 2026 teaser CTF 👉github.com/sebastianosrt/My-… I'll share more about trailer fields parsing vulnerabilities soon.
6
40
194
13,498
25 Aug 2025
I found that python hyper-h2 didn't correctly validate headers allowing http2 request splitting via crlf injection on http1 downgrades. So any proxy that uses it (like mitmproxy) might be vulnerable. github.com/python-hyper/h2/s…
2
5
44
3,392