Vulnerability Researcher

Joined October 2012
1 Photos and videos
Pinned Tweet
21 Oct 2022
After Foxit, It was fun pwning Adobe Reader! Learned quite a lot of things. New achievement unlocked.
I and @shsirk submitted our Adobe Acrobat Reader DC UaF RCE exploit to @thezdi. This was an interesting bug to exploit as we faced quite a few challenges. Stay tuned for the blog post describing how we successfully achieve RCE. youtube.com/watch?v=cguBkC0o…
1
12
Krishs retweeted
Enhanced Insecurity Mode: 23 RCEs in Edge's "Safe" WebAssembly Interpreter Microsoft's "safer" fallback when the WASM JIT is off? 23 paths to RCE in the interpreter itself. Slides now public — huge thanks to the OffensiveCon crew and everyone who came by. @offensive_con
2
25
176
13,354
Krishs retweeted
I’ve tried various agent pipelines, and here is one of them. It found five type-confusion bugs in V8 Wasm: three under non-default flags and two in DrumBrake/MS Edge. The repo includes all the bugs in detail, along with a README file that explains how the pipeline works, the prompts used, and many of the genomes it generated. Since the README is enough to let Claude vibe-code it, I won’t upload my messy and embarrassing code. Have fun :) github.com/qriousec/colony_a…
4
43
166
21,753
Krishs retweeted
My Windows reverse engineering and exploit research workflow has been: 1. Pick a binary to research like tcpip.sys 2. Use github.com/joshterrill/post-… to automate seeing existing binary versions, download, and generate diffs from them 3. Load the resulting .binexport's and .bindiff into an LLM and ask it to analyze 4. Look up the build number of previous Windows version that old binary existed in from uupdump.net/ such as 26100.8328 and create a VM from it 5. Write code and test, working backwards from LLM analysis
10
194
1,302
74,019
Krishs retweeted
As promised - full blog post is live for CVE-2026-40369 Covers everything: initial research, methodology, the exploitation path, caveats, cleanups, etc. The whole journey from finding it to production-grade exploit: pwn2nimron.com/blog

Replying to @M4x_1997
4/4: Last but not least CVE-2026-40369 - Windows Kernel Arbitrary Increment primitive reachable from any browser sandbox renderer process This one was rejected from Pwn2Own and closed anyway yesterday :( My exploit is here - blogpost will be soon: github.com/orinimron123/CVE-…
3
51
161
18,965
Krishs retweeted
Just dropped my full notes on Pwn2Own Berlin 2026. Broke down the big wins by DEVCORE, the actual techniques they used, why these matter in the real world, and exactly where you can practice the same skills yourself. Full article here #Pwn2Own #P2OBerlin #CyberSecurity
3
41
204
29,031
Krishs retweeted
🚀 Launching: Mr. Chartist Options Terminal ⭐ Star it → github.com/MrChartist/india-… India's best open-source F&O analytics platform. Built for traders who are tired of paying ₹2K/mo for option chain data. ✅ Live Option Chain Greeks ✅ Strategy Builder with payoff charts ✅ IV Rank Scanner ✅ FII/DII Activity tracker ✅ Position Tracker with P&L sim ✅ Dark Light mode 100% free. Open-source. Self-hosted. #OptionsTrading #NIFTY #BANKNIFTY #NSE #OpenSource #IndianStockMarket
29
75
323
41,127
Krishs retweeted
My BlackHat USA presentation's whitepaper and slide are now public. blackhat.com/us-23/briefings… #bhusa

4
30
156
24,390
Krishs retweeted
I have posted the slides for the talk @chompie1337 and I gave this past weekend at @h2hconference -> The Kernel Hacker’s Guide to the Galaxy: Automating Exploit Engineering Workflows #H2HC github.com/FuzzySecurity/H2H…
18
220
736
53,996
Krishs retweeted
26 Nov 2024
Disclosure of 7 Android and Google Pixel Vulnerabilities - PoC published : blog.oversecured.com/Disclos… PoC :
27
72
6,745
Krishs retweeted
✍️ Fuzzing for complex bugs across languages in JS Engines by @cffsmith powerofcommunity.net/poc2024…

8
27
2,155
Krishs retweeted
Releasing full 2 hr video of my browser exploitation workshop from VXCON 2024: youtube.com/live/b9OhamkAY2I In which I show what goes inside the mind of a skilled hacker while exploiting a highly non-trivial vulnerability in v8, from zero to exploit concept. Especially this workflow requires advanced abstract thinking, thereby emphasize the role of theoretical modeling in attacking hard zeroday research targets, which is a part of why it's fun. @zerodaytraining
8
242
702
40,977
Krishs retweeted
16 Nov 2024
🤔 (CVE-2024-7965 - exploited ITW)[356196918][compiler]Improper optimization of ZeroExtendsWord32ToWord64() leads to Memory Corruption is now open with PoC & RCA issues.chromium.org/issues/3…
12 Oct 2024
(CVE-2024-7965 - exploited ITW)[356196918][compiler] The PoC that works on x86_64/amd64 is now publicly available ./d8 --allow-natives-syntax regress-356196918.js chromium.googlesource.com/v8…
10
51
5,638
Krishs retweeted
Domato Lives! Today, we merged a WebGPU fuzzer written by @btiszka who used it to find several serious bugs in Chrome. Check it out at github.com/googleprojectzero…. Potentially also interesting for other browser vendors working on their own WebGPU implementation ;)

29
97
11,364
Krishs retweeted
13 Nov 2024
Dropped my slide for POC2024 on Linux kernel exploitation, including a journal from Pwn2Own Vancouver earlier this year. Enjoy 🙂. u1f383.github.io/slides/talk…

7
102
348
38,062
Analysis of VMware vCenter heap overflow vulnerability exploited at Matrix Cup competitions in China, June 2024 (CVE-2024-38812): blog.sonicwall.com/en-us/202… Another one in same code, 2023: blog.sonicwall.com/en-us/202… ** Both are RCE to management console, not a hypervisor VM escape!

22
87
9,628
Krishs retweeted
Our (@040xZx and myself) talk from Defcon about hacking the Xiaomi 13 Pro at Pwn2Own Toronto 2023 is up. Yay! media.defcon.org/DEF CON%2…

10 Oct 2024
The #defcon32 presentations are now live and availablle for your perusal on the #DEFCON media server, free of all commercials, data capture and pesky algorithms. We suggest clearing some disk space and personal time this weekend to snatch up some of the many, many jewels our speakers dropped in Las Vegas. While you’re on media.defcon.org you can also find the slide decks, a ton of pictures and even the DC32 soundtrack. Enjoy, learn a few things and #passiton. We’ll be posting the videos on YouTube Monday. #sharingiscaring
1
12
33
6,208