a Zauj to my lovely Zaujah, an Abah to my cute sons. Cybersecurity enthusiasts, but mainly a red teamer. I am straight. #OffSecAmbassador

Joined September 2011
159 Photos and videos

15
Ts. UnShadow retweeted
Malaysia's tech scene, finally in one place 🇲🇾 Communities, tools, grants, and government ~ all in one map 🗺️ Built by the @KrackedDevs team 👾 • Local Communities • Government Agencies • Tech Tools • Funding & Grants Beta out now! Check it out at wiki.krackeddevs.com/
11
37
218
23,424
Ts. UnShadow retweeted
Kepada yang dah tonton versi cetak rompak( gurau2 je ya @amanz 🤣)pendedahan awal animasi Nirnama, jemputlah tonton versi HD daripada pihak @thewaufactor sendiri. youtube.com/watch?v=BqEl-CGF… Akan ditayangkan pukul 2 petang nanti. Mohon doakan kelancaran urusan animasi Nirnama!
1
71
182
5,418
Ts. UnShadow retweeted
Sering dengar di Windows dan di Steam kalo main game perlu "DirectX". Teknologi ini jadi "jembatan" biar game bisa ngobrol lancar sama hardware. Jadi saya jelasin di video pendek ini :D Semoga Berguna.
18
93
762
16,453

1
43
Ts. UnShadow retweeted
May 30
Terima kasih, sebabkan content abang saya semangat nak jadi cikgu😊
5
146
1,349
105,534
it will be 7 jobs in 6 years….
48
Ts. UnShadow retweeted
Task failed successfully 😅 Hired to prevent relegation, ending the season with promotion. See you in 2026/27 @HullCity 👋
669
6,876
76,768
994,667
Ts. UnShadow retweeted
Stop burning RDP persistence with 4732 alerts. Bypass the "Remote Desktop Users" group entirely. GUI access only requires: - SeRemoteInteractiveLogonRight (Inject SID via secedit) - RDP-Tcp listener permissions (Modify CIM class) OPSEC: Trades 4732 for 4704. Most SOCs don't tune 4704 with the same aggression. h/t @Cptjesus for the concept.
5
110
544
37,114
Ts. UnShadow retweeted
Raul is one of the most knowledgeable experts on system design & software architecture on X. Highly recommend following him if you're looking to improve your knowledge.
Push-based systems come up in 90% of system design interviews. Here's the exercise you should be able to solve: Design a notification system for 100M users. Some have 50 followers. Some have 10M. The instinct is to hold a WebSocket connection open to every active user and push updates as they arrive. Clean mental model. It collapses the moment a celebrity posts. When someone with 10M followers posts, you push to 10M open connections simultaneously. Your message broker saturates. Your WebSocket servers fall over. The system fails at the exact moment it needs to work. That's the fan-out problem. And it kills more interview answers than any other mistake. The production answer: push and pull aren't binary. You pick based on follower count. Users with fewer than 1,000 followers get push fan-out. Each follower gets notified immediately. Users with millions of followers get pull fan-out. Their feed assembles on read. Nobody gets a push. Followers see the post when they open the app. Twitter built exactly this: push-on-write for small accounts, pull-on-read for large ones. But fan-out is only half the problem. Push means stateful connections. Your servers now need to know which connection lives on which machine. You can't route blindly. Most teams reach for Redis pub/sub here; the WebSocket server subscribes, the backend publishes, the message finds the right node. Add a 3-second network drop and you have another layer: what did the client miss? Now you need sequence IDs, a message buffer, and reconnect logic that replays missed events. "Push-based" became push with a pull fallback, a message broker, sticky routing, and a replay buffer. Most engineers stop at the first diagram. The ones who get the offer keep pulling the thread until the system breaks.
13
91
2,080
742,047
Ts. UnShadow retweeted
Replying to @kasturixbm5
1
7
35
893
Ts. UnShadow retweeted
"Wake up babe" Someone just accessed GitHub’s internal repositories
May 19
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
21
146
2,226
133,583
Ts. UnShadow retweeted
We’re heading to Malaysia in August! 🇲🇾
226
2,193
7,038
558,206
Ts. UnShadow retweeted
マリオのBGMを完璧に再現した2人の男性が凄すぎる
27
932
7,849
370,015

44
Ts. UnShadow retweeted
This is how I cook spaghetti aglio olio. Simple, quick, cheap and delicious. Give it a try, you probably won’t want to eat Maggi anymore at the middle of the night 😄
13
287
1,409
81,755
Ts. UnShadow retweeted
CVE-2026-44578  ⚠️ Next.js – WebSocket Upgrade SSRF (CVSS 8.6)  A server-side request forgery vulnerability in Next.js allows unauthenticated attackers to force self-hosted instances to make internal HTTP requests via the WebSocket upgrade handler.  By sending a crafted absolute-form HTTP request with Upgrade: websocket headers, attackers can access internal services, cloud metadata endpoints, admin panels, and internal APIs reachable from the Next.js server on port 80. Successful exploitation may expose cloud credentials, API keys, secrets, and configuration data.  Affected: Next.js 13.4.13 , 14.x, 15.x <15.5.16, 16.0.0–16.2.4  Mitigation: Upgrade immediately to 15.5.16 or 16.2.5.   Modat Magnify Query:  technology="Next.js"  The platform:  magnify.modat.io/  #threatintel #vulnerability #CVE202644578 #Nextjs #SSRF #WebSocket #CloudSecurity #infosec #Critical #ModatMagnify
74
416
2,386
1,492,190
Ts. UnShadow retweeted
‼️🚨 MAJOR IMPACT: AI just found an 18-year-old NGINX critical remote code execution vulnerability. It has been disclosed on GitHub including PoC code. - Affects NGINX 0.6.27 through 1.30.0 - Triggered via the rewrite and set directives in config - Update NGINX ASAP - NGINX is a widely used HTTP web server, be sure to check its prevalence in other products
Community note
The exploit requires ASLR to be disabled, which is not default on practically all systems. This is seen in the exploit code. Source github.com/depthfirstdisc…
83
393
2,598
949,850
Ts. UnShadow retweeted
May 13
another day, another universal linux LPE
May 9
0e78b6737119a3141e466464ee2748eb84a61750958d0cb5824febbdadd875be poc.c
40
344
2,548
536,000
Ts. UnShadow retweeted
May 12
Google Cloud AI engineer just showed how they go from idea to deployed app at Google in 30-minutes using Claude. 26-minutes. free. by Google AI team. one person Claude Google Cloud = a full engineering org running on a laptop. worth more than any $500 vibe-coding course.
May 12
Anthropic's Claude team just showed how to build an AI agent with real memory in under 30 minutes. 24-minutes. free. by the people who built Claude. one person 10 agents with memory = a team that runs 24/7, remembers every customer improves itself. worth than $500 vibe-coding course.
143
1,455
11,467
1,753,359