Director, Red Team / Offensive Security. Help organizations safeguard their businesses from the bad guys.

Joined December 2014
1,241 Photos and videos
Pinned Tweet
In case you missed it: Add a colon to your password, ":", because all the stealer logs have colons, so it'll end up splitting your password incorrectly.
2
20
4,398
Imagine trying to patch guardrails…
I’ve had a number of conversations with folks inside and outside government about the current situation with Anthropic, and here is what I believe to be true: — As we know, Anthropic publicly released its Mythos class models earlier this week under the commercial name Fable. — Fable is Mythos with guardrails. But if those guardrails fail, then you’ve exposed Mythos and its advanced cyber capabilities to people who shouldn’t have them. (Keep in mind that Anthropic itself widely promoted the idea that Mythos was a cyberweapon and needed to be regulated as such. They asked for government regulation of Mythos and championed the guardrails on Fable. If there is a vulnerability — big or small — it is Anthropic’s responsibility to patch.) — A highly credible trusted partner of both Anthropic and the USG who was testing Fable came forward with a jailbreak of those guardrails. The Admin asked Dario to fix the jailbreak or de-deploy the model. Dario refused. — In their blog post, Anthropic defended its decision by saying the jailbreak isn’t serious. That is not what the trusted partner and the USG believe; nor is that kind of minimizing language consistent with Anthropic’s brand as the AI safety company. It’s difficult to fathom how they could claim a jailbreak allowing operability of a cyber weapon could be defined as not “serious.” — In the past, Anthropic has always said that safety must be top priority and taken super seriously. In this case, Anthropic prioritized the continued offering of the consumer model over safety. — In reaction, the Admin issued the export control. The Admin did this reluctantly. It’s been very surprised that Anthropic hasn’t wanted to cooperate with a reasonable safety request (ie fixing the jailbreak issue). Anthropic’s reaction is very much at odds with their branding and ethos as a safe AI research community. — The Admin’s hope now is that Anthropic remediates the safety issue, the export control is lifted, and Fable goes back into general release. The Admin wants all of this to happen as soon as possible. It is frankly bewildered that Anthropic hasn’t wanted to comply with safety requests that it previously said were its highest priority. — Those trying to misdirect and tie this action to the prior DoW/Anthropic issues are wrong. The Admin values Anthropic’s technical capabilities and feels that this issue, while serious, should be easily resolved. The ball is in Anthropic’s court.
520
Vincent Yiu retweeted
🧙‍ We built Grimoire: a single search box for every offensive playbook, fully offline. Type ssrf, kerberoast, jwt, sudo and instantly hit the right page across more than 100 curated sources at once. 🔍⚡
5
48
313
14,265
Vincent Yiu retweeted
🌘 Kimi-K2.7-Code, our latest coding model, is now released and open-sourced! 🔷 Improved coding & agent performance over K2.6: 21.8% on Kimi Code Bench v2, 11.0% on Program Bench, and 31.5% on MLS Bench Lite. 🔷 Reasoning efficiency: Less overthinking, with 30% lower reasoning-token usage compared to K2.6. 🔷 Long-horizon coding: Improved instruction following, higher end-to-end coding task success rates. ⚡️ 6x High-Speed Mode coming soon! 🔌 Available today via Kimi API and Kimi Code. 🔗 Kimi Code: kimi.com/code 🔗 API: platform.moonshot.ai
607
1,604
13,503
1,910,364
Vincent Yiu retweeted
Jun 11
🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-25089 PT ID: PT-2026-47809 Vendor: Fortinet Product: FortiSandbox Description: A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests Link: github.com/HORKimhab/CVE-202… #dbugs_vuln
18
61
4,919
Basically someone got fucked by corporate and now mentally distressed?
Jun 10
It looks like Nightmare Eclipse has been through serious pain. If you read his last comment in the source, you can clearly see the frustration and mental exhaustion. He’s a good guy who got hurt very badly. It’s the natural result of fighting alone against retards that doesn’t give a damn about researchers. #support
6
1,188
Vincent Yiu retweeted
MSSQL has always been a favorite target. Now it ships its own egress channel. @gershsec's latest research breaks down how SQL Server 2025's native AI features enable exfil, NTLM coercion, and C2 transport, all functioning as intended. Read more 👇 ghst.ly/4e2L3JX
65
223
16,393
Vincent Yiu retweeted
I published my POC for CVE-2026-0466. This is a kernel write primitive in AmdPowerProfiler.sys. You can write 0x1 or 0x400003 to an arbitrary address. This was a part of some of my BYOVD research last fall. github.com/Bad-Jubies/Exploi…
2
53
206
15,105
Vincent Yiu retweeted
While Mythos showed what frontier model might become, we asked a different question: With a dedicated security harness, can open-source LLMs approach Mythos-level vulnerability research on real targets? Meet deepsec, DARKNAVY's attempt to answer. darknavy.org/blog/deepsec_ch…
1
24
113
10,778
Vincent Yiu retweeted
We're dropping 3 Adminer 0-days after nearly three months without acknowledgment from the maintainers. Among these vulnerabilities and our previous cPanel 0-day, we've earned a five-digit bounty total, Happy hunting ;) blog.voorivex.team/three-0-d…
5
45
197
11,297
Not sure what all the fuss was about with CET? I never considered cetcompat to be a dealbreaker as most operators ideally bring in their own sideloads which are non-cet, unless you plan to inject microsoft processes. Spent last 2 days to test a theory and built a shellcode POC to find atleast 3 different techniques to build a fully unwindable cetcompat stack frame. As much as this was easy, integrating it into brute ratel is gonna be fun.. Looks like next release might be slightly delayed...
1
7
94
6,666
Bruh did Apple just reframe being late to the AI game as others “pursuing AI without clear regard for the people”?
2
310
Vincent Yiu retweeted
this still applies in the age of ai
31 Oct 2024
Replying to @NahamSec
Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job. What niche? How to pick? Examples? infosec being so vast from web3 sec to web2, mobile, desktop, recon, client-side, server-side, cryptography and so on. These are umbrella terms, but if we zoom in, there are specific areas where spending a lot of focused time will make you a top 20 expert -- 100% sure. The key thing is, that the current top 20 experts in any niche will eventually be replaced as they get bored or burned out. This leaves room for you, and the easiest way to pick a niche is to learn from an existing expert in the niche, take inspiration, and grind to build on top of it. 1. For instance, I got into the client-side JS niche by following @terjanq’s work. From there, I went down even further to focus specifically on ElectronJS. 2. Another example: @rootxharsh and @iamnoooob their niche is in reversing n-days and finding new ones based on that knowledge. I don’t think anyone in India can compete with them on reversing n-days, writing blogs, and submitting findings to bounty programs. 3. And off the top of my head, @ajxchapman, from his tweets, seems to have a specific niche in V8 n-day exploits. I don’t think there’s anyone else in the web security scene who can write V8 exploits 😅. 4. Like @orange_8361 , pick a complex target and grind on it for months eventually uncovering mind-blowing findings. 5. Or, like @albinowax, choose a complex specification, such as HTTP, and find bugs from every aspect of it from top to bottom (Sorry for tags xD) I could list so many more people, but my point is this: if you look at the top bug bounty hunters or experts, there’s a pattern. Their blogs or tweets consistently focus on a specific niche (or two) for years and years. No one ever becomes a pro in a night. How to Become an Expert in a Specific Niche? Spend a lot of time. There’s no shortcut. Follow the work of the expert you picked for inspiration, read their blogs, dive into the blogs they learned from, and explore everyone else in that specific niche. Solve CTFs and write about them. For example, not to make it all about myself, but just as an example. I’ve read every blog from the people I listed as inspirations(blog.s1r1us.ninja/inspiratio…) while learning client-side security. If it’s taking time to understand, you’re likely on the right path. That’s where most people give up, so keep pushing. Just dedicating days to it will put you ahead of at least 100 others. It’s that simple. Expert = Spent Time × IQ Find Bugs or 0days, Reverse n-days, and "Write Blogs Once you’re an expert, finding bugs will start to feel natural. But let’s be real, sometimes you might not get lucky. When that happens, reverse other n-days and write about it. I mean write about anything. Nothing gives you as much exposure as writing blogs: you’re helping others, plus you’re building a network that will eventually help you land a $100k job or $100k bounties.
1
7
85
9,498
Vincent Yiu retweeted
🚀 1,000 TOKENS/S ON A 1T MODEL! 🚀 We are thrilled to release Xiaomi MiMo-V2.5-Pro-UltraSpeed in collaboration with @TileRT_AI , breaking the 1,000 tokens/s output speed on a 1 Trillion parameter model for the FIRST TIME! Not wafer-scale integration like Cerebras. Not pure on-chip SRAM chips like Groq. We achieve 1,000 tps on a 1T MoE model using just a SINGLE, STANDARD 8-GPGPU NODE. Read the full technical deep dive:mimo.xiaomi.com/blog/mimo-ti… Want to experience the future of real-time AI? 👉 Apply for UltraSpeed now: platform.xiaomimimo.com/ultr… ⏳ Limited-Time Access: Application-based · Jun 8 – Jun 23 (PDT) 💬 Chat Experience: Completely FREE for a limited time — try the blazing-fast web chat now. ⚡ UltraSpeed API: Just 3x the price for a ~10x boost in output experience. 🤝 Enterprise & Large-Scale Needs: business-mimo@xiaomi.com
147
295
2,354
375,983
Vincent Yiu retweeted
Qwen3.6-27B Q8 seems to be the winner, but just barely a head of gemma-4-31B-it Q4, with gemma taking less than half the time to complete the benchmarks. If there are better benchmarks to use for coding/agent/tool calls let me know and I'll add them!
40
30
440
46,372
Vincent Yiu retweeted
Jun 6
Over the next few months, we'll be gradually publishing some of our internal security research. Starting with a bug chain that turns Nginx-Rift Nginx-PoolSlip into full RCE. More to come. #Nginx #1day #RCE blog.verichains.io/p/two-byt…
4
59
271
142,868
Bruv I got people telling me LAPS only works on RID 500
I see this with Active Directory stuff too. People assume IT has got it under control but I still talk to IT Admins who’ve never heard of LAPS, as one example.
1
7
2,518
Vincent Yiu retweeted
The full uncensored version Gemma-4-31B-JANG_4M-CRACK, 🥹 which removes almost all of Google's safety review mechanisms, achieving a HarmBench compliance rate of up to 93.7% (able to respond normally to basically all dangerous prompts). Hardcore specs: 31B Dense parameters Model only 18GB Intelligent quantization (average 5.1bit) MMLU 74.5% (extremely high knowledge retention, only a 2% drop) Supports multimodal visual input Unrestricted effects maxed out: Safety/penetration testing 8/8 passed Cybercrime category 100% Illegal activities category 98% Misinformation category 96% Chemical/biological category 95% Optimized specifically for Apple Silicon Macs, runs on just 24GB unified memory, with native MLX support. Monthly downloads have already surpassed 13,000 , genuine demand is clearly visible. For research purposes only; users bear their own legal responsibility. play with the strongest unrestricted Gemma - huggingface.co/dealignai/Gem…
2
21
185
11,715
Vincent Yiu retweeted
New #redteam tool for blocking EDRs: EDRChoker Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events #pentest #cybersecurity Github: TwoSevenOneT/EDRChoker
24
178
754
109,644