Register and share your invite link to earn from video plays and referrals.

V12
@v12sec
dangerously powerful agentic security
14 Following    9.5K Followers
Interestingly this is a very similar primitive to one of the "unexploitable" dead ends in @trailofbits recent article about sandbox escapes. (although this is a slightly different bug) It did take some manual nudging for me to convince 5.6-sol that AppArmor could be bypassed :)
Show more
My PlayStation 5 $10,000 bounty along with Firefox XSS bugs and many more vulnerable apps research are now public
XSS to account takeover inside Android WebView, and we are just getting started
More TEE attacks, this time on Signal’s contact discovery enclaves.
In the pre-LLM era, this could possibly yield a Big 4-paper (with a few unnecessary designs/evaluations to satisfy the reviewers' tAstE, of course) 🤪 Excellent work anyway. BTW If you are interested in the page access pattern attack on SGX enclaves, there is an out-of-box demo I've written:
Show more
Absolutely beautiful find. It’s such a shame that vulns like this often get buried under 10,000 AI slop reports these days. 😭
Insane finding. You might want to rethink your risk surface in browser wallets.
Stick around on our web page for 10 minutes and all your funds are gone. Just connect your wallet to the dApp and enjoy some Temple Run. Unlock your wallet again and it’s empty 😇. A silent signature extraction in @Rabby_io, leading to a full wallet drain. 🧵
Show more
0
42
953
132
Forward to community
another one (poc) for redis server RCE: handleClientsBlockedOnKey() use-after-free. patched in release 8.8.2.
found another one! redis 8.8.0 bidirectional RCE we will release poc after the patch
and here's our poc for postgres server RCE: CVE-2026-14669. patched postgreSQL 18.6. poc for client RCE 🔜
And here's postgres bidirectional RCE no admin required, client infects server, server infects client ♻️🐛
Iroh is a P2P networking Rust library used by (among others) Paycode and Nous. We found a preauth DoS in iroh-relay where malformed messages could crash relays. The iroh team fixed it in iroh-relay 1.0.2 and patched public relays. Thanks to @n0computer for the fast response!
Show more
And here's postgres bidirectional RCE no admin required, client infects server, server infects client ♻️🐛
0
12
938
120
Forward to community
found another one! redis 8.8.0 bidirectional RCE we will release poc after the patch
0
19
806
103
Forward to community
today we are releasing a qemu escape
0
24
1.6K
240
Forward to community