
Tayfun Yelim
@tayfunyelim
🇹🇷| Hacker | Engineer | #oscp | #osce | #oswe | @marmara1883 | @METU_ODTU
ID: 521288483
11-03-2012 12:42:29
377 Tweet
183 Followers
1,1K Following







[ZDI-25-291|CVE-2025-4919] (Pwn2Own) Mozilla Firefox IonMonkey JIT Compiler Integer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: Manfred Paul (@[email protected])) zerodayinitiative.com/advisories/ZDI…

[ZDI-25-292|CVE-2025-4919] Mozilla Firefox SpiderMonkey Out-Of-Bounds Write Remote Code Execution Vulnerability (CVSS 8.8; Credit: Edouard Bochin (Edouard Bochin) and Tao Yan (@Ga1ois) from Palo Alto Networks) zerodayinitiative.com/advisories/ZDI…


Our team recently used a novel technique to increase the impact of what seemed to be only a blind SSRF. This novel technique involving HTTP redirect loops and incremental status codes led to full HTTP response leakage. Read more on Searchlight Cyber blog here: slcyber.io/assetnote-secu…



CVE-2025-4941 - Trend ZDI analyst Hossein Lotfi details the Firefox bug used at #Pwn2Own Berlin by Manfred Paul. Includes root cause analysis and video demo. zerodayinitiative.com/blog/2025/7/14…



