xpldotjs (@xpldotjs) 's Twitter Profile
xpldotjs

@xpldotjs

ID: 1389171050231988224

linkhttp://xpldotjs.github.io calendar_today03-05-2021 10:52:55

785 Tweet

127 Followers

304 Following

DirectoryRanger (@directoryranger) 's Twitter Profile Photo

Under the Hood of AFD.sys Part 1: Investigating Undocumented Interfaces leftarcode.com/posts/afd-reve… Part 2: TCP handshake leftarcode.com/posts/afd-reve… Part 3: Sending TCP packets leftarcode.com/posts/afd-reve… Part 4: Receiving TCP packets leftarcode.com/posts/afd-reve…

moton (@moton) 's Twitter Profile Photo

PoC Exploit Disclosed: Researcher Unveils Windows MS-EVEN RPC Vulnerability - securityonline.info/poc-disclosed-…

ptr-yudai (@ptryudai) 's Twitter Profile Photo

I participated in DiceCTF 2026 Quals and found cornelslop, a kernel exploitation challenge, especially interesting. Here is my writeup🍣 ptr-yudai.hatenablog.com/entry/2026/03/…

Alex Plaskett (@alexjplaskett) 's Twitter Profile Photo

An analysis of CVE-2026-21236 - A heap based buffer overflow in the Microsoft Windows Kernel afd.sys - was just published by Emily L a recent secondment with my team EDG! Nice work for her first triage of a kernel memory corruption bug! nccgroup.com/research/vulne…

Sakai (@sakaijjang) 's Twitter Profile Photo

김수키(Kimsuky)에서 만든 악성코드-구매 주문서 SBPL2509217 (개정 1).pdf.js wezard4u.tistory.com/429743 #김수키 #Kimsuky #it

Kağan (@kagancapar) 's Twitter Profile Photo

I discovered CVE-2026-5201. A heap buffer overflow in GNOME's gdk-pixbuf JPEG loader (CVSS 7.5). A 122-byte JPEG crashes any app using gdk_pixbuf_new_from_file(). RCE demonstrated on 32-bit via vtable hijack. Full write-up and PoCs: github.com/kagancapar/CVE…

I discovered CVE-2026-5201. A heap buffer overflow in GNOME's gdk-pixbuf JPEG loader (CVSS 7.5). A 122-byte JPEG crashes any app using gdk_pixbuf_new_from_file(). RCE demonstrated on 32-bit via vtable hijack. 

Full write-up and PoCs: 
github.com/kagancapar/CVE…
Varik (@d4rk7et) 's Twitter Profile Photo

Went from "V8 exploitation seems unachievable" to solving all 9 pwn.college V8 challenges. Wrote a guide on getting into browser exploitation if you already have classic pwn knowledge. varik.dev/blog/v8/gettin…

Linux Kernel Security (@linkersec) 's Twitter Profile Photo

From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android. lukasmaar.github.io/posts/heap-kas…

From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks

Article by Lukas Maar about evaluating the KernelSnitch timing side-channel attack on a variety of systems, including Android.

lukasmaar.github.io/posts/heap-kas…
Muqsit 𝕏 (@mqst_) 's Twitter Profile Photo

♣ A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass Blog: whiteknightlabs.com/2024/02/09/a-t… #infosec

♣ A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass 

Blog: whiteknightlabs.com/2024/02/09/a-t…

#infosec
chiefpie (@cplearns2h4ck) 's Twitter Profile Photo

Some of the bugs I disclosed to MSRC last year is now public on the company's advisory page. E.g: CVE-2025-47985 Windows Event Tracing Elevation of Privilege starlabs.sg/advisories/25/…

suzaki (@kunisuzaki) 's Twitter Profile Photo

Paper PowerHooK: Enabling Software-Based Power Side Channels Against AMD SEV Technologies via Transient-Execution Replay [WOOT 26] tugraz.elsevierpure.com/en/publication… AMD SEV-SNPに対する電力サイドチャネル攻撃PowerHooK。 AES-NIに対して攻撃してAESキーを取得。

Calif (@calif_io) 's Twitter Profile Photo

Welcoming gift for _ZN4DionC1Ev: QEMU and UTM Escape Blog: open.substack.com/pub/calif/p/ma… PoCs: github.com/califio/public… youtube.com/watch?v=WWfxGy…

thAI Duong (@xorninja) 's Twitter Profile Photo

MAD Bugs: QEMU and UTM Escape Welcome gift for _ZN4DionC1Ev! Now onto another cool one for Stefan Esser. Blog: blog.calif.io/p/mad-bugs-qem… youtube.com/watch?v=WWfxGy…