Kasif Dekel (@kasifdekel) 's Twitter Profile
Kasif Dekel

@kasifdekel

ID: 192466093

calendar_today19-09-2010 06:41:20

176 Tweet

706 Followers

260 Following

maxpl0it (@maxpl0it) 's Twitter Profile Photo

Found three VirtualBox vulnerabilities earlier this year. 2x Heap Overflows and 1x OOB read. Pretty great to get this post out! Come learn about emulated network offload bugs

SentinelOne (@sentinelone) 's Twitter Profile Photo

🔥New on SentinelLabs! 25 CVEs and counting: Vulnerabilities in #AWS & other major #cloud services. Kasif Dekel's latest research reveals millions of cloud users are exposed to privilege escalations from bugs in shared driver software. sentinelone.com/labs/usb-over-… #cybersecurity

Kasif Dekel (@kasifdekel) 's Twitter Profile Photo

Sorry about that Chuanda Ding & James Forshaw, I reported a LPE vulnerability and they decided to remove it. Hoped they'd release a fixed version. I find DeviceTree useful too and you can find a signed version in the repo alongside with the vuln details: github.com/kasif-dekel/OS…

maxpl0it (@maxpl0it) 's Twitter Profile Photo

- Use-after-frees from JIT - CodeQL for variant analysis - Never-before-seen exploit primitives - Tenured heap tomfoolery I’ve packed just about everything in this post!

Ronen Shustin (@ronenshh) 's Twitter Profile Photo

We discovered a container escape vulnerability in the @NVIDIA Container Toolkit. It allows attackers to gain full access to the host's filesystem and achieve Remote Code Execution (RCE). Here's everything you need to know about CVE-2024-0132 🧵👇

Kasif Dekel (@kasifdekel) 's Twitter Profile Photo

Funny lil thing I had to check. #WhatsApp `secret chat` feature isn't as secure as you'd hope. Found a funny way to easily bypass it. It’s supposed to provide local/physical protection to your convos but don't trust it with your super secret convos! 😅. Report dismissed by #Meta.

Ronen Shustin (@ronenshh) 's Twitter Profile Photo

This was a huge effort from the team. With every small primitive we discovered, we got closer—until we finally landed a full unauthenticated RCE. I had a ton of fun working on this research. ☸️👇

Ronen Shustin (@ronenshh) 's Twitter Profile Photo

We (+Nir Ohfeld) found a critical vulnerability chain in NVIDIA's Triton Inference Server (CVE-2025-23319) that can lead to full Remote Code Execution (RCE). An unauthenticated attacker can remotely take over the server, a cornerstone of many AI/ML production environments. 🧵

We (+<a href="/nirohfeld/">Nir Ohfeld</a>) found a critical vulnerability chain in NVIDIA's Triton Inference Server (CVE-2025-23319) that can lead to full Remote Code Execution (RCE).
An unauthenticated attacker can remotely take over the server, a cornerstone of many AI/ML production environments. 🧵