Marc Montpas (@marcs0h) 's Twitter Profile
Marc Montpas

@marcs0h

Software Entomologist focusing on dangerous species.

ID: 2510636469

linkhttps://montpas.me/ calendar_today26-04-2014 14:59:14

702 Tweet

1,1K Followers

896 Following

Marc Montpas (@marcs0h) 's Twitter Profile Photo

A thought for all those Object Injection flaws marked as "potentially" exploitable over the past few years. Life truly is a CTF. #wordpress #security

Lexfo (@lexfosecurite) 's Twitter Profile Photo

#phpggc: Our pentester Raphaël Dray just implemented a Gadget Chain for #Wordpress core, as per the article from WPScan - WordPress Security wpscan.com/blog/finding-a… github.com/ambionics/phpg…

WPScan - WordPress Security (@_wpscan_) 's Twitter Profile Photo

Our researchers found a serious SQL Injection vulnerability in the WP Fastest Cache plugin. It was fixed in the recent 1.2.2 update. Make sure to update now! wpscan.com/blog/unauthent… #wordpress #security

Fenrisk (@fenrisksec) 's Twitter Profile Photo

Expecting to struggle finding a gadget chain in WordPress Core during an assessment when devs suddenly decided to make it easy : fenrisk.com/publications/b…

Charles Fol (@cfreal_) 's Twitter Profile Photo

CVE-2023-49103: this analysis by GreyNoise is erroneous. The exploit WORKS with default configuration, even on docker installs. Please patch.

Ambionics Security (@ambionics) 's Twitter Profile Photo

Learn about the two @Owncloud vulnerabilities CVE-2023-49103 and CVE-2023-49105 in our new blogpost: ambionics.io/blog/owncloud-…

WPScan - WordPress Security (@_wpscan_) 's Twitter Profile Photo

Our researchers found a Pre-Auth Stored XSS vulnerability in the Popup Builder plugin (200k+ active installs). It was fixed in the recent 4.2.3 update. Make sure to update now! #wordpress #security wpscan.com/blog/stored-xs…

WPScan - WordPress Security (@_wpscan_) 's Twitter Profile Photo

Our researchers found a Pre-Auth Stored XSS vulnerability in the WP Go Maps plugin (formerly known as WP Google Maps, 400k+ active installs). It was fixed in the recent 9.0.28 update. Make sure to update now! #wordpress #security wpscan.com/blog/stored-xs…

Fio Cavallari 🍻👾🪓 (@fiocavallari) 's Twitter Profile Photo

Automattic is expanding the Jetpack and WPScan Security Research team, if you like to break PHP code and investigate malware fill out the interest form here: lnkd.in/dhFFArc9 #hiring #wordpress #securityresearch #remotejobs

Denis (@unmaskparasites) 's Twitter Profile Photo

Balada Injector: analysis of the initial and secondary infections. Domains: *.specialcraftbox[.]com and *.greenfastline[.]com (more in the post) Vulnerable plugin: Popup Builder. Thanks @marcs0h for the help with understanding the vuln

Sonar Research (@sonar_research) 's Twitter Profile Photo

🔥Multiple XSS vulnerabilities in popular CMS Joomla! (CVE-2024-21726) 🔥 PHP bug could be used to bypass sanitization - We just disclosed the technical details behind the recent Joomla vulnerability: sonarsource.com/blog/joomla-mu…

🔥Multiple XSS vulnerabilities in popular CMS Joomla! (CVE-2024-21726) 🔥

PHP bug could be used to bypass sanitization - We just disclosed the technical details behind the recent Joomla vulnerability:

sonarsource.com/blog/joomla-mu…
Charles Fol (@cfreal_) 's Twitter Profile Photo

The first part of the blog series: #Iconv, set the charset to RCE. We'll use #PHP filters and #CVE-2024-2961 to get a very stable code execution exploit from a file read primitive. #cnext

WPScan - WordPress Security (@_wpscan_) 's Twitter Profile Photo

Our researchers found a Pre-Auth Object Injection vulnerability in the SEOPress plugin (300k+ active installs). It was fixed in the recent 7.9 update. Make sure to update now! #wordpress #security wpscan.com/blog/object-in…

Marc Montpas (@marcs0h) 's Twitter Profile Photo

MOTD: Reinventing the wheel only works if it's circle-shaped. (Love uncovering relatively uncommon antipatterns like this.) #wordpress #security

Oliver Sild (@oliversild) 's Twitter Profile Photo

It's so cool to see so many people participate in our #WCUS WordPress CTF. Marc Montpas from Jetpack is currently leading the competition! 😎 You can see the live scoreboard here: ctf.patchstack.com/scoreboard

Trail of Bits (@trailofbits) 's Twitter Profile Photo

Probably not. Prompting an LLM with natural language is inherently lossy and ambiguous. Up to this point, programming has always been deterministic: Your code does what you say it should do otherwise, it’s a bug. Coding agents break that contract. blog.trailofbits.com/2025/12/19/can…