Yordan Stoychev (@yordanstoychev) 's Twitter Profile
Yordan Stoychev

@yordanstoychev

20, Security Research @osec_io ■ CTF w/ Perperikon and Team Bulgaria

ID: 3070444707

linkhttp://anatomic.rip calendar_today04-03-2015 18:25:05

295 Tweet

359 Followers

502 Following

nicolas vamous (@nvamous) 's Twitter Profile Photo

“Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel” yanglingxi1993.github.io/dirty_pagetabl… We succeeded in exploiting CVE-2023-21400 on Google pixel 7 with Dirty Pagetable. And we also pushed the exploitation of file UAF and pid UAF to the next level with Dirty Pagetable!

Yordan Stoychev (@yordanstoychev) 's Twitter Profile Photo

Excellent thread reviewing Romania's academic olympiad/competition situation and its absurdity. Bulgarian education shares the same problem.

Yordan Stoychev (@yordanstoychev) 's Twitter Profile Photo

Finished a write-up of a vulnerability in the io_uring subsystem of the Linux Kernel. This one is interesting because it gives you an incredibly powerful primitive - a multipage-wide OOB read and write to physical memory. anatomic.rip/cve-2023-2598/

Yordan Stoychev (@yordanstoychev) 's Twitter Profile Photo

This past weekend I gave my first talk at BSides Sofia. It was on modern Linux rootkits - stealth and evading EDR/XDR. Cool techniques, real-time demo, all the good stuff. It was quite the experience for sure and I was happy to see how well received it was :)

OtterSec (@osec_io) 's Twitter Profile Photo

Aptos' Fungible Asset model aims to improve security and flexibility over the legacy Coin standard. But does it eliminate all risks? In our latest blog, we analyze its design, security implications, and hidden vulnerabilities. Full breakdown → osec.io/blog/2025-02-1…

Robert Chen (@notdeghost) 's Twitter Profile Photo

in light of the recent Bybit hack, what can Solana teams do to be more secure? Solana has a unique signature model, that is arguably safer for multisigs. I wrote a quick post exploring this model, proposing a procedure for safe signing. osec.io/blog/2025-02-2…