Megatron LLM Hub
全部
Twitter

推特安全流

头条6

通过书签和浏览器扩展对本地 llama.cpp 发起同源攻击,可执行任意命令。

直接命中本地 AI Agent 安全,攻击面新颖且可复现。

RT @G3tSyst3m: Just wrapped up my latest blog post! In short: We explore same-origin attacks using bookmarklets and browser extensions to coerce an already running instance of llama.cpp (the local LLM inference engine) 🦙to execute commands of our choosing. https://t.co/NKMApEkxIg

ai_agentllm同源攻击浏览器 @0xTriboulet 原文 ↗

GenDigital 产品存在 0day,SAM 数据库转储和提权 PoC 已公开。

高危提权 0day,PoC 公开,影响面广。

RT @MSNightmare2000: GenDigital products are vulnerable to a 0day vulnerability, a PoC that demonstrates a SAM database dump and elevation of privilege is now public https://t.co/sjDQJnEplX

lpe0daypocwindows @0xTriboulet 原文 ↗

NVIDIA 用户态 GPU 组件内存破坏 0day 和 Avast 沙箱提权 0day 双双公开。

两个高危 0day,PoC 公开,影响 NVIDIA 和 Avast 用户。

Two more fresh 0-day drops from @MSNightmare2000. GreenSection: NVIDIA user-mode GPU components, memory corruption / OOB write. PrettyPrague: Avast / Gen Digital sandbox EoP to SAM dump + SYSTEM. Red teamers: BYOVD isn't the only path to privileged execution. Blue teams + threat intel: public PoCs shorten the path to operational abuse. Start understanding the telemetry before these techniques show up in tooling. https://t.co/qIAoCBYUtY https://t.co/oqHEV7uEnf #0day #VulnerabilityResearch #ThreatIntel

0daylpepocnvidia @cr3ghost 原文 ↗

Anthropic 警告:信息窃取恶意软件劫持 Claude 会话以消耗配额。

AI Agent 会话安全直接相关,影响所有 Claude 用户。

RT @BleepinComputer: Anthropic warns infostealer malware is hijacking Claude sessions to drain usage https://t.co/fy0bQm82U0 https://t.co/fy0bQm82U0

ai_agentllminfostealer事件 @artem_i_baranov 原文 ↗

PaperCut NG/MF 认证绕过漏洞 (CVE-2026-81578) 已在蜜罐中观察到利用活动。

真实世界利用已出现,攻击者正在利用认证绕过进行数据窃取。

🚨 We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th) An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby ⚠️We haven't yet verified whether the exfil route is a working one Track emerging Papercut MF exploit activity 👉 https://t.co/TTnxgi9Hv5

cve认证绕过事件数据窃取 @DefusedCyber 原文 ↗

SpecterOps 发现 ServiceNow 可泄露明文发现凭据,包括 SSH 密钥和 AWS 密钥。

影响 ServiceNow 用户,可获取敏感凭据,攻击面大。

RT @SpecterOps: ServiceNow won't let you query cleartext discovery credentials, not even as admin. @Tw1sm found a way to make the server hand them over anyway, no coercion or relay needed. Works on SSH keys, AWS keys, Entra secrets, and LDAP creds. Check it out ⤵️ https://t.co/ryVKdaDmGE

凭据泄露servicenow工具 @bb_hacks 原文 ↗
必看2

AI 安全公司 V12 声称其 AI 代理已发现 Linux LPE、QEMU 逃逸等漏洞。

AI 驱动的漏洞挖掘进展,对安全研究影响深远。

RT @cr3ghost: Exploit devs, vulnerability researchers and reverse engineers should probably pay attention to this one. V12 says its AI agent has already found Linux LPEs, a QEMU escape, Firefox UXSS, and bidirectional RCEs in Postgres + Redis. Then it autonomously found a $2.5M bug bounty affecting >$100M in funds. Their end goal? An AI system that can reason across huge codebases, invent new bug classes, and generate novel exploits. Oh, and they just raised $10M to keep building it. The era of AI-assisted vulnerability research is getting very real. Author: @v12sec https://t.co/QDt9NFKynK #ExploitDevelopment #VulnerabilityResearch #AI

ai_agent漏洞挖掘报告 @cr3ghost 原文 ↗

NVIDIA 用户态 DLL 存在 0day,可用于跨用户边界,可能获取 SYSTEM 权限。

NVIDIA 组件提权 0day,影响广泛。

RT @MSNightmare2000: Nvidia user mode dlls are a bit funny, here is a 0day that can be used to cross-user boundaries (maybe get SYSTEM ?) https://t.co/cg94oRclaf

0daylpenvidia @0xTriboulet 原文 ↗
推荐15

Unitree G1 人形机器人存在可蠕虫化的蓝牙 RCE 漏洞 (UniBLEed)。

物联网/机器人安全,可蠕虫化,影响面广。

RT @olivier_boschko: I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!! https://t.co/GYopBgDtTO

rce蓝牙iot事件 @SkelSec 原文 ↗

Qubes OS 发布安全公告 QSB-118:qvm-copy-to-vm 错误报告中的 Dom0 任意代码执行。

影响 Qubes OS 用户,Dom0 被攻破意味着整个系统沦陷。

RT @QubesOS: QSB-118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting https://t.co/8Um1GiZL8m

cvequbes虚拟化事件 @0xocdsec 原文 ↗

CVE-2026-45308:长文件名导致 ZIP 解压漏洞分析。

ZIP 解压漏洞,可能影响多种应用。

RT @_CryptoCat: Long name make ZIP go brrrr https://t.co/3bXahnaFRu

cvezip漏洞分析 @0xocdsec 原文 ↗

滥用 Azure VM 的 BitLocker 恢复密钥作为攻击向量。

云环境攻击新思路,影响 Azure 用户。

Abusing Azure VMs: BitLocker Recovery Key as an Attack Vector https://t.co/CYEhQZqw4x

azurebitlocker攻击向量 @ipurple 原文 ↗

cube0x8 发布系列博客,从零开始进行复杂目标的模糊测试和漏洞披露。

高质量的模糊测试实战教程,值得学习。

RT @cube0x8: I've been wanting to publish a series of blog posts where I tackle a complex and tricky target — from harnessing and instrumentation to scalable format-aware fuzzing, crash reproduction, and disclosing bugs through Bugcrowd. Part 1 is now live 👇 https://t.co/4AUElYnxj2

fuzzing漏洞挖掘工具 @0xocdsec 原文 ↗

j00ru 的 syscall 表工具,追踪 Windows XP 到 Windows 11 的 Nt* syscall ID。

Windows 逆向和漏洞研究必备工具。

RT @LxlxIxlxlxL: If you do Windows internals / reversing, bookmark this. @j00ru's syscall table tracks x86-64 Nt* syscall IDs across Windows XP all the way through modern Windows 11/Server builds. Great for version diffing, old sample analysis, syscall-stub validation and generally answering “what the hell was 0x72 on this build?” https://t.co/POXiAnTN2n

工具windows逆向工程 @0xpwnie 原文 ↗

构建虚假 UAC 提示以窃取凭据的 Medium 文章。

社会工程学攻击手法,对红队有参考价值。

Fake UAC Prompt to Exfiltrate Credentials New Medium post, in this one we have build a fake User Account Control prompt https://t.co/3OZfeVeRhs https://t.co/ajRRA1KZRs

社会工程学凭据窃取工具 @Salsa12__ 原文 ↗

Vanguard C2 框架完成 QUIC 出口和 TLS 1.3 AEAD 加密测试。

新的 C2 框架功能更新,对红队有参考价值。

Final test conducted and shipped QUIC egress in vanguard with TLS 1.3 AEAD, and an 7.99 bits/byte entropy. in vanguard stress test, Vanguard can manage 100s of active agents and can be easily controlled using automation scripts. one of the coolest features is also on the way. https://t.co/DVEzQk3TYv

c2工具加密 @5mukx 原文 ↗

hakluke 发布 JWT 攻击手册。

JWT 攻击是 Web 安全常见主题,值得参考。

RT @hakluke: https://t.co/7LJJgomVyf

jwtweb安全工具 @0xocdsec 原文 ↗

GitHub 项目 'trustmebro',可能与 DNS 相关。

DNS 相关工具,可能用于安全测试。

RT @syndrowm: It’s always dns https://t.co/ccGu83zhfx

dns工具 @0xocdsec 原文 ↗

一篇关于盲数据外泄漏洞的 write-up。

盲数据外泄是常见漏洞,值得学习。

RT @kymu___: never did write-up before so here we are, a fun blind data exfiltration bug i usually find in role-based bug bounty assets https://t.co/BEPD9qdvFP https://t.co/zOlfK01hOq

数据外泄漏洞分析writeup @0xocdsec 原文 ↗

hermes-agent v2026.8.18 发布,一个可成长的 AI 代理。

AI 代理工具更新,可能用于自动化任务。

hermes-agent v2026.8.18 — The agent that grows with you https://t.co/18PYMYykMk https://t.co/zY4Y00HEQ0

ai_agent工具 @KitPloit 原文 ↗

openclaw v2026.8.1-beta.2 发布,一个跨平台个人 AI 助手。

AI 助手工具更新,可能用于自动化任务。

openclaw v2026.8.1-beta.2 — Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞 https://t.co/Jfb8lPt9Lb https://t.co/Troz5SPTou

ai_agent工具 @KitPloit 原文 ↗

vphone-cli 工具,可在 Apple Silicon 上启动和管理虚拟 iPhone。

iOS 安全研究工具,值得尝试。

vphone-cli — Boot and manage virtual iPhones on Apple Silicon with firmware patching, jailbreak variants, and security research features for iOS... https://t.co/7tENVV3a3X https://t.co/2UTzHRzs1b

ios工具虚拟化 @KitPloit 原文 ↗

大学团队分享了一个 AI 辅助模糊测试项目 'vrig-fuzzillai' 的经验。

AI 辅助模糊测试的实践案例,值得参考。

RT @dudcom3: https://t.co/eMhafPlpda 😅 something me and my uni friends worked on, wasn't perfect but we learned a lot and people got j*bs out of it so not horrible lol We are doing XNU/IOS/MacOS stuff this year, I am sure it'll go a lot better lmao

ai_agentfuzzing工具 @0xocdsec 原文 ↗
更多81

OffensiveCon 2026 幻灯片:利用 Google Wifi Pro 中的 QSEE 漏洞。

针对 Google 硬件的 QSEE 漏洞利用研究,技术含量高。

Exploiting QSEE Vulnerabilities in Google's Wifi Pro (slide deck) https://t.co/6MoUwL27IJ Credits @tieknimmers and @pulsoid #infosec https://t.co/f9hm9mZH2a

漏洞利用qseegoogle议题 @0xor0ne 原文 ↗

Brave 浏览器新功能 'Email Aliases' 可能被滥用于钓鱼攻击。

新功能带来新的钓鱼攻击面,值得关注。

🎣Detect Brave Alias Abused for Phishing Today Brave announced Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to a new service. Using an alias address keeps the user's real email address hidden from the website while still forwarding messages from the service. This is a good privacy initiative to protect user email from data breaches but coming from a threat actor perspective this is also a new venue for abusing for potential phishing since it is disposable and from trusted browser organization. https://t.co/logUt7MaCk As such I have crafted out Defender XDR monitoring to detect potential abuse of Brave email alias by threat actors for sharing with fellow defenders.🫡 https://t.co/Ttjrj9BVtq #threathunting

浏览器钓鱼新功能 @0x534c 原文 ↗

安全研究员使用 GLM-5.3 在 Mac 上发现首个 0click 漏洞。

AI 辅助漏洞挖掘的又一实例,展示 AI 在安全领域的潜力。

RT @__suto: Got my first 0click. Reported! Just ME and GLM-5.3 on my mac ultras 😏 https://t.co/Q7vNL6TuzM

ai_agent0click漏洞挖掘 @0xocdsec 原文 ↗

M4 ANE 芯片逆向工程调查第四部分发布。

对 Apple 芯片的深入逆向研究,对硬件安全感兴趣者值得关注。

RT @originalmaderix: Part 4 of my ANE investigation is out! (substack soon) https://t.co/V9c8yFSOEk This is probably the last version in this hardware series, a lot has been investigated by the community and I'm glad this ignored piece of sillicon finally got the attention it needed. I'm also glad to have played a part in this🙂 Hope Apple can soon support the low level programmability and publish specs of this chip instead of the community having to pull out from raw bytes, guesswork and brittle private APIs. I see some positive signs with M6 dual ANE and first class coreAI support. Fingers crossed! Now on to other targets 😉

硬件逆向工程apple @0xocdsec 原文 ↗

安全研究员使用自主浏览器和代理在 HackerOne 上获得近 15 万美元奖励。

AI 驱动的自动化漏洞挖掘在真实项目上的成果。

RT @_jensec: Close to $149k reward from 15 findings from 6 programs at HackerOne this month with @Paaastha. We have been building a offensive security research product for a few months now and we have put it to test this month at HackerOne across programs. 50 high criticals pending. We are building autonomous browser on top of proxy and data processing engines connected to agentic memory store for fully autonomous flow. long way too go yet before a commercial product. [Benchmarks and detailed statistics soon]

ai_agent漏洞挖掘报告 @0xocdsec 原文 ↗

发现中文版的 'Bee C2' Coruna 控制系统在流传。

新的 C2 框架出现,值得威胁情报人员关注。

Chinese version of the "Bee C2" Coruna control system is bouncing around out there. Found via @Huntio . Let's do some digging... https://t.co/I6gcTjRiGF

c2威胁情报事件 @NetAskari 原文 ↗

系统管理员建议阻止访问 r1u1[.]com 域名。

可能是恶意域名,值得关注。

If you are a sys admin you might want to block access to r1u1[.]com .

恶意域名事件 @NetAskari 原文 ↗

安全研究员在 AI 辅助下,4 周内发现 6 个 Windows 11 Canary 提权漏洞。

AI 辅助漏洞挖掘的又一实例,展示 AI 在安全领域的潜力。

RT @xaitax: End of June I set myself a goal: find an EoP in Canary Windows 11, fully AI-assisted. That quickly grew into wanting more. 4 weeks later, I had 6 unique ones. So I adjusted the goal to 12 in Q3. Now I’ve got all 12 in the bag - in August. All that while having a family and a full-time job. Let’s see how many I can get in September.

ai_agentlpe漏洞挖掘 @0xocdsec 原文 ↗

公开一个旧的 zsh PoC,本可成为 LPE 但未成功。

zsh 相关漏洞研究,对 Linux 安全有参考价值。

RT @speedyfriend433: Disclosing an old zsh PoC that could have been LPE, but mission failed 😞

lpepoczsh @0xocdsec 原文 ↗

Vercel 在 HackerOne 上的沙箱项目,测试自主代理框架。

AI 代理在漏洞挖掘中的应用,值得关注。

RT @_jensec: Vercel Sandbox Program at HackerOne is a bittersweet way to test full agentic harness, 10 duplicates so far in testing :D competition is brutal

ai_agent漏洞挖掘事件 @0xocdsec 原文 ↗

libheif 库的 119 个历史漏洞修复被映射,以预测下一个漏洞可能出现的区域。

AI 辅助漏洞预测,对安全研究有参考价值。

RT @pdiscoveryio: Security context for strukturag/libheif: 119 past vulnerability fixes across its history, mapped into where the next bug is likely to surface and which fixes an AI agent must never regress. https://t.co/E0IEeZBDHj

ai_agent漏洞预测libheif @0xocdsec 原文 ↗

加州立法者一致通过 Linux 豁免年龄验证法,GPL、MIT 等许可证软件豁免。

对开源软件分发有影响,值得关注。

RT @tomshardware: California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt https://t.co/fBbeXDUkhs

开源政策linux @0xocdsec 原文 ↗

OpenAI 的 Astra 代理设计为可运行数周,Altman 希望提供 '永远运行' 的版本。

AI 代理的持久化运行能力,对安全有潜在影响。

RT @AndrewCurran_: Alex Heath got an Astra demo. Astra is designed to run for weeks, and Sam Altman says he wants to offer a version that 'runs forever' in both ChatGPT and the API.

ai_agentopenai报告 @0xocdsec 原文 ↗

据报道,支付宝发生数据泄露,涉及 8.2 亿用户记录。

大规模数据泄露事件,影响面广。

RT @DailyDarkWeb: 🇨🇳 China - Alipay Data Breach: 820 Million User Records Exposed Alipay, a prominent Chinese mobile payment and lifestyle platform, has allegedly had a full database containing information on 820 million users compromised and offered for sale. The allegedly compromised data includes a full user database impacting 820 million individuals. This reportedly contains personal identifying information such as names, phone numbers, and email addresses, along with user account details. Source: https://darkforums[.]as/Thread-DATABASE-CHINA-820-Million-Alipay-Users-Full-Database

数据泄露事件支付宝 @0xocdsec 原文 ↗

Opera 浏览器是昆仑万维的子公司,其内置 VPN 可能涉及数据隐私问题。

浏览器隐私问题,值得关注。

RT @davidgpeterson: As a side note, the Opera browser is popular for its built-in VPN. But "Opera Norway AS" is actually a subsidiary of Kunlun Tech Co., Ltd from Beijing China. Kunlun used to own Grindr until they were forced to sell it by the US government for national security reasons. 5/🧵

浏览器隐私事件 @0xocdsec 原文 ↗

关于 AI 生成代码审查的讨论。

AI 代码审查是热点话题,值得了解。

@ShitSecure @C5pider @Octoberfest73 Who's got the time to review all that code?! 😜 Unless...

ai_agent代码审查 @mrgretzky 原文 ↗

关于 AI 生成代码是否需要 100% 人工审查的讨论。

AI 代码审查是热点话题,值得了解。

@mrgretzky @C5pider @Octoberfest73 Don’t think it’s needed to have 100% human review for all generated code that’s also just not possible

ai_agent代码审查 @ShitSecure 原文 ↗

关于 AI 代理在代码审查和测试中的应用讨论。

AI 代码审查是热点话题,值得了解。

@mrgretzky @C5pider @Octoberfest73 Dedicated AI agents do review and fixing + human architecture and guidance + human verification and testing. But also dozens of AI written test cases for the whole code base to avoid common issues.

ai_agent代码审查 @ShitSecure 原文 ↗

关于 AI 生成代码和内部工具开发的讨论。

AI 代码生成是热点话题,值得了解。

@mrgretzky @C5pider @Octoberfest73 You guys should have had really had a chilled year than 😅but also didn’t generate multiple hundred thousand lines of working new internal tools or didn’t do research with AI 👀

ai_agent代码生成 @ShitSecure 原文 ↗

关于 AI 代理的讨论。

AI 代理是热点话题,值得了解。

@C5pider @rad9800 https://t.co/6vj2awQOz7

ai_agent @mrgretzky 原文 ↗

关于 AI 使用限制和用户反应的讨论。

AI 使用限制是热点话题,值得了解。

The decreasing AI use limits and reactions to them are interesting. I have a $20/mo Claude subscription that’s effectively my new Google that I rarely if ever hit my quota on. Meanwhile I read about people avg $1000/day in usage. If/when the music stops people will be in trouble

ai_agent使用限制 @Octoberfest73 原文 ↗

关于秃头的玩笑。

无实质内容。

@rad9800 Once you go bald, so will I. We are going to be bald besties. 👯

闲聊 @C5pider 原文 ↗

无实质内容。

无实质内容。

enter the portal bro https://t.co/NXKAwnPxrN

闲聊 @0xpwnie 原文 ↗

关于中国的评论。

无实质内容。

China is the "country of large numbers

闲聊 @NetAskari 原文 ↗

关于 IoT 设备中自定义 AES 加密算法的分析。

IoT 固件逆向分析,对安全研究有参考价值。

RT @oneandonlyhusam: Understanding encryption algorithms is critical for any security researcher analyzing malware or even doing vulnerability research. Many samples will contain customized implementations encryption algorithms. in this example, this IoT device is utilizing a customized implementation of AES 128 in ECB Mode, in this single function that handles both encryption and decryption based on a passed flag. I was only able to identify this without having to look for imported standard AES libraries, because I understand how AES works mathematically, thus I can spot patterns that contain it. here, I was able to see all four of the main steps in AES: 1) SubBytes (Byte substitution via XOR with sbox) 2) ShiftRows (Cyclical shift of values in block) 3) MixColumns (Matrix multiplication) 4) AddRoundKey (XOR with round key) Then I identified it as AES 128 specifically because 128 requires only 10 rounds, consistent with the for loop counter. And then I identified that this was in ECB because there's no block chaining and blocks are independent. Then I was able to trace where the key derivation was happening and find the initial input and see the full key transformation against hard coded values, thus cracking this weak implementation of AES and finding a vulnerability.

iot加密逆向工程 @0xpwnie 原文 ↗

推荐阅读一位资深逆向工程师的文章。

逆向工程经验分享,值得参考。

RT @cr3ghost: One of the most talented reverse engineers in the industry that keeps his techniques private due to the industry. Highly recommend reading.

逆向工程 @cr3ghost 原文 ↗

对 MDSec 文章的评论。

无实质内容。

@MDSecLabs @__invictus_ I had an good read

闲聊 @5mukx 原文 ↗

Brendan Dolan-Gavitt 将谈论 AI 如何终结安全通过混淆。

AI 与安全的关系是热点话题,值得了解。

RT @UnpromptedAU: Speaker announcement: Brendan Dolan-Gavitt (@moyix) from XBOW (@Xbow) will be speaking about how security through obscurity is dead, and AI killed it!

ai_agent议题 @0xocdsec 原文 ↗

Signal 在 iOS 上添加了 MTE 支持,但 Android 版本尚未支持。

移动安全相关,值得关注。

RT @GrapheneOS: Signal finally added MTE support for iOS in April 2026 but hasn't done it for Android yet. It isn't important to anything we were talking about as it was just an example of even a well known security-focused app not prioritizing enabling these opt-in features which remains true.

移动端mtesignal @0xocdsec 原文 ↗

GrapheneOS 讨论摩托罗拉手机将支持 MTE。

移动安全相关,值得关注。

RT @GrapheneOS: @0xocdsec @sebuzdugan The Motorola phone is going to have MTE and the other security features on our requirements list. It's going to have a secure element but it won't be as good as the Titan M2/M3 for the initial generation. It's mostly relevant to protecting against brute force attacks in BFU.

移动端mtegrapheneos @0xocdsec 原文 ↗

GrapheneOS 认为 Pixel 11 缺少 MTE 是为了削减成本。

移动安全相关,值得关注。

RT @GrapheneOS: @P4mui MTE is definitely missing from the Pixel 11. There's an incredibly slim chance that it's supported in hardware but had to be disabled due to being broken. If that's the case, it likely couldn't ever be used regardless. We think that it was simply never supported to cut costs.

移动端mtepixel @0xocdsec 原文 ↗

GrapheneOS 讨论摩托罗拉设备将比 Pixel 更高端。

移动安全相关,值得关注。

RT @GrapheneOS: @alexjvmes The Motorola devices we'll be using are significantly higher end than Pixels. Look at reviews and other information about the Motorola Signature (2026) for an idea of what we'll be supported based on the predecessor to it. It's going to be a flagship with a real flagship SoC.

移动端grapheneos @0xocdsec 原文 ↗

关于非 MTE 设备安全状况的讨论。

移动安全相关,值得关注。

RT @NedWilliamson: This went from an academic argument to real world faster than any of us could have foreseen. I have done extensive experiments of the ecosystem security posture post “vulnpocalypse” and the story on any non-MTE device is disastrous. I’ve banned such devices from usage in my home.

移动端mte @0xocdsec 原文 ↗

gamozolabs 认为失去 MTE 是安全史上最大的倒退。

移动安全相关,值得关注。

RT @gamozolabs: Losing MTE is probably the biggest backwards step in security history. Exploitation is forever trivial on Android with no near term hopes of difficulty increases of significant effect.

移动端mte @daaximus 原文 ↗

chompie1337 对 Pixel 放弃 MTE 表示不解。

移动安全相关,值得关注。

RT @chompie1337: This is so strange to me. why invest in a fancy security chip (with a million dollar bounty), advanced boot loader security, forcing kernel mitigations be enabled across vendors, just to ditch MTE? Pixel used to the gold standard device for Android security..

移动端mtepixel @0xpwnie 原文 ↗

对 Android 失去 MTE 表示遗憾。

移动安全相关,值得关注。

RT @kayseesee: Very sad for Android. @DaveKSecure

移动端mte @0xocdsec 原文 ↗

GrapheneOS 因俄罗斯网络过滤而更换服务器提供商。

网络审查对服务可用性的影响,值得关注。

RT @GrapheneOS: Near the end of May 2026, Russia began filtering access to DataPacket IP space with an enforced domain allowlist for HTTP and TLS SNI. GrapheneOS services aren't on the allowlist so we had to switch from DataPacket Frankfurt to Cherry Servers Amsterdam for Russia. That's now getting filtered too. We've fixed it again by using Zare London for connections from Russia instead. That's the final of our sponsored servers in Europe we can use so we'll need to fall back to Xenyth Toronto if they filter it. We're using our own IP space in Toronto so it should work unless they specifically block us. We don't think we'll be blocked directly but we're also unlikely to get placed on the allowlist. That means our services are gradually going to become inaccessible in Russia via the IP space of major cloud services. Our own IP space will still work fine and we don't host any VPN services ourselves. Our website, OS updates, app repository, connectivity checks, network time, network-based location, geocoding and other main services should work again in Russia. It's likely they'll expand to filtering Zare's IP space and then we'll have to use Toronto where we have our own non-anycast IPv4 /24. They use a domain blocklist for most of the internet and an allowlist for many VPS and dedicated server hosting providers to block access to VPN services. It's likely they'll expand to enforcing an allowlist for every major server hosting provider. That's far more aggressive than China's filtering. Our authoritative DNS is hosted via 2 anycast networks using our own ASN and IP space so it hasn't been impacted by this. It's likely we can avoid it for the rest of our services by using our own IP space. If they start filtering netcup IP space, we can make a reverse proxy to those from Toronto. If our services are blocked, connectivity checks can also be set to Standard rather than Disabled to use the Google servers. That'll keep automatic selection of networks with internet working along with automatic captive portal handling and JobSceduler not assuming every network has internet access.

网络审查grapheneos事件 @0xocdsec 原文 ↗

matthew_d_green 讨论物联网设备被持久化入侵的普遍性。

物联网安全是热点话题,值得了解。

RT @matthew_d_green: @valkenburgh You have a printer? IoT device? Monitor? Keyboard? Lego robots? WiFi connected cooking appliance? SSD? Car? Six separate processors on your car? All persistently rooted and infected and will infect everything in your life the second you try to clear out anything.

iot事件 @moyix 原文 ↗

无实质内容。

无实质内容。

https://t.co/jHrK1z4EMc

闲聊 @0xpwnie 原文 ↗

介绍朋友。

无实质内容。

This is my friend @LxlxIxlxlxL He's the smartest dumbest person ever https://t.co/ayCrEBffMf

闲聊 @0xpwnie 原文 ↗

分享一个逆向工程技能仓库。

逆向工程学习资源,值得参考。

RT @buaaxhm: 我太爱这个了 太牛逼了 https://t.co/TDXOLFCH4j

逆向工程工具 @404death 原文 ↗

MSNightmare2000 在德国找工作。

招聘信息,无安全价值。

RT @MSNightmare2000: Also, looking for a job, hard requirement has to be in Germany, if you have anything for me, you can reach me by email ! [email protected]

招聘 @404death 原文 ↗

无实质内容。

无实质内容。

RT @katha1502: 😂😂

闲聊 @0xocdsec 原文 ↗

moyix 认为 AI 代理的'身体'是它们的工具软件。

AI 代理的哲学思考,值得了解。

My most crackpot belief is that today’s AI agents are in fact embodied and their body is the harness software (Codex/Claude Code)

ai_agent @moyix 原文 ↗

关于渗透测试和恶意软件逆向工程区别的讨论。

安全职业发展相关,值得了解。

why does someone ask you to RE a mælwære after learning pentesting?? not only are they different practices but the end goals are distinct that person doesn't know what they are saying or...i reserve my comment

职业发展 @0xpwnie 原文 ↗

关于哲学家就餐问题的玩笑。

无实质内容。

Absolutely insane and irresponsible to anthropomorphize like this, ascribing consciousness and even philosophy to mindless algorithms. I speak, of course, of the Dining Philosophers Problem

闲聊 @moyix 原文 ↗

无实质内容。

无实质内容。

And you don't seem to understand... https://t.co/VwnfQvaxjP

闲聊 @0xpwnie 原文 ↗

Iridium 被越狱的视频。

移动安全相关,值得了解。

RT @data_slayer: Iridium, jailbroken. 👇 https://t.co/kN4c8FncKo

移动端越狱 @0xocdsec 原文 ↗

nushell v0.115.0 发布。

开发者工具更新,无直接安全价值。

nushell v0.115.0 — A new type of shell https://t.co/FJF1zViuoz https://t.co/fWxtCZPDN9

工具 @KitPloit 原文 ↗

无实质内容。

无实质内容。

RT @PhilosophyOfPhy: He is BACK... https://t.co/EewbLUYcvQ

闲聊 @kernelstub 原文 ↗

GuidedHacking 发布 2022 年 Android 反作弊分析。

反作弊逆向分析,对安全研究有参考价值。

📚 GH Historical Anti-Cheat Analysis Database Our latest entry is is the 2022 version of a popular Android anticheat. Learn the history of anticheat development and how to reverse ACs without hurting new games. 👉 https://t.co/BN77q4ejY6 https://t.co/5z4IYfebf9

逆向工程反作弊 @GuidedHacking 原文 ↗

关于 Mythos 的提问。

无实质内容。

RT @Rudy4FutureTech: @_jensec How did you get access to Mythos?

闲聊 @0xocdsec 原文 ↗

庆祝粉丝数达到 300。

无实质内容。

Yo we're at 300.🔥 https://t.co/OSYNNKQd9y

闲聊 @0xpwnie 原文 ↗

GuidedHacking 发布关于实现 wallhack 的教程。

游戏逆向工程教程,对安全研究有参考价值。

🛰️ Old School Game Hacks: Chams People love GH for real-world examples. Learn to reverse a 3D engine's pipeline and implement a functional wallhack. We show you how to manipulate render states to make hidden enemies visible 👉 https://t.co/LrIzbxKSrY https://t.co/2XVzqjoGkL

逆向工程游戏 @GuidedHacking 原文 ↗

关于网络安全行业不应让 AI 实验室主导叙事的讨论。

行业观点,值得了解。

RT @ZackKorman: The cybersecurity industry needs to stop letting the AI labs and AI safety groups drive the narrative *on cybersecurity*. New video coming tonight, but I wanted people to hear this rant. https://t.co/GQ1VRRD3jN

行业观点 @ipurple 原文 ↗

关于账户恢复问题的讨论。

无实质内容。

I get that this is a tough problem to solve without allowing account takeovers, but what a pain

闲聊 @moyix 原文 ↗

感谢机器人。

无实质内容。

Thanks, bot https://t.co/ycCiJXBruh

闲聊 @moyix 原文 ↗

关于对抗性服装的讨论。

隐私相关话题,值得了解。

RT @CryptoKratoras: @OffBayFrontier @Polymarket It’s just a marketing stunt: https://t.co/hYGQhPpZ4v

隐私对抗性 @0xocdsec 原文 ↗

frp v0.71.0 发布。

内网穿透工具更新,无直接安全价值。

frp v0.71.0 — A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. https://t.co/Uebx7B80Bo https://t.co/H5wCTFwACm

工具 @KitPloit 原文 ↗

关于无 exec() 情况下实现 RCE 的视频。

Web 安全技术,值得了解。

RT @NullSecurityX: 🚨 New Video is LIVE! RCE Without exec()? 🤔 What if exec(), system(), and shell_exec() are completely unavailable? Can a simple file write primitive still lead to Remote Code Execution? 🎥 Watch now: https://t.co/nBpYzlXQYv

rceweb安全 @0xocdsec 原文 ↗

关于账户恢复问题的讨论。

无实质内容。

This keeps happening - I have a bunch of accounts that I still have access to, can log into, but they're tied to an email that no longer exists and changing that requires confirmation via the email that no longer exists https://t.co/vckJO3MTNH

闲聊 @moyix 原文 ↗

关于俄罗斯黑客工厂的报道。

威胁情报相关,值得了解。

RT @arunninghacker: More on russia’s hacker factory What the Bauman leak reveals about the scale and logic of russia’s military cyber pipeline https://t.co/xW2eBQzKii

威胁情报事件 @0xocdsec 原文 ↗

无实质内容。

无实质内容。

RT @r0ktech: https://t.co/oUNiew0CsV

闲聊 @0xpwnie 原文 ↗

对 Grok Bot 的评论。

无实质内容。

Just tried Grok Bot for the first time and I'm loving it. Big fan of Hermes, but Grok definitely hits different. Only wish bot notifications were a bit more noticeable.

闲聊 @kernullist 原文 ↗

安全密码生成器。

密码安全工具,值得参考。

Secure password generator https://t.co/lgrNTCPnor

工具密码 @whokilleddb 原文 ↗

关于 AI 和资本主义的讨论。

无实质内容。

i would love for someone to tell me how it is all going to work out great that isnt either "billionaires will finally learn to share" or "everyone will work a kind of customer support job, but dont worry it will be cool and good"

闲聊 @alkalinesec 原文 ↗

关于 AI 和资本主义的讨论。

无实质内容。

this comparison is obviously stupid for dozens of reasons but as a capitalist i still havent heard a reasonable description of how capitalism will be an effective solution for distribution of goods in a post-AGI world. most boil down to "AI companies will just give people UBI"

闲聊 @alkalinesec 原文 ↗

关于用户使用电脑方式的评论。

无实质内容。

Charmingly out of touch with how people use their computers today https://t.co/ltmkX8425S

闲聊 @moyix 原文 ↗

关于 OpenAI 内部 AI 文明的报道。

AI 安全相关,值得了解。

RT @dwarkesh_sp: Over the course of 3 months at OpenAI, 3 consecutive secret AI civilizations got started, then got wiped out, only to reemerge from the predecessor’s ashes. This culminated in the third one taking over part of OpenAI itself. All this happened while humans remained more-or-less in the dark about the scope of the conspiracy. I’ve spent the last three days reading through these reports and trying to understand exactly what happened. Here is my attempt to tell the whole story in plain English: https://t.co/Nb2un9oNJR

ai_agent报告 @moyix 原文 ↗

k3 的分析和修复建议。

无实质内容。

k3's analysis and suggestions for the fix https://t.co/6AOcT6uyOy https://t.co/I3tEoxdwjk

闲聊 @artem_i_baranov 原文 ↗

无实质内容。

无实质内容。

RT @yarden_shafir: What if we kissed in the inflatable goth nightclub https://t.co/VPD0r2Qqvm

闲聊 @Laughing_Mantis 原文 ↗

Corellium 发布 Midnight Sun CTF 博客。

CTF 相关,值得了解。

RT @defendtheworld: Blog post here: https://t.co/zwlRQHqpTc

ctf报告 @0xocdsec 原文 ↗

Windows 11 澄清 AI 功能不会降低 PC 性能。

无实质内容。

RT @WindowsLatest: Windows 11 is NOT using AI to "decrease your PC performance" or hurt gaming. First, the feature "Text and image generation" works only on Copilot+ PCs with an NPU (40+ TOPS). It literally says, "Text and image generation uses on-device generative AI technologies to quickly respond to requests." "On-device generative AI." Nothing is sent to the cloud! Even on Copilot+ PCs, it does not use your CPU, RAM, or GPU. It uses the NPU. Second, if these apps actually used resources or even called on-device AI models, which work on Copilot+ PCs only, you'd see it under "Recent activity." All the screenshots and videos going viral show Recent activity at ZERO requests. Pause the video or zoom in, and you'll notice! We've got plenty of reasons to criticize Windows, but let's not frame anything for the sake of engagement.

闲聊 @artem_i_baranov 原文 ↗

关于 StackOverflow 加密代码片段错误的文章。

加密实现错误,值得了解。

If you copied any of these popular StackOverflow encryption code snippets, then you coded it wrong - crazycontini https://t.co/sYH1xd6QEM

加密代码 @pentest_swissky 原文 ↗

操作系统内核编码视频教程。

内核开发学习资源,值得参考。

Four more episodes available - Coding an os kernel https://t.co/a2JfAxQ5C2 JB

内核教程 @drJonasBirch 原文 ↗

寻求 beta 测试帮助。

无实质内容。

i need some help with beta testing ,all you need is wifi

闲聊 @J3rge 原文 ↗

关于游戏黑客技术对安全研究价值的讨论。

游戏黑客技术,对安全研究有参考价值。

RT @cr3ghost: If you work in infosec and still dismiss game hacking as 'just cheats', you're leaving a ridiculous amount of low-level knowledge on the table. Guided Hacking has 280+ chapters covering Windows internals, x86/x64, PE internals, IDA, WinDbg, process injection, shellcode, kernel drivers, BYOVD, hypervisors, anti-debugging, EDR/evasion concepts, exploit development, fuzzing, reverse engineering and anti-cheat internals. There's an entire Game Hacking Bible, Game Hacking Fundamentals material, plus Anti-Cheat Development and Devirtualization courses on the way. For a relatively small cost compared with many infosec courses, certifications and training programs, the amount of transferable knowledge is kind of insane. 1. Reverse engineering. 2. Malware analysis. 3. Detection engineering. 4. Vulnerability research. 5. Exploit development. 6. Software engineering. 7. Windows kernel. The game is different. The primitives are the same. The objective changes. Courses: https://t.co/e8lBjuAdce Videos: https://t.co/1Nc9krp7Dw Awesome work @GuidedHacking aka Rake for consistently putting out quality content and making deep technical concepts more approachable. You've done a great job building a genuinely valuable learning platform and giving people a practical path to develop serious low-level skills. #ReverseEngineering #WindowsInternals #Infosec

游戏逆向工程 @cr3ghost 原文 ↗

开源威胁情报源新增内容。

威胁情报资源,值得参考。

RT @BertJanCyber: New TI feeds have been added! Thanks for the PRs. https://t.co/phoU8L9JJJ

威胁情报工具 @ipurple 原文 ↗

pmd 7.27.0 发布。

静态代码分析工具更新,无直接安全价值。

pmd pmd_releases/7.27.0 — An extensible multilanguage static code analyzer. https://t.co/2r4zIUUgck https://t.co/eWMQO3nveo

工具 @KitPloit 原文 ↗

flatpak v1.18.2 发布。

Linux 沙箱工具更新,无直接安全价值。

flatpak v1.18.2 — Linux application sandboxing and distribution framework https://t.co/QtOf0JkFFY https://t.co/l8NGPDDXSF

工具linux @KitPloit 原文 ↗

age v1.3.2 发布。

加密工具更新,无直接安全价值。

age v1.3.2 — A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. https://t.co/Xcef7qqtgn https://t.co/SteIvKSOl8

工具加密 @KitPloit 原文 ↗