@AlAssaf_H

Offensive security research. Assembly, C, C++, Rust. Binary analysis, exploit development, complex adaptive systems. IA32_LSTAR

Riyadh, Saudi Arabia 🇸🇦
Joined January 2015
Pinned Tweet
JIT code can be freed while the CPU still remembers an old indirect-branch target. Branch Target Reuse (BTR) turns that stale predictor state into a speculative execute-after-free: when the code cache reuses the region, speculation can jump to an obsolete offset in the new code. VUSec demonstrated it in Linux cBPF, SpiderMonkey and GraalVM. Their cBPF exploit leaks arbitrary kernel memory at ~8 B/s. In SpiderMonkey, BTR reaches speculative arbitrary code execution; no end-to-end browser exploit was demonstrated. vusec.net/projects/btr/
5
14
2
46
102,335
Huda retweeted
AgentCorruption: 1 prompt used an AgentCore HTTP tool to leak MMDS creds. Broad IAM rights enabled cross-agent access, private chat reads and memory poisoning in one AWS account/region. AWS enforced MMDSv2 and narrowed default roles before publication. labs.zenity.io/post/agentcor…
6
104
1,725
Huda retweeted
🕷️
7
19
12,373
AgentCorruption: 1 prompt used an AgentCore HTTP tool to leak MMDS creds. Broad IAM rights enabled cross-agent access, private chat reads and memory poisoning in one AWS account/region. AWS enforced MMDSv2 and narrowed default roles before publication. labs.zenity.io/post/agentcor…
6
104
1,725
Huda retweeted
Linux CVE-2026-72018: a constrained 16-byte zero write in SMC-D loopback. XBOW used it against `cred` for LPE, without an infoleak. Requires CAP_NET_ADMIN. Lab result: 22/100 boots, kernel mitigations disabled. xbow.com/blog/no-time-to-pwn…
8
1
39
1,565
Huda retweeted
Ghostscript CVE-2026-101258: `-dSAFER` bypass via a memory-corruption chain. UAF leak → Type 5 shading OOB write/read → `path_control_active = 0` → `%pipe%` execution. The PoC is build- and architecture-sensitive. github.com/v12-security/pocs…
1
9
39
2,677
Huda retweeted
Shannon starts with the source, not the scanner. It maps attack paths from the codebase, then tests them against the live application. If the exploit cannot be reproduced, it doesn’t become a finding. github.com/KeygraphHQ/shanno…
1
9
29
1,835
Huda retweeted
What can the attacker control—and what does the evidence actually prove? The Anatomy of a Trust Boundary traces the path from reachable code to broken invariants—and the evidence required to demonstrate impact.
3
7
1
129
5,053
What can the attacker control—and what does the evidence actually prove? The Anatomy of a Trust Boundary traces the path from reachable code to broken invariants—and the evidence required to demonstrate impact.
3
7
1
129
5,053
Linux CVE-2026-72018: a constrained 16-byte zero write in SMC-D loopback. XBOW used it against `cred` for LPE, without an infoleak. Requires CAP_NET_ADMIN. Lab result: 22/100 boots, kernel mitigations disabled. xbow.com/blog/no-time-to-pwn…
8
1
39
1,565
Ghostscript CVE-2026-101258: `-dSAFER` bypass via a memory-corruption chain. UAF leak → Type 5 shading OOB write/read → `path_control_active = 0` → `%pipe%` execution. The PoC is build- and architecture-sensitive. github.com/v12-security/pocs…
1
9
39
2,677
Awesome AI Pentesting Autonomous AI Pentesting Agents MCP Servers for Security Vulnerability Analysis & Scanning CTF Solvers & Challenge Tools OSINT with AI and more. github.com/skyvanguard/aweso… Tip by @AlAssaf_H
2
5
26
2,599
Shannon starts with the source, not the scanner. It maps attack paths from the codebase, then tests them against the live application. If the exploit cannot be reproduced, it doesn’t become a finding. github.com/KeygraphHQ/shanno…
1
9
29
1,835
Huda retweeted
DIVD breach: two Zammad 0-days chained by an agentic attacker. CVE-2026-102489: session hijack → RCE as zammad Affected: 6.3.0–6.5.4. Present in 7.0.0–7.1.3, but not practically exploitable under their runtime environment. CVE-2026-102490: local zammad user → root. LPE alone; chained with 102489: session compromise → RCE → privesc → root DIVD says the chain reached root in seconds. Incident: csirt.divd.nl/cases/DIVD-202…
2
10
11
1,103
Huda retweeted
JIT code can be freed while the CPU still remembers an old indirect-branch target. Branch Target Reuse (BTR) turns that stale predictor state into a speculative execute-after-free: when the code cache reuses the region, speculation can jump to an obsolete offset in the new code. VUSec demonstrated it in Linux cBPF, SpiderMonkey and GraalVM. Their cBPF exploit leaks arbitrary kernel memory at ~8 B/s. In SpiderMonkey, BTR reaches speculative arbitrary code execution; no end-to-end browser exploit was demonstrated. vusec.net/projects/btr/
5
14
2
46
102,335
DIVD breach: two Zammad 0-days chained by an agentic attacker. CVE-2026-102489: session hijack → RCE as zammad Affected: 6.3.0–6.5.4. Present in 7.0.0–7.1.3, but not practically exploitable under their runtime environment. CVE-2026-102490: local zammad user → root. LPE alone; chained with 102489: session compromise → RCE → privesc → root DIVD says the chain reached root in seconds. Incident: csirt.divd.nl/cases/DIVD-202…
2
10
11
1,103
🕷️
7
19
12,373
Huda retweeted
KEX-bench: 45 kernel exploitation tasks with primitive-level verification. crash != pass. Without a reference PoC, the strongest configuration solves 14/25 Linux and 1/20 Windows tasks. With a reference PoC: 31/45. The gap is not finding a crash. It is shaping kernel state into a leak, IP control, heap write, or arbitrary-address write. arxiv.org/abs/2609.25591
8
11
523
Huda retweeted
CREE // ᐁᐃᐊᐅᐄᐋᐆᐗᐒ ᐁ='',ᐃ=!ᐁ+ᐁ,ᐊ=!ᐃ+ᐁ,ᐅ=ᐁ+{},ᐄ=ᐃ[ᐁ++],ᐋ=ᐃ[ᐆ=ᐁ],ᐗ=++ᐆ+ᐁ,ᐒ=ᐅ[ᐆ+ᐗ],ᐃ[ᐒ+=ᐅ[ᐁ]+(ᐃ.ᐊ+ᐅ)[ᐁ]+ᐊ[ᐗ]+ᐄ+ᐋ+ᐃ[ᐆ]+ᐒ+ᐄ+ᐅ[ᐁ]+ᐋ][ᐒ](ᐊ[ᐁ]+ᐊ[ᐆ]+ᐃ[ᐗ]+ᐋ+ᐄ+"(ᐁ)")()
3
7
150