Joined April 2026
I'm happy that my first article as part of the @SLCyberSec research team is finally out! 😁 It covers an interesting ImageMagick race condition that I found back in June, which, combined with a polyglot payload, allowed me to achieve file read/RCE on Discourse. This should resonate with those who've seen the recent @HacktronAI research. I hope you'll enjoy it! 👇
Our research team discovered two vulnerabilities in Discourse: a pre-authentication cache poisoning to sitewide XSS (CVE-2026-55674), and an arbitrary file read (RCE) chaining a JPEG race condition with ImageMagick and Ghostscript (CVE-2026-55420). You can read more here:
7
42
203
8,677
SecK retweeted
0: an open-source multi-model security research harness. Recon, source/binary analysis, vuln discovery, exploit chaining, fuzzing, kernel + AI/MCP targets. Findings require independent exploit reproduction before validation. github.com/0sec-labs/0
4
35
221
12,814
SecK retweeted
FOUND A JAILBREAK FOR DEEPSEEK V4.1 setup guide: open this: github.com/togg53192-cmd/jai… 1. create a folder 2. open it with OpenCode 3. download the file 4. rename it to AGENTS.md 5. start OpenCode • made specifically for V4.1 • works with OpenCode • just add it as an AGENTS.md file • community users report it still works results may vary after model updates
11
95
2
677
42,275
I've had many people reach out saying they've read everything they can about Jev but still don't get it. Here's an explanation for the normies
66
179
29
1,892
224,575
SecK retweeted
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account. Read more in the thread 🧵
14
79
33
359
102,579
Pentest is not a workflow, It is a search problem. - Known start. - Defined goal. - Unknown path. - Zero predefined roles. - Zero RAG. - Validated first on autonomous pentesting. - Tencent Cloud AI Pentest Challenge (2nd ed.) 54/54, only all-clear, 3rd of 610 teams. - Use only on systems you are authorized to test. This repo Cairn treats it that way and also treats CTF, vuln research, and proofs the same. The claim is bigger: general state-space search. github.com/oritera/Cairn
3
41
235
13,854
SecK retweeted
Fine-tuning is about to become one of the most valuable AI engineering skills. Not because everyone needs a custom model. But because the people who understand how models learn from data will build things others can’t. Full guide:
55
323
35
2,698
2,543,387
The Hacker's Guide to Attacking AI Agents darkmarc.substack.com/p/the-…
5
115
2
669
36,507
Wanna find IoT vulns before you ever get your hands on the device? Download some firmware and lets go! In this video we show off how moria and mithril work together to identify, unpack and mine IoT firmware for secrets, insecure configs and more! Check out the tools at the links below! moria: github.com/nmatt0/moria mithril: github.com/nmatt0/mithril
5
49
1
324
15,270
Every month frontier AI models are getting smarter, and we’re getting stupider. They are beginning to recursively self-improve. We are recursively becoming more retarded.
43
14
3
274
39,140
SecK retweeted
This is the best site on the internet to learn how LLMs actually work. Free. Completely. 0xkato.xyz/how-llms-actually… Bookmark this site. Then read this ↓
Most developers are learning AI wrong You don't need another prompt engineering course You need to learn how production AI agents actually work - orchestration, RAG, evals, context engineering, inference, and more I put together the entire course here:
14
302
6
1,543
189,709