SecK retweeted
Whoever created this, huge respect.
webhacklist.com/
SecK retweeted
I'm happy that my first article as part of the @SLCyberSec research team is finally out! 😁
It covers an interesting ImageMagick race condition that I found back in June, which, combined with a polyglot payload, allowed me to achieve file read/RCE on Discourse. This should resonate with those who've seen the recent @HacktronAI research.
I hope you'll enjoy it! 👇
SecK retweeted
new era site for reading top bug bounty writeups
webhacklist.com/#museum
SecK retweeted
enjoy all
github.com/mdpsec/bug-bounty…
SecK retweeted
0: an open-source multi-model security research harness.
Recon, source/binary analysis, vuln discovery, exploit chaining, fuzzing, kernel + AI/MCP targets.
Findings require independent exploit reproduction before validation.
github.com/0sec-labs/0
FOUND A JAILBREAK FOR DEEPSEEK V4.1
setup guide:
open this: github.com/togg53192-cmd/jai…
1. create a folder
2. open it with OpenCode
3. download the file
4. rename it to AGENTS.md
5. start OpenCode
• made specifically for V4.1
• works with OpenCode
• just add it as an AGENTS.md file
• community users report it still works
results may vary after model updates
SecK retweeted
I've had many people reach out saying they've read everything they can about Jev but still don't get it. Here's an explanation for the normies
SecK retweeted
Today, @washingtonpost covered critical vulnerabilities @depthfirstlabs found in TikTok. These vulnerabilities allowed hackers to access anything on a user’s device that TikTok itself could access, including the camera, microphone, payment information, photos, and the user’s entire TikTok account.
Read more in the thread 🧵
SecK retweeted
Pentest is not a workflow, It is a search problem.
- Known start.
- Defined goal.
- Unknown path.
- Zero predefined roles.
- Zero RAG.
- Validated first on autonomous pentesting.
- Tencent Cloud AI Pentest Challenge (2nd ed.) 54/54, only all-clear, 3rd of 610 teams.
- Use only on systems you are authorized to test.
This repo Cairn treats it that way and also treats CTF, vuln research, and proofs the same.
The claim is bigger: general state-space search.
github.com/oritera/Cairn
SecK retweeted
Cache key injection: Smuggling poison through the door yeswehack.com/lab/research-c…
SecK retweeted
Fine-tuning is about to become one of the most valuable AI engineering skills.
Not because everyone needs a custom model.
But because the people who understand how models learn from data will build things others can’t.
Full guide:
SecK retweeted
Good series on Pwning AI Agents
Part 1: Exploiting AI Coding Agents m10x.de/posts/2026/04/pwning…
Part 2: RCE and Data Exfiltration m10x.de/posts/2026/06/pwning…
Part 3: Read Only Bypass m10x.de/posts/2026/07/pwning…
Part 4: Exploiting MCP Hosts with a Malicious MCP Server m10x.de/posts/2026/08/pwning…
SecK retweeted
The Hacker's Guide to Attacking AI Agents darkmarc.substack.com/p/the-…
SecK retweeted
Wanna find IoT vulns before you ever get your hands on the device?
Download some firmware and lets go!
In this video we show off how moria and mithril work together to identify, unpack and mine IoT firmware for secrets, insecure configs and more!
Check out the tools at the links below!
moria: github.com/nmatt0/moria
mithril: github.com/nmatt0/mithril
SecK retweeted
Every month frontier AI models are getting smarter, and we’re getting stupider.
They are beginning to recursively self-improve. We are recursively becoming more retarded.
SecK retweeted
$15k - CSPT to full account takeover, then 2FA bypass via the prototype chain - @whoareme33
whoareme.com/blog/cspt-accou…
SecK retweeted
This is the best site on the internet to learn how LLMs actually work.
Free. Completely.
0xkato.xyz/how-llms-actually…
Bookmark this site.
Then read this ↓