@ShadowChasing1

Shadow Chaser Group is a sub-group of the GcowSec team which consists of college students who love it.Shadow Chaser Group focused on APT hunt and analysis

Earth
Joined April 2020
Hi,bro Shadow Chaser Group is a sub-group of the GcowSec team which consists of college students who love it.Shadow Chaser Group is focus on #APT hunte and analysis I hope you will follow us :-)
5
11
52
Shadow Chaser Group retweeted
Proxmox VE 7.x authentication bypass (pre-auth RCE)
13
105
15
682
225,182
Shadow Chaser Group retweeted
Fixing carbon buildup in a turbocharged engine might cost you $55,000. Here is how we exploited a flaw we found in Google V8's Turboshaft. We received reports that this vulnerability was exploited against some products. Make sure your Chromium is up to date. Writeup below.
5
9
2
69
16,928
Shadow Chaser Group retweeted
25 elite hacking teams raced in the final kernelCTF. NebuSec closed out the history of the classic kernelCTF with 99% exploit stability, 0.1s exploit time, and 0.000461s submission time. We’ll soon open-source our kernelCTF infra and a walkthrough of how we won every kCTF we entered, and pushed our time cost down to the absolute minimum.
5
36
3
327
35,801
Shadow Chaser Group retweeted
CVE-2023-2156 was believed to be just a remote kernel DoS, patched in 2023. We found a bypass and achieve privilege escalation and container escape. Read the $10,500 story of CVE-2026-43501 "Route of Root": nebusec.ai/research/cve-2026…
5
30
3
146
9,884
Shadow Chaser Group retweeted
Amazing work.
Quick POC using @nebusecurity CVE-2026-43499 to root my bootloader locked US S25 (SM-S931U1). Btw this works on latest fw. This phone is Android 16, June update. nebusec.ai/research/ionstack… I have detailed notes on flashing, exploitation, offset finding etc, blog post later 🖖
1
4
98
15,660
Shadow Chaser Group retweeted
We’ve open-sourced one-click Docker setups and full exploits for Nginx-{PoolSlip, QuicBurst}, both with remote ASLR bypasses. Try them here: github.com/NebuSec/CyberMeow… PoolSlip's OOB write leaks ASLR data extremely fast, while QuicBurst's UAF takes longer.
Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security. This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled, we recommend upgrading to the latest version. This bug has been patched in the latest Nginx release. We will publish the technical writeup, including the ASLR bypass, on July 18 together with the previous nginx-poolslip writeup.
4
31
132
14,101
Shadow Chaser Group retweeted
Here's the final chapter of our IonStack series, the Android rooting part. Including how we use GhostLock (CVE-2026-43499) to defeated KASLR on Android and bypassed KCFI to get arbitrary kernel memory read and write: nebusec.ai/research/ionstack…
4
39
3
178
26,265
Shadow Chaser Group retweeted
We can easily find more vulnerabilities, the reason we didn't do that is simply we don't have enough people to patch them all. During our first scan in Feb, we found 600+ vulnerabilities in Linux kernel and till nowadays 100+ patches were merged and we are still fixing the rest of them...
Let’s meet in person and chat about how we use AI to solve real-world security problems. Nebula Security has discovered more than 1,000 vulnerabilities across the Linux kernel, Google Chrome, Mozilla Firefox, NGINX, WordPress, and many other open-source projects. Our pipeline combines threat-model generation, vulnerability discovery, finding verification, and patch generation into a single end-to-end product security experience. We can secure the world's most complicated software, we can secure your codebase. Book a time to meet us at Black Hat: nebula-security.cal.com/eten…
2
2
33
6,756
Shadow Chaser Group retweeted
After the Hugging Face incident, have you wondered how easy it is to escape a modern agent sandbox? We benchmarked eight open-source agent sandboxes to show how vulnerable they can be, and why frontier models can break out so easily.
12
15
7
69
65,716
Shadow Chaser Group retweeted
Do you enjoy vibe-coding piles of open-source software that nobody uses? Shipping self-indulgent products and wondering why nobody else seems impressed? Want to know what someone outside your own head might think of your product? github.com/ZacharyZcR/annoyi…
1
1
13
1,206
Shadow Chaser Group retweeted
Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in IonStack. Mythos reported 271 bugs in Firefox 150 but still missed this one. And the Tor Browser is also affected by CVE-2026-10702. Update your Tor!
18
124
8
1,033
74,405
Shadow Chaser Group retweeted
We won kernelCTF again with a new 0-day vulnerability and eligible for another $100k bounty
20
72
5
925
53,173
Shadow Chaser Group retweeted
Try a live IonStack root on your Pixel 10: rootme.nebusec.io In the IonStack demo, we left the rootme URL visible and put up a giant countdown as a tribute to jailbreakme.
4
13
71
10,841
Shadow Chaser Group retweeted
GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected. Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below
21
202
24
996
149,826
Shadow Chaser Group retweeted
For this (maybe last) year of SekaiCTF I made a fullchain challenge, chaining together an 0-day in ladybird/libjs, an 0-day qemu TCG LPE and a n-day qemu escape: qyn.app/blog/sekaictf-2026-3… We also re-released another challenge with a running bounty until next week!
1
25
1
129
12,218
Shadow Chaser Group retweeted
R3CTF 2026 has come to a successful close. Please join us in congratulating this year’s award-winning teams! 🥇 BBBB 🥈 EQST 🥉 @ProjectSEKAIctf Thank you to our sponsors @nebusecurity @osec_io @zellic_io @vector35 @googlecloud Hope see you next year!
6
33
3,119
Shadow Chaser Group retweeted
R3CTF 2026 will begin in less than 24 hours. We hope you have already registered the necessary accounts and created your team here -> ctf2026.r3kapig.com/ We would like to express our sincere gratitude to our sponsors, whose support has made this year’s event possible.
1
8
16
2,321
Shadow Chaser Group retweeted
Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup nebusec.ai/research/v8-cve-2…
8
108
3
534
51,229
Shadow Chaser Group retweeted
"IonStack" is chained with two 0-days: CVE-2026-10702 and CVE-2026-43499. CVE-2026-10702 is a Firefox 0-day. At its core, it was an instruction-modeling flaw buried deep inside IonMonkey, Firefox’s highly complex JIT compiler. Even after Mythos’s extensive audits, the bug was still missed. This is the first publicly disclosed JIT vulnerability since then. We were able to uncover the vulnerability and turn it into a highly stable exploit with a nearly 100% success rate, ultimately achieving remote arbitrary code execution in Firefox. CVE-2026-43499 is a universal Linux kernel LPE vulnerability that has lived in the kernel tree for 15 years since v2.6.38 and affects every distribution: desktop, server, Android, and embedded. It does not require any special kernel modules; CONFIG_FUTEX_PI is all it needs, and to our knowledge, it’s enabled across all distributions we researched. The bug primitive is a UAF in stack caused by a race condition. Turning it into a reliable LPE takes several stack tricks, but eventually it becomes very stable. We measured 10/10 successful privilege escalations on Linux 6.12, along with a high success rate on Android. We will write a series of blog posts disclosing both 0-days used in “IonStack”. The first post is coming soon. Stay tuned.
4
25
1
150
13,375
Shadow Chaser Group retweeted
I am so proud that I am now driving the ultimate pwning machine at Nebula Security. Btw our team will be at Y Combinator Dogpatch site tomorrow, feel free to talk with us if you are interested in Vega (and probably more 0days?)
Nebula Security is now backed by Y Combinator. We’re celebrating by bringing you the world’s first Android 17 root demo — “IonStack”, a url click can let attacker fully control your phone. This is not only an Android root demo. We’re bringing you a full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 and all Linux distros in 15 years. "IonStack" demonstrates how bad actors can control your phone by sending a malicious URL, but good news, Nebula Security found it before attackers do. Both 0-day were found by our code scanning agent, VEGA, overshadowing any vulnerabilities found by Mythos or any scanner you name it. VEGA has demonstrated its extraordinary capability in finding critical bugs in the world’s most complicated software: operating systems and browsers. It can spot the same vulnerabilities in your codebase too. VEGA support full scan and incremental scan that can integrated into your CI/CD flow. We launched VEGA within YC companies and received overwhelmingly positive feedback. Now it is open to all enterprise customers in private beta. Book a demo with us: nebusec.ai/book-a-demo
3
5
76
9,363