@efaavi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Hacker & Developer. Hunting bugs. Building https://nitter.cf/t.co/qiMEJOTD1H & NameMC Extras.
Florida
Joined November 2024
- Tweets532
- Following240
- Followers5.6K
- Likes3.4K
this is me btw 👋
‼️ BREAKING: A 16-year-old hacker broke into an internal Microsoft analytics service with a forged, unsigned login token and ran SQL as admin, reaching databases that held over 17 trillion rows, including Bing search analytics and 17,990 employee email records.
The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav.
He says he only pulled metadata and two single rows of Bing data, never touched customer data, and reported the flaw to Microsoft the same night.
Microsoft locked the endpoint four days later, paid him $5,000, and had editorial control over his write-up, cutting sections and figures and reshaping how the impact was described before it went public.
Faav retweeted
‼️BREAKING: An actively exploited unknown critical Citrix NetScaler zero-day has prompted governments and organizations to SHUTDOWN all their devices immediately.
We don't know what's exactly going on yet. Stay tuned for more info.
Faav retweeted
one of my engineers reached out to me about how they struggled to find satisfaction in their work in the age of AI. I asked them if I could publish our brief exchange, and they agreed. I know people are feeling similarly, so maybe they can relate. shubs.io/do-we-still-enjoy-s…
Faav retweeted
A malicious Twitch chat message can trigger code execution in OBS Studio.
The attack targets OBS Studio and custom Twitch chat overlays (Browser Sources) that insert unsanitized chat directly into the page and can execute JS within the overlay.
cyberinsider.com/malicious-t…
Readers added context they thought people might want to know
Chat alone can’t hack OBS.
The proof of concept needed a custom overlay that rendered messages as unsafe HTML, plus a flaw in OBS 32.2.2’s built-in browser. It doesn’t show Streamlabs or StreamElements are vulnerable. OBS has merged a browser update for 33.0.
blog.scrt.ch/2026/09/22/how…
github.com/obsproject/obs…
Faav retweeted
Replying to @Masonhck3571
despite the stuff they DIDNT let him disclose, just leaking bing searches of people could ruin careers and marriages of thousands of people
How I Could've Accessed 17 Trillion Microsoft Records
blog.faav.net/how-i-couldve-… :)
Shoutout to @samwcyo, @pgp, @0daystolive, @davi1337_, @p0psec, @_bughunter, @jkbrah, @javoriuski, @xssdoctor, @rez0__, @Rhynorater and others for keeping me motivated or giving feedback on the blog 🤝
Faav retweeted
We just published two blog posts about PageBreak, Google's AI web security scanner (that I've helped develop for the better part of the year). We share our approach and a couple of findings, enjoy!
- blog.google/security/agentic…
- bughunters.google.com/blog/p…
Faav retweeted
📢📢📢 Attention bug hunters!
Want to know more about how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage?
If yes, check out his blog post 👇
bughunters.google.com/blog/b…
i hate security disclosure so much. the number of companies that take our work for granted is insane. how about you talk to us collaboratively from the start instead of being asinine about it?
like, give us some respect, bro. we worked on this shit for weeks/months and showed you something that could have become a massive disaster if a bad guy finds it, and you don’t even seem to give a fuck and see us like some villains?
Faav retweeted
Another 0-Click ATO in Meta's AI Systems!
I recently discovered a critical vulnerability in @Muse leading to a 0-Click Full Account Takeover (ATO) on @facebook, @instagram & @Meta.
This places me in the Top 5 on Meta's Bug Bounty Leaderboard.
Thanks to the @metabugbounty Team.
Faav retweeted
I bought a Fable dataset from one of the top Chinese LLM routers yesterday.
With just 6TB data, I can take over 7 Chinese/CIS gov entities & 19 top Chinese firms like Xiaomi, Huawei, NIO, Minimax using SSH keys, VPN configs, Aliyun keys, GitLab tokens sent to the router.
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.
We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.
Check our paper: arxiv.org/abs/2604.08407
Faav retweeted
Replying to @SLCyberSec
@SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products including Zendesk and Nuclei 😉
read the whole writeup here: searchlight-web-new.webflow.…
and watch Nuclei getting pwned with a template file here 👇🏻
Faav retweeted
(A)I reverse engineered Burp's project format and made a tool to extract proxy history, Repeater tabs, and Site map from project files. I've always wanted to do this.
parsiya.net/blog/burp-projec…