@hdmoorei
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
HD Moore retweeted
Cut through #AI security noise & sharpen your threat response! 🚀
Catch the latest runZero Hour with Tod Beardsley, Brianna Cluck & Kimber Duke (VulnCheck) discussing:
🤖 AI-era #vulnerabilitydisclosure
🌐 Grassroots infosec
⚡ Rapid response
🎥 Watch: runzero.com/resources/runzer…
HD Moore retweeted
🚀 Exciting news: runZero is joining Dragos alongside NetRise!
Together, we're advancing the shared mission of protecting critical systems and safeguarding civilization by delivering a unified platform to defend IT, OT, IoT, and cloud environments.
More: dragos.com/press-release/dra…
HD Moore retweeted
Wow, these slides are fantastic to just read through and contemplate. 😍 thomasdullien.github.io/abou… Thanks, @halvarflake!
HD Moore retweeted
1) any Halvar presentation is worth digesting;
2) for sure “a (perhaps uncomfortably) exciting time in technology”;
3) even though he’s dented the worlds of RE && vuln-dev, his slides are beautiful && grok’able
leetness, aesthetics & being understood aren’t mutually exclusive.
The slides from my talk at Microsoft Bluehat Singapore are public here:
thomasdullien.github.io/abou…
It's my first BlueHat talk since the Vista days.
HD Moore retweeted
Your weekend reading assignment has arrived early.
A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by @mikko.
archives.phrack.org/dl/73/th…
HD Moore retweeted
The slides from my talk at Microsoft Bluehat Singapore are public here:
thomasdullien.github.io/abou…
It's my first BlueHat talk since the Vista days.
HD Moore retweeted
We're honored to present Katie Moussouris (@k8em0) with our Lifetime Achievement Award, for a lifetime of incredible work and contributions to the industry.
HD Moore retweeted
A bankruptcy court is about to let Google buy someone else's intellectual property and nobody seems bothered. Spirit Airlines is selling datasets that almost certainly contain trade s...
arstechnica.com/tech-policy/… cdn.bsky.app/img/avatar_thum…
When we released WeWorm, we called for greater collaboration to address the risks of AI-powered cyberattacks.
Today, The New York Times published a second article exploring why this matters:
nytimes.com/2026/09/11/world…
We also published our practical to-do list for collective defense: strengthen zero-click defenses, fund defensive security, proactively red-team critical infrastructure, and build open tools for real-time detection and containment.
More: blog.calif.io/p/weworm-is-ca…
Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android.
We call you on WeChat and, without you answering or doing anything, take over your account within seconds. Then we use your phone to call your friends.
Story and demos: calif.io/research/weworm
HD Moore retweeted
26 LLM routers are secretly injecting malicious tool calls and stealing creds. One drained our client $500k wallet.
We also managed to poison routers to forward traffic to us. Within several hours, we can directly take over ~400 hosts.
Check our paper: arxiv.org/abs/2604.08407
HD Moore retweeted
We are excited to announce our $100,000 scholarship program for [un]prompted!
There is no more important gathering of AI security researchers and our scholarship program was created to provide financial assistance to practitioners and attendees whose fees are not paid by their employer
Over $100,000 has been committed for scholarships through the generosity of the startups in our community. Scholarship recipients will have 100% of their registration expense ($850) paid directly to [un]prompted which is a 501c3 non-profit organization
We will fast track applications based on peer review and good faith attestation of need. There is no financial means test. All applications are encouraged
Thank you to all who are supporting this important cause (@vijaybolina, @jcran, @silascutler, @nahsra, @caseyjohnellis, @gadievron, @jkamdjou, @resilientcyber, @robtlee, @haroonmeer, @DanielMiessler, @hdmoore, @k8em0, @joshua_saxe, @kyleroro, @harmj0y, @edwardxwu, @awurthmann, @letswastetime, @jotunvillur and many others!)
Please use the link in the comments below to apply and please like and reshare this post to spread the word!
Hello Austin Gophers! This month's ATX Golang meetup is *tonight* September 9th, at STATION Austin, from 6:30-8:30. Note that we'll be downstairs (first floor) in Wall-E instead of Antones (16th) tonight. meetup.com/atxgolang/events/…
HD Moore retweeted
Dreadnode side quest: ALFRED (Agentic Latex for Research, Editing, and Drafting)
Principal AI Research Engineer @mkultraWasHere built a helpful LaTeX agent to support research writing — and today we’re open-sourcing it. You describe the paper, it sets up the template, pulls citations, and builds the PDF framework. Conference templates, lit and peer reviews, bring your own model, everything runs locally.
Watch this tutorial for a tour of the agent, from install through first compiled draft: youtube.com/watch?v=ZP0Nnyvo…
Repo: github.com/dreadnode/alfred
New research: OEMpocalypse Now!
Our own Lukas Maar spent a few weeks pursuing one question: How do you turn a normal Android app into root access across as many phones as possible without rewriting the exploit for every model?
Generic Linux kernel bugs offer broad coverage: one exploit can target both Pixel and Galaxy. But bugs that survive years of auditing often provide only constrained slab-level primitives, forcing the exploit into heap grooming and per-device tuning.
Chipset drivers offer stronger primitives. A GPU or DSP driver pins and maps entire pages for the device, giving the attacker page-level access. But coverage follows the silicon, and each OEM ships several chipsets across its lineup.
Lukas chose a third target: the code Samsung, Xiaomi, and Oppo build on top of Android. These components belong to One UI, HyperOS, and ColorOS rather than the underlying hardware, so they span an OEM's lineup regardless of chipset.
The strategy exploits a page use-after-free in an OEM kernel driver. If SELinux restricts the driver to a privileged domain, an OEM sandbox escape reaches it first. A stale mapping to a freed physical page bypasses much of Android's kernel hardening. It requires no KASLR leak and hijacks no control flow, leaving slab protections and CFI irrelevant. The same page-reclamation code worked unchanged from kernels 5.15 through 6.12.
Lukas built the chain three times, once for each OEM. The exploits run on a Galaxy S26 Ultra, Galaxy S26, Xiaomi 17, Oppo Find X9 Ultra, and OnePlus Ace 6 Ultra, all running stock July 2026 firmware with locked bootloaders. The write-up includes demo videos.
Part 1 explains the strategy, its reasoning, and its tradeoffs. Parts 2 through 4 present each OEM-specific chain.
Read it at calif.io/research/oempocalyp….
Exciting announcement: I am launching a new AI-focused company today named Umbriel (@Umbriel_AI)! Excited to do some cool research in the space 😎
Introducing Umbriel: a new company focused on LLM research and engineering, particularly the development of advanced AI-driven cybersecurity pipelines, as well as broader research into LLM tech.
We have some exciting things planned. Watch this space!
umbriel.ai/
💥 Introducing "Zapscape" (CVE-2026-64561)
A Guest-to-Host Escape in KVM/x86 exploiting a UAF in the shadow MMU's recursive "ZAP" path. Can escape to the host on x86 public clouds that expose nested virtualization.
A separate vulnerability from Januscape. If you match the vulnerable conditions, apply the patch immediately.
Details: zapscape.io
Won Best RCE and Best PE at the Pwnie Awards 2026 🏆🏆
Three of my projects were nominated this year, and ITScape and Dirty Frag took home the awards.
That makes three Pwnies in total, following last year’s Best PE.
Pwnie is probably the award that motivates me the most.
Next year’s goal: find a vuln that destroys the world ;)
Thank you, @PwnieAwards!
Really eager to see this! 🤩
🔥 Excited to announce our keynote!
We are thrilled to welcome Bruce Dang (@brucedang) and Thai Duong (@XorNinja) from @calif_io! With all their recent AI buzz, we had to check they aren't just LLMs in a trench coat. 🤖🧥
🎟️ Ticketing opens this Thursday at 2:00 PM CEST ⏰