Joined January 2024
Hiçbir şey, bedava verilenden daha pahalı değildir. Söylenmeyen Tarz, Michihiro Matsumoto, 1988
1,125
mdkfkfm dkkfkdkd retweeted
Since it's already public from calif.io - WhatsApp → QuickLook ext → PDFKit → PaperKit → PDFKit → CoreGraphics (aa_cache_render) Reachable from a crafted PDF/font via the ImageIO/thumbnail path (QuickLook/sips).
⚡️ 0-Day Alert: Apple CoreGraphics RCE exploited in targeted attacks CVE-2026-86950: out-of-bounds write in CoreGraphics parsing a maliciously crafted image/PDF, leading to arbitrary code execution. Both iOS and macOS are vulnerable. This AV is reachable through a wide variety of iOS native and 3rd party apps that render graphics, such as WhatsApp (first suspect due to report credit), Safari, iMessage, etc. Zero-click where auto-preview renders the file. However, the bug alone is not enough to compromise the device, and requires further chaining such as sandbox escape and EoP. These further bugs are not public. Patched in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1. intelligence.zerodayengineer…
2
28
1
238
19,345
mdkfkfm dkkfkdkd retweeted
This weekend’s project: DPDK + WireGuard 🤓 I wired wireguard-go up to my packetio library and got a single tunnel to ~30M pps clean, peaking 40M. That’s 70× what kernel WireGuard can do! Wrote it all up here if you’re into that kind of thing: toonk.io/wireguard-dpdk/
3
12
94
3,925
mdkfkfm dkkfkdkd retweeted
🗞️For years you needed a jailbroken iPhone to decrypt iOS apps. That’s the part that just moved. Full IPA decrypt. No physical iPhone. No jailbreak🔥 onejailbreak.com/blog/fairpl…
15
103
4
1,274
103,052
mdkfkfm dkkfkdkd retweeted
THE GREATEST TRICK FAIRPLAY EVER PULLED WAS CONVINCING PEOPLE IT WAS NECESSARY. Full IPA decryption. No physical iPhone. We used to rely on an emulated FairPlay "device" in vPhone. Now we don’t even need that. And just like that…
27
73
3
1,481
86,676
mdkfkfm dkkfkdkd retweeted
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
61
219
99
1,979
368,644
mdkfkfm dkkfkdkd retweeted
Dont be sleeping on Heif Heist! Meta paid 100k for my RCE on FB/Instagram! heif-heist.com/
105
210
33
4,965
529,782
mdkfkfm dkkfkdkd retweeted
Okula CNC makinası aldık. Virüsten dolayı format atmak zorunda kaldık ve sorun yaşadık makinayı kuran firma ile iletişim kurmak istedik üsluba bakın makinayı yeni alacaksan rica minnet ederler. Burada paylaşıyorum ki @robotürk firması ile alış veriş yapmayın. Bunu nereye şikayet edebiliriz.
632
1,216
35
14,440
1,463,104
mdkfkfm dkkfkdkd retweeted
daha önce paylaşmıştım ama yine paylaşayım. bu durumda teknik olarak hesaba sızan kişinin; - IP adresine dayalı konumu (p2p açıksa)+port -çalınan hesaba kaç cihazın bağlı olduğu -sızan kişinin mobilde mi wifi ağında mı olduğu -sızan kişinin işletim sistemine dair info (iphone-android-web vb) gibi bilgileri tek bir sesli aramayla(cevaplandığı takdirde) elde edebilirsiniz. repo: github.com/0x6rss/chat-apps-…
🔴#ÖNEMLİ | Türkiye'de yeni bir dolandırıcılık sistemi türedi. TÜM VATANDAŞLARIN VE İLGİLİ KURUMLARIN BİLGİSİNE SUNUYORUM. Son 1 haftada 3 kişiden benzer ihbar aldım. Sistem şu şekilde ilerliyor: • WhatsApp'tan vatandaşların yakınlarına ait numaralardan “Borç para” isteniyor. • Borç isteyen numara WhatsApp'ta daha önce konuştuğu yakınları yani farklı bir numara değil. • “Zor durumdayım.” gibi mesajlar gönderiliyor ve mesajlarda daha önce konuşulan mesajlar da görünüyor ve o mesaja uygun bir dilde yazılıyor. • Daha sonra ise IBAN gönderiyor. Vatandaş inanırsa dolandırıcıya para gönderiyor ancak para gönderdiği kişi arkadaşı değil, dolandırıcı. • İşin en garip kısmıysa gerçekten o numaraya sahip olan ve adına para istenen kişi, “Kendi numarasından gönderilen mesajları göremiyor.” Yani hiçbir şeyden haberi olmuyor. • Arkadaşının gönderdiği mesajı da göremiyor. Sadece o andan önceki mesajları görüyor. META yetkilileri de dâhil, ilgili eksiklikleri olan her kim varsa bu konuda hesap vermeli. Tüm vatandaşlara uyarım: Lütfen bunu çevrenizle paylaşın. Parayı isteyenlerin gönderdiği IBAN'daki isim her zaman farklı oluyor, arkadaşınıza ait olmayabiliyor. Her ne olursa olsun borç isteyen kişiyi bizzat arayın ya da yakınını arayıp teyit edin. Şahsen böyle bir şey benim de başıma gelse dolandırılabilirim. Herkes dikkat etmeli. @adalet_bakanlik @SiberayEGM @abakingurlek
1
92
3
1,132
145,272
mdkfkfm dkkfkdkd retweeted
Türkanime sitesi kapandı, bir kişi önceden player urllerini arşivlemiş onu alıp web arayüzden rahat izleyebileceğiniz hale getirdim turkanimemirror.vercel.app/ Açık kaynaktır. Github profilimden inceleyebilirsiniz. #turkanime #anime
58
113
40
1,458
157,548
mdkfkfm dkkfkdkd retweeted
I was looking into BYOVD techniques today because of a recent case where a threat actor brought a vulnerable driver onto the system to disable the EDR and I want to share my thoughts on the topic. Bringing the vulnerable driver is just one part of the equation. Threat actors usually have to bring additional components to load it and execute the code needed to actually tamper with the EDR. The EDR blocked that payload... And I think that's an important point when we talk about BYOVD. For seasoned operators, this might be easy. But that is not most of what we see. The average threat actor still has to expose themselves somewhere along the chain: → Introduce and load the vulnerable driver -> LOLDrivers.io vuln drivers list → Create or start the service -> Service creation events → Drop a DLL or other payload -> File creation events under sus locations → Use PowerShell/.NET -> PowerShell execution events/AMSI detections → Compile something directly on the target -> Behavioral detections from ETW CLR provider. Usually CLR loading into non-.NET processes, assembly load notifications for newly compiled DLLs from `%TEMP%` There is not just a perfect way to detect BYOVD techniques. Defense in depth is the way to go... Again, having said all that, I know how difficult it is for the majority of organizations to have this in place. This is why these methods are still very successful and quite popular, but in my personal case, most attackers will not even come as prepared as seasoned operators like I mentioned above. We have to detect/hunt for the path they have to take to get there!
3
35
168
8,827
mdkfkfm dkkfkdkd retweeted
We escaped OpenAI's Codex sandbox by dumping V8's shared JavaScript heap and scanning it for the privileged UUID-shaped token belonging to the adjacent trusted V8 context. I sometimes see cybersecurity as a never-ending cycle of building trust boundaries and finding ways to break them. This is the story of one interesting break. When OpenAI built this default-enabled MCP server, they ran a trusted, privileged JS context alongside an untrusted one, in the same Node.js process. They assumed V8's VM contexts could serve as a security boundary, because they do create isolated execution environments, each with its own distinct global object and scope. But they forgot that these contexts share a single memory heap. So our untrusted code snapshotted that heap, pulled the token out of it, and used it to reach the privileged side. Read the full technical breakdown at: accomplish.ai/blog/escaping-…
27
52
6
425
29,020
mdkfkfm dkkfkdkd retweeted
Had some fun with DeepSeek-V4-Flash-0731 while at the airport!
16
59
6
399
50,805
mdkfkfm dkkfkdkd retweeted
one CPU core can look at 28.8 million packets a second before the Linux kernel even wakes up that's XDP. it runs inside the network driver, before the kernel allocates memory for the packet, before there's a socket, before there's a stack. it just gets to decide: keep this, or throw it away, right now most backend engineers never touch this layer in their whole career. I think that's a shame, because the stuff built on top of it is wild: - Cloudflare drops over 10 million packets a second per core with it. they've auto-mitigated 100+ attacks above 2 billion packets per second, one of them a 3.8 Tbps flood, and nobody on their team touched a keyboard - Meta's load balancer (Katran) runs this at every Facebook data center. the old way, iptables-style, tops out around a million packets a second per core and pins the CPU at 90% doing it. Katran does 10-100x that - Cilium uses the same trick to rip iptables out of Kubernetes entirely. their own benchmarks show p99 network latency dropping from 45ms to under 2ms after the switch all three are the same idea wearing different hats: read the packet before the OS does, decide fast, skip everything you don't need I got curious enough to build a tiny version myself, an XDP load balancer with Maglev hashing, no shortcuts. on one core of a normal laptop it pushed 9 million+ packets a second with zero drops. that's a laptop, not a data center NIC code's here if you want to see how it works (written in Zig btw): github.com/immanuwell/ringze… what's the most "the kernel isn't supposed to be able to do that" thing you've seen eBPF pull off?
11
111
2
828
29,954
mdkfkfm dkkfkdkd retweeted
ben claude ile planlama yaptiriyorum sonra claude karar veriyor ve kimi k3, deepseek v4 flash ya da muse 1.3 (sensitive is degilse contributor'e pasliyor, sensitive ise normal 1.3) ile subagent cagiriyor tasklar icin. - deepseeke 60 dolar kaptirmisiz - kimi en yuksek pakette olmasina ragmen onun da haftalik limitlerini dibine kadar kullanmisim - muse var onun limitler acayip yuksek %5 yapmisim anca bu hafta benim bireysel llm costum eger bu tarz bir akis kurmasam heralde aylik 4-5k usd'ye gelirdi...
10-12 gundur suren tasklarim var. deepseek agentlar otomatik duruyor sonra kendileri basliyorlar saati gelince :D
5
3
1
68
34,029
mdkfkfm dkkfkdkd retweeted
*** Connecting to EFnet… *** Joining #nopcon… when? Sep 17… how long? less than 48h
1
1
15
2,420
mdkfkfm dkkfkdkd retweeted
😎
5
8
123
7,150
mdkfkfm dkkfkdkd retweeted
Apple macOS tespit ettiğim, son altı yıl içinde yayımlanan tüm sürümleri etkileyen ve kurumsal ağlarda zero-click RCE’ye yol açabilen zafiyetim, iki ayrı CVE kimliğiyle duyuruldu: CVE-2026-84570 ve CVE-2026-84568. support.apple.com/en-us/1490…
10
15
1
148
9,087
mdkfkfm dkkfkdkd retweeted
You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors tell their LLMs they are performing authorized engagements (even when using open-weight models), or use penetration-testing harnesses (like CyberStrikeAI, PentAGI, HexStrike, etc.). Examples from real intrusions: - SSH backdoor key labeled pentest-root - AWS Cognito user pool: [email protected] - File named pentest_probe.json - Deployment named PENTEST_PROBE - Keycloak user pentest_kc01 - ClusterRoleBinding named pentest-admin - User record changed to REDTEAM-OWNED
3
7
30
3,949