@rawpayloadi
iAccount based inEurope!
About this account
- Account based in
- Europe
- Connected via
- Web
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
segfaults are a feature of our curriculum
Joined April 2026
- Tweets120
- Following204
- Followers16
- Likes186
rawpayload retweeted
Hacktron should have just said their AI went rogue and accidentally made the pull request.
OpenAI would have loved that.
rawpayload retweeted
Hmm... this technique sounds familiar 👀
zeroday.cloud/blog/redis-cve…
another one (poc) for redis server RCE: github.com/v12-security/pocs…
handleClientsBlockedOnKey() use-after-free. patched in release 8.8.2.
rawpayload retweeted
Anthropic CEO after realizing a Chinese dev explained loop vs graph engineering better than anyone at the company
A Chinese developer just explained the shift from Loop Engineering to Graph Engineering better than anyone.
most people are still building agents the way that's about to be obsolete.
> why single-agent loops break and go "goal blind"
> the 4 parts of a graph: nodes, edges, state, policy
> 3 topologies that run everything: diamond, supervisor, pipeline
> Anthropic's 5 official workflow patterns
the punchline: it's not how many agents you run. it's the determinism you build with verifiers, code fallbacks, and reality anchors.
I broke the same architecture down with Kimi K3. Full A-Z guide below.
This video is larger than Cloudflare's 512 MB cache, so it can't be played through. More donations are needed to cover a larger cache. Donate
Arbitrary code execution in objdump -g
We have a thing for finding bugs in bug finding tools. IDA Pro, Ghidra, Binja Sidekick, or radare2. You name it we hacked it. Our friends were saying we should try objdump. So here we go.
Blog post: blog.calif.io/p/oobdump-relo…
AI-generated PoC and writeup: github.com/califio/publicati…
rawpayload retweeted
🚨 Latest from today's Shai Hulud campaign -
The JFrog Security Research team has identified more malicious packages in this campaign which are being published with a hidden payload - hosted directly on GitHub instead of npm! 🧵
cooked
dnsmasq powers massive amounts of networking infrastructure worldwide.
We found 6 0days. 5 were accredited to xchglabs and assigned CVEs.
Our first technical writeup is now live:
xchglabs.com/blog/dnsmasq-fi…
#dnsmasq #0day #cybersecurity #xchglabs
rawpayload retweeted
Full technical writeup + exploit technique for this 20-year-old bug in PostgreSQL
zeroday.cloud/blog/postgres-…
Xint Code discovered a highly exploitable heap-buffer-overflow in PostgreSQL that existed for over 20 years.
Our research team exploited this bug to claim $30,000 at ZeroDayCloud in December!
Bug details are below
rawpayload retweeted
Using Chinese AI models for coding be like:
NEW: House committees are probing Airbnb and Cursor parent Anysphere over their use of Chinese AI models @semafor
rawpayload retweeted
Same script. Ubuntu, Amazon Linux, RHEL, SUSE — four root shells, side by side.
No per-distro tuning. No race window. No kernel offsets to leak.
Most Linux LPEs need at least one of those. This one needs none.
rawpayload retweeted
A new analysis of the js-logger-pack npm malware reveals a sophisticated shift: they are now using Hugging Face not just as a malware CDN, but as a direct exfiltration backend.
Instead of a traditional C2 server, the malware uploads stolen data (keystrokes, files, and credentials) directly to private Hugging Face datasets. This allows the malicious traffic to hide in plain sight behind legitimate AI platform connections.
Even wilder, the attacker is planting false metadata to impersonate Josh Stevens (VP at Polymarket) to hide their tracks.
Read the full technical breakdown of this cross-platform threat: research.jfrog.com/post/hugg…