@rdjgri
iAccount based inNetherlands
About this account
- Account based in
- Netherlands
- Connected via
- United States Android App
Account-level information from X, not a live location or the device used for a specific post.
Security Researcher @v12sec - CTF with Superflat / @0rganizers / ICC team Europe 22/23/24/25
Joined November 2018
- Tweets136
- Following676
- Followers1.9K
- Likes1.1K
Pinned Tweet
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨
Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome.
This PoC Downloads the file, then pops open the file manager for unsandboxed RCE
(lovingly refered to as the full chain from temu)
Rick de Jager retweeted
Security researchers from Zellic and V12 are presenting at BSides Canberra this week!
@farazsth98 on weaponizing a subtle kernel bug.
@rdjgr on heap corruption bugs in ghostscript, and the many targets affected.
Both talks will be on main stage on Friday morning, come say hi!
Interestingly this is a very similar primitive to one of the "unexploitable" dead ends in @trailofbits recent article about sandbox escapes. (although this is a slightly different bug)
It did take some manual nudging for me to convince 5.6-sol that AppArmor could be bypassed :)
Rick de Jager retweeted
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663.
Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page.
This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps.
PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance...
Breakdown and POC. 🧵
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud.
V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything.
Two separate critical bugs: arbitrary read and RCE.
Here's how. 🧵
and here's our poc for postgres server RCE: github.com/v12-security/pocs…
CVE-2026-14669. patched postgreSQL 18.6.
poc for client RCE 🔜
Rick de Jager retweeted
If you like my reverse-engineering, deobfuscation or malware work, I'm looking for a job - I am a security researcher with a knack for deep tooling/capability development and I've also done blue-team/pentesting work.
DM me if you want my resume or if you want to ask questions!
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663.
Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.