And this one is human insight w/ LLM-assisted research. Took about one week to finish everything. The AI really rescued me from a lot of tedious work
— excluding the part where it changed the Domain Admin password, locked me out, and claimed it got RCE 🤦
Amaze! Amaze! Amaze! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) was able to exploit Edge with a sandbox escape! If confirmed, we wins $175K. He's off to the disclosure room to explain how he did it. #Pwn2Own#P2OBerlin
MAD Bugs: Claude Wrote a Full FreeBSD Remote Kernel RCE with Root Shell (CVE-2026-4747)
To our knowledge, this is the first remote kernel exploit both discovered and exploited by an AI.
https://t.co/Cv8M69i1Mk
Turns out my #PHRACK article is live! 🔥
> The Art of PHP — My CTF Journey and Untold Stories!
Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the @Phrack crew for keeping it real! 🎉
https://t.co/BMCLlHti7q
🎉 感謝所有隊伍參與 HITCON Cyber Range 2025 資格賽!
各位資安好手辛苦了!感謝大家熱情參與 HITCON Cyber Range 2025 資格賽,本次競賽由 HITCON 與 TRAPA Security 共同舉辦!吸引來自全球各地的隊伍參戰,共計 43 支企業藍隊參與角逐,其中 37 支來自台灣,6 支為國際隊伍,分別來自馬來西亞、日本與蒙古。歷經 14 小時不間斷的實戰挑戰,每一隊都展現出超強應變力與堅強團隊合作精神,讓整場比賽精彩萬分、高潮迭起!
我們目前正積極彙整比賽數據與審核結果,並將於近期內正式公告晉級隊伍名單,請持續鎖定我們的官方社群與網站,以掌握第一手消息!📢
資格賽雖已落幕,但精彩才正要開始——誰能挺進 10 月總決賽舞台,爭奪最強藍隊榮耀?讓我們繼續見證這場資安盛事的每一個高光時刻!🔥
📍敬請持續關注 HITCON Cyber Range 2025,更多精彩即將揭曉!
📅決賽: 2025 年 10 月 17 日 (五)
🕙 10:00 至 16:00(共 6 小時, UTC+8) 現場決戰!
📩 聯絡信箱:[email protected]
🚀 Thank You for Joining the HITCON Cyber Range 2025 Qualifiers!
Dear cybersecurity experts, thank you for your hard work! We sincerely appreciate everyone’s enthusiastic participation in the HITCON Cyber Range 2025 Qualifiers. The event was jointly organized by HITCON and TRAPA Security and attracted teams from around the world, who faced an intense 14-hour nonstop practical challenge. A total of 43 teams participated, including 37 from Taiwan and 6 international teams representing Malaysia, Japan, and Mongolia.
Each team demonstrated exceptional adaptability and strong teamwork, making the competition thrilling and full of highlights!
We are currently consolidating the competition data and reviewing the results. The list of teams advancing to the next stage will be officially announced soon. Please stay tuned to our official social channels and website to get the latest updates! 📢
Although the qualifiers have concluded, the excitement is just beginning—who will make it to the grand finals in October to compete for the ultimate Blue Team glory? Let’s continue to witness every shining moment of this cybersecurity spectacle! 🔥
📍Keep following HITCON Cyber Range 2025—more highlights and surprises are on the way!
📅 Final : Friday, Oct. 17, 2025
🕙 10:00 – 16:00 (6 hours, UTC+8), Onsite.
📩 Contact Email: [email protected]
#HITCON #CyberRange #HITCONCyberRange2025 #資安競賽 #藍隊 #CyberSecurityCompetition #BlueTeam #IncidentResponse
"For anyone who dares to call themselves a researcher, this exam should be easy enough to make you laugh."
https://t.co/J9zjOr6CbJ
My new blog post shares my thoughts on OSEE.
Where is the learning path?
Where is the value of the course?
Is the course still relevant today?
Will it help you get a job?
Tips for Pwn2Own player: pick a target that no one care, then you got no collision.
Shout out to my colleague: @h3xr4bb1t
We manage to bypass all the hardware protection together 🎉
I implemented a PoC for CVE-2024-30090, which @scwuaptx discovered. The PoC uses an arbitrary increment primitive on nt!SeDebugPrivilege to escalate privileges to SYSTEM.
https://t.co/Is4oKsShDF
#CVE-2024-30090 #PoC#LPE