I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
not sure why, but releasing Pyre - Ghidra's decompiler running fully in your browser. Drop an ELF / Mach-O / PE / wasm, navigate decompiled C with cmd-click + xrefs in Monaco. No server, no upload, binaries must never leave the page...
source. https://t.co/1cCwmILbuQ
deployed at: https://t.co/LnJesWibf6
Windows 11 24H2 LPE vulnerability (CVE-2026-21250)
→ Local privilege escalation
→ Potential SYSTEM access
Exploit PoC is public 👇
https://t.co/FsaHGVdhWj
Patch or mitigate ASAP.
#CyberSecurity#Infosec#Pentesting
The latest Proxmark3 release is called BREAKMEIFYOUCAN!
Not a random name.
That is the actual 3DES factory default key NXP burned into every MIFARE Ultralight C they shipped since 2008.
Somebody finally broke it properly.
The paper drops the keyspace from 2^112 down to 2^28.
Counterfeit cards fall in under 60 seconds from a single card interaction. The tooling is merged: https://t.co/2CYKrRdv22
#Proxmark3 #RFID #NFC #MifareUltralightC #NXP #OpenSource
Oh this is clean. A searchable, filterable RFID attack reference.
HID Prox, MIFARE, EM4100, animal tags, organized by frequency AND tool (Proxmark, Flipper, Chameleon...). This is the cheat sheet that used to live in your notes app.
Bookmark it!
you'll thank yourself on your next physical engagement.
https://t.co/XJL1B5tbkR
Finally got this virtual iPhone running iOS 26.1 up and running on macOS. It's jailbroken and going to help with security research a ton. Big thank you to @wh1te4ever for this.
This is not for the average user and is complicated to set up. Highly recommend Codex and/or Claude to assist.
For those interested, the project is here:
https://t.co/ygp2iV8kuv
And the writeup is here:
https://t.co/WaYM6QiFLD
Account Takeover via Password Reset Poisoning
Tips :-
1- During signup or password reset flow replace the Host header value with:- Host: https://t.co/zFcxlbYqnq
2- Observe that the email verification or password reset link got poisoned
credit: @wadgamaraldeen#bugbountytips
Gemini 3 Deep Think generated a real-time 3D WiFi radar that maps every network around you as glowing nodes in a Matrix-style space — in one shot. It used Pearson correlation to infer which APs are physically close, since RSSI alone isn't enough.