The Exploiting Reversing Series (ERS) currently features 1051 pages of exploit development based on real-world targets:
[+] ERS 09: https://t.co/V0K5p1XvH9
[+] ERS 08: https://t.co/MPwYP7j8Qt
[+] ERS 07: https://t.co/h18hZC0azl
[+] ERS 06: https://t.co/Sh8pgB4bh8
[+] ERS 05: https://t.co/rdaPMOm4WM
[+] ERS 04: https://t.co/Vf0Fnwf0tc
[+] ERS 03: https://t.co/4lo5Hi0gnd
[+] ERS 02: https://t.co/6SNMK1tBkd
[+] ERS 01: https://t.co/YMTSBl59VC
Now is the time to take a break to dedicate all my energy and focus to security research and new projects that will be announced in the coming weeks and months.
Have a great day and enjoy reading.
#exploit #exploitation #windows #chrome #macOS #iOS #hypervisors #vulnerability #research
not sure why, but releasing Pyre - Ghidra's decompiler running fully in your browser. Drop an ELF / Mach-O / PE / wasm, navigate decompiled C with cmd-click + xrefs in Monaco. No server, no upload, binaries must never leave the page...
source. https://t.co/1cCwmILbuQ
deployed at: https://t.co/LnJesWibf6
Every pentester should have these in their toolkit 👇🔥
From Shodan to https://t.co/jroBP3BGxS, this list covers servers, OSINT, attack surface, code search & threat intel
Did I miss anything? Drop your favorite tools in the comments 👇
#BugBounty #CyberSecurity #Infosec #Hacking #Recon
Understanding glibc malloc by sploitfun
https://t.co/bMmDBnyK5I
* How is heap memory obtained from the kernel?
* How efficiently is memory managed?
* Is it managed by the kernel, by the library, or by the application itself?
* Can heap memory be exploited?
Get those answers.
Let's Zoom-In to the new start of the week... 🔍
Releasing #IDA Plugin #ZoomAllViews — Ctrl+Scroll font zoom for every IDA view. 💪
Because this should work out of the box. Now it does. 🤓
• Zoom in/out in Disassembly, Pseudocode, Hex View, Strings, Imports, Functions, Structures, and every chooser 😲
• Works across Normal & Debug view widgets — Stack, Registers, Locals, Watch
• Row heights scale automatically with font size
• Graph/Proximity/Xref views excluded — IDA's native zoom untouched ☝️
• Toggle on/off via menu or Ctrl-Shift-Z
• Single file, zero dependencies 🫰
• Compatible IDA 8.x — 9.3+ (PyQt5 / PySide6) 🛠️
https://t.co/9ZGAhvqi2s
#IDAPro #ReverseEngineering #IDAPython #Malware #DFIR @HexRaysSA
Exploit PoC Telegram Web app XSS / Session Hijacking 1-click
The XSS vulnerability is triggered using the event type web_app_open_link via postMessage. (CVE-2024–33905)
https://t.co/cGj0ywhSMA
Run the FunnyApp.exe, and you’re a Windows admin. An unknown individual just dropped a zero-day exploit for elevating privileges on Windows https://t.co/oaBn4MlIkO
We used Claude to discover CVE-2026-34197, a remote code execution vulnerability affecting the #Apache#ActiveMQ Classic web console. This is exploitable with default creds or completely unauthenticated for certain versions.
https://t.co/C1uKzMCrM8