We are a global company made up of hackers and security researchers working together to tackle advanced vulnerabilities & techniques using AI. Building @pwn_ai
@albinowax@BlackHatEvents This is absolutely fantastic. We are thinking along the same lines!
Check our novel researcher announcement here:
https://t.co/M6rOYvRmqn
Very curious to see your finds! And the future is going to be VERY VERY exciting!
Today we’re announcing something new in offensive security: the first AI system for novel vulnerability class discovery.
An architecture built to discover undocumented exploit-building behaviors and previously unknown novel attack vectors that can later yield zero-days across real-world targets.
The Search for AGI through Security is here. Read more:
https://t.co/wOLQN5A6PW
@ColliCryptoboy@tikus@galnagli our lawyers advice against giving Pentest reports to the wrong people and it is a headache to confirm if a bug bounty hunter will just report the findings. The CLI will be generally available once it's ready but it's still unfortunately under progress. Will lyk if we open hiring
@ColliCryptoboy@tikus@galnagli Our CLI product is not yet released. Our pentest product is live but you can't use it on platforms you do not own. Currently we only run pwn after verifying the requester is the owner for safety reasons (we don't want to provide detailed vuln reports to wrong ppl) - CLI soon ;)
🚨 ZERODAY: ImageMagick 🚨
Our autonomous pentester https://t.co/zHUcIkHqvr just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯
💥 Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! 🥰
https://t.co/nNAvFAvPOx
🚨 ZERODAY: ImageMagick 🚨
Our autonomous pentester https://t.co/zHUcIkHqvr just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯
💥 Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! 🥰
https://t.co/nNAvFAvPOx
🎄🎁 Here is a 0day unauthenticated root RCE affecting over 70,000 devices on the internet.
https://t.co/yvgRXuR4nX
For our first post, we show how pwnai autonomously found a root rce affecting XSpeeder, over 8 months ago. To our knowledge, this is the first agent-found, remotely exploitable 0day RCE published.
Merry Christmas & Happy New Year 🎅💥
🎄🎁 Here is a 0day unauthenticated root RCE affecting over 70,000 devices on the internet.
https://t.co/yvgRXuR4nX
For our first post, we show how pwnai autonomously found a root rce affecting XSpeeder, over 8 months ago. To our knowledge, this is the first agent-found, remotely exploitable 0day RCE published.
Merry Christmas & Happy New Year 🎅💥
Looks like nation-state actors are utilizing fully autonomous hacking engines. Wild to see them finally doing what we’ve already built, tested, and pushed way further at @pwn_ai. The future of hacking is autonomous!
What we are building is insane. If vendors patched quicker, we would've showed you already. The sort of vulnerabilities https://t.co/6oiPiGELL0 is finding is on par with the top security researchers. preauth RCE after preauth RCE fully autonomously. Will drop a blog post soon.
With little help with @pwndotai , which is an agentic hacking ecosystem we are building, we are able to get 1-click RCE in Cluely (@cluely). The exploit takes time to setup but it's straight forward and can be reached via many techniques, and an indirect prompt injection. The full technical report is sent to Cluely team and we expect them to address it in a timely manner. In the meantime go follow @Pwndotai for upcoming announcements and advisories using our agentic tools
For the last year and a half we have been secretly working on multiple products that will shake and transform cyber security as we know it. From vulnerability detection, source code audit and penetration testing, to bug bounty and offensive security research. Stay tuned! 🤫
Here's a little tip to escalate Client Side Path Traversal (in <script src>) to XSS in wordpress sites;
It is possible to use the /wp-json/?_jsonp=<payload> rest-api path to execute arbitrary js functions.
Read more at https://t.co/FFZaJVmdFz
Credits: @OctagonNetworks
This CSP bypass technique utilizing SOME attack went under the radar but allowed for a novel way to defeat CSP with only A-z,. characters & windows. Another interesting fact of the specific issue is, WordPress remains vulnerable to this day and affects all WordPress sites (49% of the internet)
The technique was nominated for Top Web Hacks for 2022 by @PortSwigger.
You can read how it works on our blog: https://t.co/ApK22DJZ0H
Researchers have uncovered several serious vulnerabilities in Juniper Networks devices, some of which could be exploited for code execution.
Read: https://t.co/zoqEajBfhk
#infosec#cybersecurity#hacking
🔥✍️New post: CVE-2022-22241 preauth RCE and multiple high severity vulnerabilities affecting all Juniper networking devices including Juniper SSLVPN.
https://t.co/rwufOdOo96 #networking#hacking