Did you read our latest publication?
Our newest advisory highlights a Linux kernel use-after-free vulnerability discovered by independent researchers during TyphoonPWN 2026: https://t.co/enBP5PRWpM
SSD Secure Disclosure is a trusted partner for advanced vulnerability researchers, providing a direct path from high-impact research to coordinated disclosure and competitive compensation.
We are actively looking for Linux vulnerability research, including kernel exploitation, privilege escalation, memory corruption, and other high-impact findings.
You focus on the research. We handle the rest. Learn more at https://t.co/RE5d7kXSaQ
🚨 New advisory was just published!
2 independent security researchers discovered and submitted a use-after-free vulnerability in the Linux kernel's Bridge STP implementation during TyphoonPWN 2026. The vulnerability earned second place in TyphoonPWN's Linux Privilege Escalation category.
Read our full advisory: https://t.co/enBP5PRWpM
🚨 New advisory was just published!
An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://t.co/CZW8oU0aaJ
Well, I got to give a big big credit for anyone who got accepted into the @defcon Main stage talk this year.
I just got a decline for my MCP research, 12 CVEs, systematic issue in Anthropic's code, enabling us to hack 6 companies production servers, breaking almost any AI coding agent AND infecting 9/11 MCP marketplaces without being blocked.
If this talk wasn't accepted, there should be some explosive over the top presentations this year 🙈🤯
Because I really don't know what could be missing... Should I hack the NSA next year to get accepted or something?... 😣🥲
0liverflow/cve2poc: CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID https://t.co/ggJxFLaMae
Finally hacked the MiBand 9 and 10 SoC
The BES2700iMP was until now fully closed and without any public SDK/Hacks.
By using the leaked IHC SDK I was able to run a full custom firmware to of course Play some DOOM on it!
🎬
https://t.co/AW6vBFaj5F
GitHub:
https://t.co/wpYSzcTCvp
Only a few tickets left for TyphoonCon's "Exploiting 10x Faster: LLM Agents and MCPs for Modern Vulnerability Research" training by @beta_b0t and @G1ND1L4 !
Grab your tickets now at: https://t.co/sBUdOQo1tC
TyphoonPWN: Call for Innovation is open and we’re already seeing strong submissions coming in. Forget the usual targets. We want new attack surfaces. New ideas. New wins.
🔓 WiFi smart locks
📱 Android exploitation
⌚ Smartwatches
🏠 Smart home takeovers
🔊 Bluetooth devices
If it’s connected - break it.
💰 Win up to hundreds of thousands in prizes
🌍 Get global exposure on the TyphoonPWN stage
Be the one who hacks what no one else is looking at: https://t.co/MI4z6PjFIo
🌪️ Want to join us in Seoul for TyphoonCon 2026?
One of our sponsors is raffling a FREE conference ticket!
Like and share this post for your chance to win.
Don’t miss your shot. Come join us in Seoul!
Kirils Solovjovs takes the stage at TyphoonCon 2026!
He’ll dive into reverse engineering the DUOX PLUS intercom system exposing protocol flaws and demonstrating MITM, spoofing, and signal manipulation using simple hardware tools.
https://t.co/dHxLAceBYb
Curious how a bug in Linux’s ipset subsystem could lead to full kernel compromise?
In our new article, we revisit CVE-2024-53141 to break down the bug, explore the memory layout, and show how it can be turned into a powerful privilege escalation.
Read it here: https://t.co/BvuWrjYRJM