Here is a great repo for studying real-world exploited zero-days and their root causes.
repo: https://t.co/IAxDKpU03y
Worth bookmarking for anyone into security research and bug bounty hunting.
#CyberSecurity#BugBounty#InfoSec
the same technique giving cheaters wallhacks in Valorant is the same one being used in malware to pwn you. Still working no patch, undetected from AV's and AC's.
I pulled the source from a cheating forum, built it, and ran it on my fully patched Windows 11 machine. it reads memory straight out of another running program without needing admin, without loading a driver, without calling any API that your EDR monitors. it just uses two normal Windows functions that have existed since the 90s, SetWindowsHookEx and SendMessage.
I reversed the root cause in Ghidra. two functions that ship in every copy of Windows ntdll.dll and shell32.dll will blindly execute whatever function pointer you hand them through a window message. Microsoft's own exploit protection CFG signs off on it because they're legitimate functions. no CVE. no patch. 279 stars on GitHub. Microsoft won't fix it because they consider same-privilege process interaction "by design." Chinese researchers found the same technique in live malware back in 2023.
We’re continuing to work with Microsoft and GitHub to investigate the impact of the malicious Nx Console version 18.95.0. I'll share any updates on X (@jeffbcross and @NxDevTools) as well as in our security advisory: https://t.co/szBoQ3doaX.
Initially, Microsoft indicated to us that there were 28 installs of the malicious version 18.95.0. Based on our own analytics for the compromised version, we currently believe the number of users who received the malicious package may be significantly higher; potentially over 6k installs.
We’ll keep working to determine the actual impact and exposure, and I don’t want to speculate beyond the facts we have right now. But I also don’t want to minimize the situation.
This is my top priority right now. Our team has been, and continues to be focused on understanding exactly what happened, helping affected users, hardening our systems and release processes, and being as transparent as possible throughout the investigation.
Aaaand it's official! Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning a whooping $200,000 and 20 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
Incident response for Nuclear facilities: insights into the most protected area of OT cybersecurity. ☢️🧪🖥️🌡️🤯
More details on:
LinkedIn: https://t.co/NiIiZ9dMOh
Substack: https://t.co/cdjHGFcFnF
MIT just quietly dropped a free AI curriculum that puts $50,000 university courses to shame.
12 books.
Zero tuition.
From the same institution that produced the people building the models everyone is talking about.
FOUNDATIONS
1. Foundations of Machine Learning — https://t.co/Un6UbjJ3Xo
2. Understanding Deep Learning — https://t.co/UQxZmyESdn
3. Machine Learning Systems — https://t.co/YAgrLVGAXt
ADVANCED TECHNIQUES
4. Algorithms for ML — https://t.co/YlBk59o8Hp
5. Deep Learning — https://t.co/KMO1uWPyk1
REINFORCEMENT LEARNING
6. RL Basics (Sutton & Barto) — https://t.co/sOZlDXzu41
7. Distributional RL — https://t.co/uOkviYiAq7
8. Multi-Agent Systems — https://t.co/Dx9caJVx1d
9. Long Game AI — https://t.co/K9Qm2TjAQ6
ETHICS & PROBABILITY
10. Fairness in ML — https://t.co/MgkLdRvicO
11. Probabilistic ML Part 1 — https://t.co/Zz33gQi1vG
12. Probabilistic ML Part 2 — https://t.co/qBe776EjCg
This is a complete MIT-level AI education.
Not a YouTube playlist.
Not a Twitter thread full of fluff.
Textbooks written by the researchers who built the field.
The people who actually study this will not just understand AI better than their peers.
They will understand it better than most people currently getting paid to work in it.
Most people will bookmark this and never open it.
The ones who open it tonight are the ones who show up in 12 months having built something nobody around them understands yet.
Bookmark this.
Open the first one tonight.
Follow @cyrilXBT for more resources that actually compound.
Car Hacking with GearGoat
GearGoat is a car simulator that allows you to work with the CAN bus, which is the internal communication network used by most modern vehicles
In the real world, this is equal to connecting a CAN adapter such as CANable or Macchina M2 into the OBD-II port, which is typically located under the dashboard. This port is essentially a gateway into the vehicle’s internal network
See it in action on our article: https://t.co/1h5buGT237
@three_cube@_aircorridor #cybersecurity
"TCP is a byte stream, not a message protocol. If you do not know the bytes on the wire, you do not understand the system."
Track 17, The Networker, is live.
You will build TCP servers from raw syscalls, implement length-prefixed and line-delimited message framing, build a binary serialization format, and create gRPC streaming from first principles.
Stop guessing and start reading the wire yourself: https://t.co/eJaQvEg9wI
I just gave Claude Code a rooted Android phone…
It autonomously reverse-engineered Subway Surfers, hooked the coin logic, bypassed the anti-cheat, and gave itself UNLIMITED coins in ONE session.
🔴 Active Directory Attack Architecture – Visualized Like Never Before
If you’re into Red Teaming / AD Exploitation, this is 🔥
This interactive map breaks down how attackers move from initial access ➝ domain dominance using real-world techniques.
💡 Why it matters:
Modern cyber attacks don’t happen in one step — they follow structured paths like reconnaissance, exploitation, lateral movement, and privilege escalation ()
🎯 What you’ll learn:
• Attack paths inside AD
• Privilege escalation chains
• Lateral movement techniques
• Real attacker mindset
🧠 Think like an attacker → defend like a pro
🔗 Explore here: https://t.co/CKLvM4p7FV
#cybersecurity #redteam #activedirectory #pentesting #infosec #ethicalhacking #mitreattack #oscp
Harvard made its Senior Engineer roadmap available to the public at no cost.
Stop paying for $2,000 bootcamps. Prof. Vijay Janapa Reddi just put the entire ML Systems (CS249r) curriculum on GitHub.
If you master these 6 pillars, you're ahead of 99% of the field:
🏛️ Architecture
🚿 Data Pipelines
🚢 Production
🛠️ MLOps
🔋 Edge AI
🔒 Privacy
This is the "Black Box" of Big Tech infrastructure, open-sourced.
Read. Learn. Bookmark.
"Handbook on Guided Missiles" 1946 War Department report on German & Japanese rocket powered missiles & aircraft. This rarely-seen classic (scanned from a photocopy) provides a vast pile of information, including a great many diagrams. Air Doc 26 here:
https://t.co/gqzVsFB2bT
Was remembering this crazy 0-click iOS exploit chain:
GIF in iMessage → actually PDF with JBIG2 → integer overflow in JBIG2 decoding → Use logic to emulate computer architecture → sandbox escape → Pegasus malware
https://t.co/sZxpSY2HLb