Slides from my today's talk at #BlackHatUSA2026 : "Breaking the Seal: Static Deobfuscation of Compiled #V8 JavaScript Bytecode #Malware" : https://t.co/g4YeOvKMJy // #BHUSA#BlackHat2026
Since launching the EDR Internals & Development course last month, the feedback coming in has been incredible.
Students are learning how EDRs work internally while building an agent from the ground up. The training is packed with technical depth and is not easy, making it very rewarding upon completion.
EDR Internals & Development: https://t.co/LeGYIWO09h
New blog post, it's been a while! Have you ever wanted to know what HyperGuard protects from NTOSKRNL?
I also found a few interesting bits of information around its protection of the (beautiful :3) Alt Syscalls - so check it out here!
https://t.co/JLll5mFYgZ
Our AI agent, deepsec, reproduced @orange_8361's fabulous pure-logic Microsoft Edge RCE demonstrated at Pwn2Own Berlin 2026, starting only from the binary diff!
Happy to share a technical analysis by @h0j3n on our recent CVE-2026-54121 a.k.a Certighost. glhf🔥
Technical analysis: https://t.co/jYrZDLPlJr
POC: https://t.co/yBeHg1vQHP
Our research team (with the help of their agents) did it again! Second v8ctf in flag one week!
Entirely separate 0day ARW bug and new 0day heap sandbox escape
Last week I did a livestreamed talk on browser security. In case you missed it and are interested, here are the slides: https://t.co/YPuTVmOSzx
And the recording: https://t.co/6L5UVQeooG
Thanks @calif_io for hosting and the audience for listening and asking questions! :)
Hi everyone! CVE-2026-50458, a Windows kernel 0-day I discovered a few months ago has been patched by Microsoft in this month's Patch Tuesday. You can read the in-depth analysis here:
https://t.co/KM3sjPcFc8
YSoNet v2026.7.8 is out 🎉
What’s new:
• Updated SharePoint Plugin
• Adding new references/research
• New gadget filtering
Updated SharePoint example:
https://t.co/K72yXEFM1p
See the screenshot for the new filtering experience in interactive mode.
Exciting news! I'm hiring experienced vulnerability researchers @theZDI.
Do you love VR, sharing your work, and want to run categories at Pwn2Own? Come work with us (remotely).
Apply here: https://t.co/n7asBQcNOC
Feel free to DM me if you have any questions.
Pwn2Own Berlin 2026 took place quite some time ago, but only today have I had the opportunity to share details about our journey during the competition. This post focuses on analyzing a patched Windows LPE vulnerability.
https://t.co/2bTKmt4aKW
YSoNet now supports interactive mode + autocomplete in PowerShell.
String obfuscation has also been added to GitHub builds to reduce false detections, alongside several bug fixes.
Enjoy, and contributions are always welcome!
https://t.co/9BofGcFaWh | https://t.co/maASRXe9Cu
@mihomoparty Hello! That's amazing!
How are you learning browser pwn? (Do you have any study materials, or are you teaching yourself?)
I'm also in the process of learning browser pwn (I'm doing fuzzing, but I can't get it to crash, lol).
https://t.co/Wdnd3jXSw4
Alright, let's try this livestream thing again. Hopefully it will work this time.
We spent some time hacking browsers and wanted to understand what the future of exploitation may look like in this field. So we decided to invite the GOAT of browser hacking, @5aelo, to share his perspectives on browser security and exploitation. He'll discuss the current state of the art browser exploitation and mitigations.
The event will be live-streamed on YouTube and everyone is welcome to attend + ask questions. It will take place on July 16, 17:00 CEST.
Ask your questions by filling in this form: https://t.co/OfBzuTUzd1
Add to your Google calendar: https://t.co/QewG6L1QkI
Add to your Outlook calendar: https://t.co/fyJHXlGd2W
https://t.co/Wdnd3jXSw4