We are happy to share our ai-free (lol) research on the decade old ReDoS topic, we go through a couple findings, for example if you use IsPhoneNumber decorator in say your nestjs application, your currently trivially vulnerable to getting your server 🥶
https://t.co/6QQyVXf3fv
I’ll be authoring pwn challenges for @citeflag CTF this year.
Registrations are open, qualifiers start April 3rd, and there will be prizes for the winners.
I did some vulnerability research on bareiron minecraft server project and found 3 vulnerabilities which resulted in RCE:
CVE-2025-69806
CVE-2025-69808
CVE-2025-69809
https://t.co/UHva8KbwPd
We achieved a guest-to-host escape by exploiting a QEMU 0-day where the bytes written out of bounds were uncontrolled.
Full breakdown of the technique, glibc allocator behavior, and our heap spray/RIP-control primitive ↓
I started working on a small side project:
https://t.co/cZ9KMQlP40
It's an ahead-of-time binary translation toolchain.
It transpiles windows binaries to any other OS/platform.
It is super limited right now, but managed to translate a 32 bit windows binary to x86_64 linux 🥳
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller.
Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit.
🔍 Full technical write-up 👇
https://t.co/R0E5Uqql1E