Memes | Coffee | I apparently use Emacs now | CTF with Shellphish | Malware | All posts and thoughts are probably from Stack Overflow | Tick 196 enthusiast

My Desk
Pascal retweeted
We asked GPT 5.6-Cyber to escape a VM used to sandbox agents. It broke out three times. In its final escape, the agent found three 0-days on its own and chained them into a working exploit. blog.trailofbits.com/2026/08…
70
334
1,698
491,216
Pascal retweeted
We are pleased to release tmp.0ut 5 Volume! Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!! tmpout.sh/5/
21
331
1,186
84,123
I wrote Task Unmanager: keeps killing processes Russian Roulette style, until your machine crashes
528
4,198
60,053
2,055,496
We are approaching perfect binary decompilation, and, crazier still, LLMs may soon be the best decompilers on the planet. I'd like to introduce DecBench, an evaluation site to determine how close we are to completing the field of perfect decompilation. Links and more in 🧵
21
134
931
105,666
Hello hackers! We're running a study about fuzz harnessing on pwn.college! Go learn a bit about fuzzing and get a gift card at the same time :-) This is the first of hopefully some more material around the topic in the next few months, so stay tuned for that as well!
pwn.college has just added a dojo focused on creating fuzz harnesses for OSS-Fuzz, pwn.college/fuzz~c7f7b8c2/ $50 Amazon gift card for the first 30 participants who complete it, only 14 so far as of today.
20
175
21,353
You've seen the trends in AIxCC: LLMs can hack source, find vulns, and patch them. But what about on binaries without source? Do decompilers close the gap, or is there more to grow? Come see my talk at DistrctCon where I merge and dissect these two fields: AI Hacking + Decomp.
5
21
2,164
Pascal retweeted
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
899
3,173
481,340
Pascal retweeted
You are probably gonna hate me for the title of this blogpost, but, here is a quick peek into one of the most surprising components of our @DARPA AIxCC CRS: DiscoveryGuy. support.shellphish.net/blog/… (Planning to publish a few more of these "quick peek" into the system 👀)
3
27
63
7,692
Spreading the awareness on this. GH is one of those amazing communities for helping improve the diffusion of knowledge in not just the GameHacking scene but also the general hacking/cybersecurity scene. If you haven’t heard what’s happening to GH I recommend checking this tweet.
🚨 Official Statement from Guided Hacking Regarding Malicious Impersonation & Fraudulent DMCA Campaign 🚨 To our community, fellow content creators and platform partners: We are issuing this statement to address a serious, ongoing problem: a malicious and fraudulent campaign by cybercriminals who are impersonating Guided Hacking with the stated intent of "destroying Guided Hacking's reputation forever". We understand the confusion and anger this has caused, and we are committed to resolving it. Here are the facts: 1. The Problem: A Coordinated Attack on Our Reputation Cybercriminals are submitting fraudulent copyright strikes claiming to be from Guided Hacking. This is a deliberate effort to ruin our reputation within the community by targeting game hacking YouTubers and other creators. To be unequivocally clear: Guided Hacking is NOT sending these fraudulent notices. We are the targets of this impersonation, just like the creators who have been affected. We have been under constant attack for over a decade by cybercriminals because we reject them as our peers. Guided Hacking has always been 100% devoted to education, not cybercrime. Specifically, be aware of fraudulent notices sent by individuals or entities claiming to be: Lukas Feiler at Baker McKenzie (impersonated) Myxelo (a fake, AI-generated legal entity) These parties are NOT authorized to represent Guided Hacking. Any DMCA takedown notice from them is fraudulent. 2. Important Clarification: We Do Issue VALID Takedowns This situation is complex because we must protect our intellectual property. Our authorized agents do send ~15 legitimate DMCA takedown notices per week. These are 100% valid and target people who knowingly and willfully are distributing our copyrighted content. Because we issue legitimate takedowns, and this third party is now sending fraudulent takedowns in our name, it is crucial that every takedown notice is treated on a case-by-case basis. Please do not assume all notices are fraudulent, as this would allow piracy of our work to continue unchecked. 3. Our Actions to Fight Back We are not taking this attack lightly. We are actively working to stop these criminals and have already taken the following steps: Preparing Legal Action: We have identified the individuals responsible for this campaign and are preparing legal action against them. Platform Collaboration: We are working directly with YouTube to report the fraudulent activity and help them distinguish between our valid notices and these forgeries. Assisting Creators: We are in direct contact with all affected YouTubers who have reached out to us, providing evidence and support to get their content reinstated. Notifying Impersonated Attorneys: We have informed the real attorneys being impersonated so they can also take action. 4. What to Do If You Have Been Affected If you have received a DMCA takedown notice claiming to be from Guided Hacking, we are here to help you resolve it. Do not panic. Please use the contact form on our official website to send us all the details of the notice you received. Our team will investigate immediately to A) verify if the takedown is fraudulent and B) provide you with the necessary support to get your video reinstated if it is. If you report a valid takedown as being fraudulent, we will not personally respond, our attorney will reach out to you instead. We are committed to helping every creator who has been unfairly targeted by this malicious campaign. We will continue to post updates on this matter exclusively on our official Twitter/X account: @GuidedHacking. Thank you for your understanding and for helping us spread the word. Sincerely, Guided Hacking
1
11
662
It’s a shame to see people try to destroy the reputation of a community that’s seeking to help people learn the intricacies of computers through game hacking. I hope anyone caught in this crossfire sees the quoted tweet and knows GH isn’t the one being adversarial
1
78
Pascal retweeted
🚨 New blog post: ELEGANTBOUNCER - Catch iOS 0-click exploits without having the samples. Features iOS backup forensics & messaging app scanning for iMessage, WhatsApp, Signal, Telegram & Viber attachments. 🔗 Link -> msuiche.com/posts/elegantbou…
7
62
196
37,580
Great challenge in SekaiCTF by @qynln based on my WASM escape talk/article. I especially like the Symbol.toPrimitive trick for better function calling, also allowing for control over thisArg! github.com/project-sekai-ctf…
1
4
50
3,374
Need some good read for the weekend? Check the master thesis "An In-Depth Study of Smart Building Systems: Firmware Analysis and Device Emulation" here webthesis.biblio.polito.it/s… Beside the usage of EMBA I like the Kernel and GCC analysis in the paper. Good job and valuable feedback
4
22
66
4,115
I Just documented a cool way to authenticate proxied tooling to LDAP in an AD environment using C2 payload auth context, without stealing any tickets or hashes! Keep tooling execution off-host and away from EDR on your Red Team assessments! specterops.io/blog/2025/08/2…
4
116
409
33,948
Secure enclaves in post-exploitation world. A strategy to exploit vulnerable enclave DLLs and transform ROP-based execution to hide implant memory during sleep. Fantastic post by Cedric Van Bockhaven (@c3c) of Outflank Team (@OutflankNL)! Source: outflank.nl/blog/2025/06/16/… #redteam #blueteam #maldev #malwaredevelopment
1
29
101
6,504
I know a lot of people will hate me for saying this but it has to be said. I get a lot of DMs saying RT is getting harder everyday, traditional loaders dont work anymore, opensource tools tend to crash or get detected instantly. But wasnt that the whole point of Red team? Thats why red teams get paid way more than PT/appsec. RTs are not supposed to be easy, its not just about stealing the first kerberos ticket/Ad Cert and becoming DA. You get paid for the expertise. If you have the same skills as that of general appsec/strategic team, then why would you get paid more? Somehow somewhere someone thought that RTs can be easy money and started providing cheap RTs, providing general PT in the name of RTs, confusing amateur orgs between RT and PT, but infact Redteam was always about research, helping the target organization improve their defense and find flaws in creative ways, or to identify the effects of an adversary. If you have done that and succeeded in improving the security of the org, then it means the next one to improve is you. You cant pray for weak security while doing redteams. Challenges make you better. Staying constant is for the weak.
22
56
376
34,812
Pascal retweeted
For my last year of DEF CON CTF with @nautilus_ctf I created a deck-building card-game named Nautro, written entirely in ZIG Play cards to produce resource chains to increase your total energy Most easy vulns found during the game were patched, I challenge you to exploit it!⬇️
2
10
66
11,370
Pascal retweeted
My article "High-Performance Network Scanning with AF_XDP" has been released on the 72th issue of Phrack. phrack.org/issues/72/3_md#sc…
14
52
293
25,700
Pascal retweeted
Tomorrow 7 PM PDT! Livestream w me and @MalwareTechBlog. We’ll look at this month’s Patch Tuesday, dissect a bindiff, and try to turn it into an exploit. I might also try to get him to solve the STILL UNSOLVED Windows Phrack CTF challenge 🤔 twitch.tv/malwaretechblog
10
49
218
33,577