Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things. Co-founder & CTO @ @usemilgram

Simone Margaritelli retweeted
7
139
1,708
14,857
Simone Margaritelli retweeted
PoC is public. Internet-facing MikroTik SSH → full admin. No password. No key. MikroTrick: CVE-2026-67279 + CVE-2026-86060. Fresh on CISA KEV. Chain: password auth as `-2` (rejected but left sticky) → pre-auth rekey drops the auth gate → `/nova/bin/login` treats `-2` as “read identity + policy from fd 2” → all-ones mask = full admin. IoC: `login failure for user -2 via ssh` then `user added by ssh:-2@…` PoC: github.com/digiprosec/MicroT… Writeup: cert.pl/en/posts/2026/09/mik… Patch: 7.23.4 / 7.24.2 / 6.49.21 - then hunt `ops` + Flagged. #MikroTik #RouterOS #CVE #PoC #InfoSec #CyberSecurity
6
48
225
15,674
Simone Margaritelli retweeted
Replying to @tomekkorbak
questions: 1. why was the DNS tool able to bypass the sandbox? 2. why 2.5 hours from detection to pausing the run?
5
10
205
45,934
Simone Margaritelli retweeted
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
60
211
1,933
346,077
Simone Margaritelli retweeted
We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome. This PoC Downloads the file, then pops open the file manager for unsandboxed RCE (lovingly refered to as the full chain from temu)
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
3
32
386
25,556
Simone Margaritelli retweeted
Had some fun finding and exploiting state machine logic bug in af_alg_sendmsg last year, it leads to OOB access, arbitrary write then container escape that unnoticed since 2011 kernelCTF writeup: github.com/star-sg/security-… Fix commit: git.kernel.org/pub/scm/linux…
We're likely 1st to publicly exploit crypto: af_alg as a new attack surface in kernelCTF. Our members @n0psledbyte & @st424204 started poking it in Sep 2025, finding a 0-day container escape unnoticed since 2011. @AnthropicAI @OpenAI: interested in collaborations? We are all ears
1
39
146
18,212
Simone Margaritelli retweeted
imagine turning this on at the beach and every bluetooth speaker within 500 yards detonates like a claymore
Anduril Armory. The global storefront for commercial-off-the-shelf capabilities is live. Every item ready to deploy. "We have the demand coming in, orders are booked." - Matthew Steckman, President and Chief Business Officer at Anduril Industries. Armory.Anduril.com
145
587
15,452
664,206
Simone Margaritelli retweeted
🚨 CISA KEV — WSO2 MULTIPLE PRODUCTS CVE-2026-5430 (CRITICAL AUTH BYPASS / ACCOUNT TAKEOVER) CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) Catalog on September 24, 2026, based on evidence of active exploitation. Products (vendor advisory WSO2-2026-5328): • WSO2 API Control Plane 4.6.0, 4.5.0 • WSO2 API Manager 4.6.0–4.1.0 • WSO2 Traffic Manager 4.6.0, 4.5.0 • WSO2 Universal Gateway 4.6.0, 4.5.0 Vendor severity: Critical — CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); adjusted to 9.8 for single-tenant deployments Vendor overview: JWT authentication can be bypassed when a token is signed using an unsupported algorithm, enabling unauthorized access and potential admin account takeover CWE (KEV): CWE-347 (Improper Verification of Cryptographic Signature) Federal due date: September 27, 2026 (BOD 26-04); forensic triage: Yes ⚠️ Analyst Note: This is an official CISA KEV addition (catalogVersion 2026.09.24; count 1723; dateReleased 2026-09-24T19:00:55Z) plus WSO2’s official security advisory. Prefer those primaries over secondary media. CISA’s KEV shortDescription labels this a “path traversal” that could enable unrestricted file upload / RCE, while the linked vendor advisory WSO2-2026-5328 and CWE-347 describe JWT authentication bypass / account takeover. Post from the vendor technical description; note CISA’s active-exploitation signal and due date. CISA has not published a detailed exploitation-campaign narrative in the KEV entry; treat “known exploited” as the authoritative urgency signal and apply vendor fixes / BOD 26-04 guidance. Official vendor advisory: security.docs.wso2.com/en/la… CISA alert (two-KEV add): cisa.gov/news-events/alerts/… CISA KEV catalog: cisa.gov/known-exploited-vul… #DDW #DarkWeb #CISA #KEV #WSO2 #CVE20265430 #APISecurity #ThreatIntelligence #CyberSecurity
1
4
31
6,791
Simone Margaritelli retweeted
We found 2 vulnerabilities in Salesforce Agentforce that let an attacker turn the agent against the company using it. We call these SalesBleed 🧵
3
14
91
9,450
The fan club bots swarm is hilarious 😂
1,515
Simone Margaritelli retweeted
42
473
6,406
221,134
Simone Margaritelli retweeted
Dont be sleeping on Heif Heist! Meta paid 100k for my RCE on FB/Instagram! heif-heist.com/
104
210
4,957
524,975
Simone Margaritelli retweeted
My @x33fcon talk about Credential Relay Phishing is finally out! Watch me struggle through the live Google phishing demo, a day after the pirate ship party, which deprived me of my last few brain cells. 😜 Wrath of demo gods and AI lulz included. 🥳 piped.video/dNtqZJmtIpw
4
39
131
11,874
Simone Margaritelli retweeted
Using Apple's Corelocation you can identify network devices in areas where Wigle simply doesn't have coverage. This is Pine Gap, a joint Australian and United States satellite communications and signals intelligence surveillance base. You cannot get within 25KM before getting stopped. Using Apple's own infrastructure you can map out the location of over 140 Fortinet devices on the base.
27
164
1,779
113,155
Simone Margaritelli retweeted
🚨 PUBLIC EXPLOIT RELEASED FOR LINUX KERNEL CONTAINER ESCAPE — CONTAINER USER CAN REACH ROOT ON HOST DepthFirst has published technical details and exploit code for CVE-2026-80521, a Linux kernel AF_UNIX use-after-free that can break the container security boundary. • Exploitation starts from unprivileged code inside a container and can yield root on the underlying host • The vulnerable AF_UNIX functionality is reachable through syscalls allowed by default Docker/Kubernetes seccomp profiles • DepthFirst used the bug to compromise a Google kernelCTF target in July • The flaw was reported to kernel.org in August; researchers learned it had independently been reported by Kyle Zeng of OpenAI • An upstream Linux kernel fix was released August 6 • DepthFirst published its full research and exploit on September 22 • Ubuntu tracks CVE-2026-80521 as affecting relevant releases; downstream patch status should be checked rather than assuming the upstream fix is already deployed • No confirmed in-the-wild exploitation has been identified ⚠️ Analyst Note: This is especially relevant to multi-tenant container infrastructure. Containers share the host kernel, so a kernel escape can turn compromise of one workload into root access to the underlying node and potentially expose neighboring workloads. The availability of public exploit material materially lowers the barrier for reproduction. Operators running untrusted or internet-facing container workloads should verify their actual host-kernel build and patch state now. Primary: depthfirst.com/research/cont… #Linux #CVE202680521 #ContainerEscape #Docker #Kubernetes #Kernel #CloudSecurity #PoC #ThreatIntel #DDW #DarkWeb
13
58
10,829
We all have a different sense of aesthetics. Personally I love how Rust code looks like, but I’d never push my personal view as a generally accepted fact while on a stage looking like Temu Jesus on cocaine.
71
26
654
36,650