Infosec fanboy, reverse engineer

Poland
A Tale of Several Hijacks and What It Taught Me About Runtime-Driven Testing - if you fancy reading a story about simple vulnerabilities (Ghostscript CVE-2026-19547 and similar in Apache, PHP, GnuPG, wget, Microsoft Coreutils) and with an interesting moral, here's my latest article 😉 atos.net/en/lp/cybershield/a…
1
2
347
Microsoft Coreutils (version 2026.9.3 and earlier) tail.exe 🤭
1
3
631
Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks: atos.net/wp-content/uploads/…
5
90
419
97,566
My new article is out - Anatomy of Access: Windows Device Objects from a Security Perspective atos.net/en/lp/cybershield/a… I wish I had this resource 5 months ago 😉
1
4
432
Julian Horoszkiewicz retweeted
I find it frustrating that none of these "guardians" of Linux and open source have reacted to the OS-level age verification law: - Linux Foundation - Open Source Initiative - Free Software Foundation - Software Freedom Conservancy
233
792
5,719
178,343
Two more kernel-mode CVEs: CVE-2025-15037, CVE-2025-15038 (ASUS Business System Control Interface) 😉 asus.com/security-advisory
1
260
Julian Horoszkiewicz retweeted
We strongly oppose the Unified Attestation initiative and call for app developers supporting privacy, security and freedom on mobile to avoid it. Companies selling phones should not be deciding which operating systems people are allowed to use for apps. uattest.net/
50
964
5,706
146,149
Julian Horoszkiewicz retweeted
Important: We have revised our license to include additional jurisdictions implementing the age verification laws. Residents of Brazil are no longer authorized to use MidnightBSD. We will not implement ID checks as Brazil requires. (not just attesting age)

ALT Idiocracy Test GIF

127
288
2,415
217,108
My second public acknowledgement for a kernel-mode vulnerability: nvidia.com/en-us/security/ac… 😉 This one is for a pool overflow in NVIDIA Install Helper Service (NVI2SystemService64.sys). Because at the time I had discovered and reported the issue the product had already reached EOL, the vendor will not assign a CVE number to it. In other words, this vulnerability did not make it to CVE because it stayed unreported for too long. This policy approach to EOL products is quite common among vendors and exemplifies one of numerous scenarios for which CVE as a tool for vulnerability and risk management is not sufficient. For anyone interested in such scenarios, I recommend reading my article dedicated to this subject: hackingiscool.pl/slipping-th….
125
My first public acknowledgement for a kernel-mode vulnerability 😉 CVE pending. asus.com/security-advisory/#…
1
111
Julian Horoszkiewicz retweeted
The entire world is moving to criminalize privacy. We can't let them do that. Privacy is the foundation of a free society. Privacy is protection against powerful people. Privacy is normal.
We were contacted by a journalist at Le Parisien newspaper with this prompt: > I am preparing an article on the use of your secure personal data phone solution by drug traffickers and other criminals. Have you ever been contacted by the police? Are you aware that some of your clients might be criminals? And how does the company manage this issue? Absolutely no further details were provided about what was being claimed, who was making it or the basis for those being made about it. We could only provide a very generic response to this. Our response was heavily cut down and the references to human rights organizations, large tech companies and others using GrapheneOS weren't included. Our response was in English was translated by them: "we have no clients or customers" was turned into "nous n’avons ni clients ni usagers", etc... GrapheneOS is a freely available open source privacy project. It's obtained from our website, not shady dealers in dark alleys and the "dark web". It doesn't have a marketing budget and we certainly aren't promoting it through unlisted YouTube channels and the other nonsense that's being claimed. GrapheneOS has no such thing as the fake Snapchat feature that's described. What they're describing appears to be forks of GrapheneOS by shady companies infringing on our trademark. Those products may not even be truly based on GrapheneOS, similar to how ANOM used parts of it to pass it off as such. France is an increasingly authoritarian country on the brink of it getting far worse. They're already very strong supporters of EU Chat Control. Their fascist law enforcement is clearly ahead of the game pushing outrageous false claims about open source privacy projects. None of it is substantiated. iodéOS and /e/OS are based in France. iodéOS and /e/OS make devices dramatically more vulnerable while misleading users about privacy and security. These fake privacy products serve the interest of authoritarians rather than protecting people. /e/OS receives millions of euros in government funding. Those lag many months to years behind on providing standard Android privacy and security patches. They heavily encourage users to use devices without working disk encryption and important security protections. Their users have their data up for grabs by apps, services and governments who want it. There's a reason they're going after a legitimate privacy and security project developed outside of their jurisdiction rather than 2 companies based in France within their reach profiting from selling 'privacy' products. discuss.grapheneos.org/d/241… Here's that article: archive.is/AhMsj
66
952
4,524
175,054
Julian Horoszkiewicz retweeted
Do you want to be de-banked over digital ID rules? Vietnam is terminating bank accounts without a linked digital ID. We are not exaggerating when we say this is what could happen in the UK. It is already happening elsewhere. The people must remain in control, we must reject Digital ID.
57
733
1,628
23,709
Julian Horoszkiewicz retweeted
The UK is rolling out a national digital ID, the “Brit Card," despite 2.7M+ signatures against it. Tied to borders, benefits, and public services, it’s the spine of a new surveillance state. Combined with the Online Safety Act, identity verification is becoming mandatory to live, work, and speak.
UK Government Dismisses Public Outcry, Pushes Ahead with Controversial Digital ID Plan reclaimthenet.org/uk-digital…
16
84
328
15,423
Julian Horoszkiewicz retweeted
Isn’t she the person who proposed chat control? Seems like a weird behavior for someone who proposed the regulation. It’s not so fun when you are the one getting your messages analyzed is it now? Hypocrite.
Von der Leyen is Deleting Texts AGAIN
12
128
718
28,174
Julian Horoszkiewicz retweeted
🚨 Denmark keeps pushing for Chat Control - but we keep pushing back! Join us in our fight for #privacy ✊ Check why #Germany is the deciding factor 🇩🇪 and learn how to stop #Chatcontrol (including email addresses of German politicians): 👉 tuta.com/blog/chat-control-c…
34
303
996
38,150
Julian Horoszkiewicz retweeted
Americans have absolutely no idea how bad things are in Europe They are going into a totalitarian dictatorship the likes of which Orwell thought were too insane to come up with
is this a joke??????????
224
831
7,012
177,169
Julian Horoszkiewicz retweeted
ChatControl will allow the EU to use keyword filters to probe into what every private citizen says to friends and family about private topics, using AI and machine learning models to create heatmaps of dissidents. Combined with hate speech laws, it’s a recipe for utter disaster.
🇪🇺 My fellow Europeans You have to fight ChatControl 💪 Don't let @vonderleyen read your chats! metalhearf.fr/posts/chatcont…
376
3,128
8,788
425,783
CVE-2025-20074 - Local Privilege Escalation in Intel® Connectivity Performance Suite. intel.com/content/www/us/en/… #CVE #windows #EoP #privilegeescalation
100
CVE-2025-49797 - Local Privilege Escalation in Brother software (Windows). support.brother.com/g/b/faqe… Here is the full list of 1077 affected device models: support.brother.com/g/s/id/s…
101