Mathematician gone InfoSec. Interested in the Linux kernel, vulnerability research & reverse engineering.

ulisses retweeted
If you want to see how one incorrectly placed exclamation mark in the Linux kernel's nftables subsystem can lead to a local privilege escalation, have a look at my blog post. It covers a technical analysis of the bug I found and how it can be exploited blog.exodusintel.com/2026/06…
12
22
3,133
ulisses retweeted
here's a technical write-up i wrote on one of the kernel bugs we've found :)
In the first of a three-part series, @sam4k1 does a technical deep dive on CVE-2026-31532: a race condition in the Linux kernel's SocketCAN subsystem discovered, validated, and patched by our pipeline. bynar.io/blog/discovery-vali…
2
14
67
11,159
ulisses retweeted
CFP is open for SAFACon Party! This is your chance to share your coolest research at an exclusive, invite-only conference. Sunshine, spanish vibes, food, drinks, party, heated VR debates are guaranteed. All your favorite VR folks will be there, so should you. Ping me for details
9
34
4,753
It's official - #SAFACon 2026 will be held on the 8th of May in a secret location around Barcelona. Invites coming out from January, stay tuned for more info...
1
6
18
6,113
Honey wake up, a new alternative to userfaultfd / FUSE for lengthening race windows just dropped!! github.com/google/security-r…
2
24
137
13,673
Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130) willsroot.io/2025/09/ksmbd-0… Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration!
11
197
749
82,105
My new article: "Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"⚡️ I tell a bug collision story and introduce my pet project kernel-hack-drill, which helped me to exploit the hard bug that received @PwnieAwards 2025 a13xp0p0v.github.io/2025/09/…
4
84
258
35,092
Documented instructions for setting up KGDB on Pixel 8. Including getting kernel log over UART via USB-Cereal, building/flashing custom kernel, breaking into KGDB via /proc/sysrq-trigger or by sending SysRq-G over serial, dealing with watchdogs, etc. xairy.io/articles/pixel-kgdb
5
142
457
34,964
ulisses retweeted
with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓 sam4k.com/page-table-kernel-…
5
78
293
16,816
ulisses retweeted
ngl gang i might have got a bit lost in the sauce with this one, but if you're curious about how mmap() is implemented, check out part 2 of my memory management linternals series sam4k.com/linternals-explori…
14
57
4,056
🚨 New Blog Post: Exploiting CVE-2024-0582 via the Dirty Page Table Method! Discover how dangling pages can corrupt Page Table Entries (PTEs) and redirect user-space memory to kernel-space. Read the full analysis: kuzey.rs/posts/Dirty_Page_Ta… #ExploitDevelopment #KernelSecurity
30
119
7,024
Slides of my talk at #Zer0Con2025! ⚡️ Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits ⚡️ I presented the kernel-hack-drill open-source project and showed how it helped me to exploit CVE-2024-50264 in the Linux kernel. Enjoy! a13xp0p0v.github.io/img/Alex…
3
101
342
28,640
Just saw it mentioned on LWN, handy site for checking which distros enable a certain config option: oracle.github.io/kconfigs/?c…... Just replace UTS_RELEASE with whatever config option name minus CONFIG_, for example: oracle.github.io/kconfigs/?c…...
8
28
5,846
The Linux Memory Manager preorder and early access book nostarch.com/linux-memory-ma…
2
64
303
19,097