Security Researcher @v12sec - CTF with Superflat / @0rganizers / ICC team Europe 22/23/24/25

May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
63
676
8,313
304,363
Rick de Jager retweeted
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
7
15
176
30,289
Rick de Jager retweeted
We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome. This PoC Downloads the file, then pops open the file manager for unsandboxed RCE (lovingly refered to as the full chain from temu)
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
3
32
372
24,818
Rick de Jager retweeted
Security researchers from Zellic and V12 are presenting at BSides Canberra this week! @farazsth98 on weaponizing a subtle kernel bug. @rdjgr on heap corruption bugs in ghostscript, and the many targets affected. Both talks will be on main stage on Friday morning, come say hi!
2
9
62
3,045
Interestingly this is a very similar primitive to one of the "unexploitable" dead ends in @trailofbits recent article about sandbox escapes. (although this is a slightly different bug) It did take some manual nudging for me to convince 5.6-sol that AppArmor could be bypassed :)
user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇
5
31
3,605
Rick de Jager retweeted
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
44
254
2,370
461,044
Rick de Jager retweeted
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps. PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance... Breakdown and POC. 🧵
5
55
332
47,320
Rick de Jager retweeted
Stored XSS in Forgejo, leading to full control over a victim's account:
1
10
41
4,484
Rick de Jager retweeted
XSS to full account takeover and wallet drain in Ditto. V12 found a deeplink parser bug that steals Nostr private keys with just one click. Here's how. 🧵
5
13
100
20,606
Rick de Jager retweeted
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud. V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything. Two separate critical bugs: arbitrary read and RCE. Here's how. 🧵
17
146
723
137,313
Rick de Jager retweeted
another one (poc) for redis server RCE: github.com/v12-security/pocs… handleClientsBlockedOnKey() use-after-free. patched in release 8.8.2.
found another one! redis 8.8.0 bidirectional RCE we will release poc after the patch
2
17
128
22,810
Rick de Jager retweeted
and here's our poc for postgres server RCE: github.com/v12-security/pocs… CVE-2026-14669. patched postgreSQL 18.6. poc for client RCE 🔜
And here's postgres bidirectional RCE no admin required, client infects server, server infects client ♻️🐛
4
56
300
33,055
Rick de Jager retweeted
🐬🐬🐬 dolphin rce 🐬🐬🐬
41
104
2,168
205,699
Rick de Jager retweeted
Type text into Wikipedia. Get the shell's output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found by V12. Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.
9
86
663
122,141
If you like my reverse-engineering, deobfuscation or malware work, I'm looking for a job - I am a security researcher with a knack for deep tooling/capability development and I've also done blue-team/pentesting work. DM me if you want my resume or if you want to ask questions!
I continue being a reverse-engineering thing. LyticEnzyme has been updated to support both closed and open type worlds, and to enable recovery of method symbols even from stripped bins! Stretch goal is pseudocode cleanup of SubstrateVM snippets using a custom Lang. Repr.
2
15
126
9,800
Rick de Jager retweeted
here's a mariadb RCE, what should we look at next?
13
45
396
72,112
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
44
254
2,370
461,044
With this proxy, we can: 1. Advertise a custom map named with a path traversal. 2. Overwrite the bug reporter exe. 3. Crash the victim’s game using a crash bug. (left as an exercise to the reader) A stealthier attacker would overwrite a game DLL instead and go undetected.
1
2
33
7,240
Finally, two huge shout-outs for the RE work: • @ZetaTwo for the excellent RE//verse talk • The intern who released AoE2DE_s_original.exe without obfuscation ;) The bug was patched in April (update 174992); MSRC just took a while to assign the CVE.
1
2
43
7,549