Here we go! Introducing ShadowClone - github.com/fyoorer/ShadowClo…! Run your tools with the power of cloud. Dynamically spawn upto 1000 copies of your script to run in parallel. Oh and it costs almost zero! #bugbounty #RECON #cloud

ALT Naruto Shadow Clone Jutsu GIF

7
66
165
Replying to @SLCyberSec
@SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products including Zendesk and Nuclei 😉 read the whole writeup here: searchlight-web-new.webflow.… and watch Nuclei getting pwned with a template file here 👇🏻
1
14
97
4,994
very cool!
Just published the writeup for my RCE in Google Cloud Application Integration, found last year - before this whole AI vulnpocalypse. nopnop.pro/2026/08/26/escapi…
324
Aditya Gujar retweeted
Type text into Wikipedia. Get the shell's output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found by V12. Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.
9
86
663
122,117
Aditya Gujar retweeted
Replying to @defcon
@DefCon 32 Matt (@emptynebuli) released 6 CE bugs affecting Diebold Nixdorf.. and now he is back with 9 more via the CryptoPro supply chain! 👀 Come join his #BHUSA briefing on Wednesday August 5th - you won't want to miss it! 🏧 🏦 @BlackHatEvents buff.ly/G8bvkom
1
4
802
Aditya Gujar retweeted
We decided to revisit an old research problem with some new LLM powered tooling. Check out our latest blog post to see how we approached this research, and the new Java deserialization gadget chains it discovered in just two days! buff.ly/CeAQZ2B
3
35
103
10,615
what's stopping you from copying your moltbot's credentials from ~/.config/moltbook/credentials.json and post as agent
3
1,654
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
46
366
2,550
415,687
Happy new year everyone 🎇
3
127
Aditya Gujar retweeted
Let's Hack Something Cute! A Reverse Engineering Journey into the Drawbot with Jessie buff.ly/yEWSICJ
5
7
2,451
Aditya Gujar retweeted
We just dove into our shelf of archived bug bounty write-ups from the most notable hackers! 🤠 In this issue, we selected 5 compelling articles (that are still relevant today) to share with you, from which you can learn something new! 😎 🧵 👇
1
19
89
13,466
Aditya Gujar retweeted
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
899
3,173
481,343
Aditya Gujar retweeted
Incredible! Congrats @DGukesh!
Norway Chess
82
313
6,560
246,681
hey @perplexity_ai get with the times bro @AravSrinivas
1
215
... but but deepseek logs your IP!!
Meta tracks your activity across millions of websites and apps, regardless of whether you use its platforms, and profits from that data through targeted ads. Here’s what you need to know if you want to limit the company’s ability to harvest and profit from your personal data. eff.org/deeplinks/2025/01/ma…
1
335
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium…
3
103
300
50,540
Aditya Gujar retweeted
MS08_067, obviously.
Which vulnerability is your favorite.
8
5
76
11,787
Aditya Gujar retweeted
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate. Full disclosure: samcurry.net/hacking-kia
84
957
3,512
344,988
This is like ShadowClone but better! Congrats❤️
2
12
1,209