splitline 👁️🐈⬛ @_splitline_
友民党 / CTF with ${cYsTiCk} / script kiddie at @d3vc0r3 / Tâi-gí, zh-TW, en-US, es-PY / 🐈⬛ blog.splitline.tw Tsu-lô-Kuān, Formosa / Taiwan Joined July 2019-
Tweets373
-
Followers3K
-
Following637
-
Likes3K
@albinowax btw this feels like the part where I'm supposed to drop a blog link, maybe I should write faster 😭
@albinowax omg not me getting name-dropped by James Kettle well I should probably try to pwn the other half so I can keep avoiding storytelling...
DEVCORE CONFERENCE 2027 | CFP is open #Redteam, #VulnerabilityDiscovery, #Physicalsecurity, firmware and hardware RE, #AI attack surfaces. Bring the research that starts from a hacker's view. Deadline: Oct 11, 2026, 23:59 GMT+8 sessionize.com/devcoreconfere…
@albinowax @SEC_T_org Can’t wait for your talk too!
Tomorrow at @SEC_T_org, I’ll be breaking down the journey of how I found paths to compromise software supply chainS. We’re going down the Linux side this time ;)
@Bugcrowd guys give me one more like for 67
I earned $67.6767 for my submission on @Bugcrowd bugcrowd.com/h/{id: "splitline"} #ItTakesACrowd
0 = 1 proven in Lean. Exciting and novel result! github.com/endrazine/lean…
bug bounty still works, sure problem is how much critical infra sits nowhere near it most of it hasn't even had someone lazily throw a "hey chatgpt, find a 0-day for me make no mistakes" prompt at it yet
你是否也習慣將「官方網站下載」、「Microsoft Store 上架」或「官方套件管理庫」當作萬無一失的信任背書? 但「官方」真的就代表安全嗎? 從建置、簽章到發布,每一層都有可能成為攻擊者的切入點。 今年 HITCON,三場硬核議程將從三個完全不同的信任層級拆解軟體供應鏈,顛覆其安全想像: 💥 原初之穢:先莫管供應鍊夆毒,阮直接共官方發布源頭駭掉矣 | 講者:splitline 如果負責宣告「這是官方版本」的發布系統被駭了呢? 本場演講將揭露 Python、Ubuntu、Go、Alpine 與 Windows 套件生態系上游發布端的脆弱盲區。即便最終執行檔帶有合法數位簽章,只要上游建置環境遭滲透,簽章也可能無法保證你拿到的東西安全。 現場將公開多個實戰案例,展示攻擊者如何用非預期的邏輯漏洞直接拿下控制權。 ☠️ Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto | 講者:Seongsu Park 當原本專注於國家間諜行動的 APT 組織轉向加密貨幣撈金,攻擊者開始重新利用各種「可信」背書。 從架設高擬真交易平台、申請公司簽章,到成功把木馬化應用程式上架到 Microsoft Store,再結合 AI 輔助開發、macOS TCC 權限操作與精準白名單投遞,這場議程將展示官方通路沒有被攻破,也可以被攻擊者拿來建立信任,造成極致濫用。 🚨 黑吃黑: 瞄準駭客的供應鏈攻擊 | 講者:Jason3e7、Samuel 當獵人自己成為獵物? 攻擊者密切盯著高熱度 CVE 的公開資訊,在社群瘋傳、復現 PoC 的黃金時間,將高度混淆與多階段載入的後門深埋在 PyPI 工具的深層依賴鏈中。 當研究員為了復現漏洞,在終端機按下執行的瞬間,測試環境就已淪為被控端點。 三場議程,三個不同的信任位置。 從官方建置環境、官方的發布通路,到你以為只是研究工具的第三方依賴——當「看起來可信」不再等於「真的安全」,我們還能相信什麼? 📅 HITCON 2026:8 月 21 日-8 月 22 日 🔎 完整議程:hitcon.org/2026/zh-TW/age… 🎫 購票連結:hitcon.kktix.cc/events/hitcon-… #HITCON2026 #HITCON #供應鏈安全 #漏洞復現
My #BHUSA 2026 slides are online! It was an honor to share our AFD research and how a different perspective led to 30+ Windows kernel vulnerabilities. Blog post coming soon — check out the slides here: i.blackhat.com/BH-USA-26/Pres…
so i actually got more than one RCE chain (~2.5?) for SharePoint at Pwn2Own this year, even though i ended up using the freakishly simple one (for strategic reasons :p) here's another one of them: msrc.microsoft.com/update-guide/v…
@orange_8361 TM比我好看的没我骚🤷💨比我骚的没我好看
I put this meme into my bh talk lol @AikidoSecurity
Two of our researchers hit the #BHUSA stage for the first time. Angelboy(@scwuaptx ) shares how a different angle on AFD led to 30+ new #Windows kernel vulnerabilities. Splitline(@_splitline_ ) exposes backdoor risks in Go, Python & Flutter pipelines. #VulnerabilityResearch
@BlackHatEvents Teaser #2 x.com/_splitline_/st…
an incredibly simple but also incredibly critical bug i found on Python[.]org! big thanks to PSRT and the maintainers for the quick fix and thorough follow-up for the tl;dr: i can do this:
@BlackHatEvents Teaser #1 x.com/_splitline_/st…
some supply chain compromise
Next week at @BlackHatEvents #BHUSA, I'll present “Born Corrupted: How We Backdoored Trusted Language Binaries” We found ways to compromise Python, Go, Flutter & Julia at the supply-chain layer, turning trusted bins into whatever hackers want them to be! Check out the abstract:
crazyman_army @CrazymanArmy
6K Followers 2K Following CTFer / APT hunter / RedTeam / BlueTeam the member of @r3kapig the leader of @ShadowChasing1 CVE-2022-30190 find job opportunities opinions are own not group
cts🌸 @gf_256
68K Followers 1K Following founder and hacker @zellic_io @v12sec @pb_ctf yt https://t.co/nlNai6iiMP
Huli | lang: zh-Hant-... @hulitw
5K Followers 544 Following Front-end <=> Security | English account: @aszx87410 | 偶爾跟 @Water_Paddler 一起打 CTF | 無聊的時候喜歡寫文章
NiNi @terrynini38514
3K Followers 646 Following Security Researcher at @d3vc0r3 / Pwn2Own Master of Pwn (Toronto 2022, Berlin 2026) / CTFer @balsnctf
Jim Huang @jserv
12K Followers 8K Following "A hacker, a lecturer, a father" // Adjunct faculty at @NCKU_official
Moriarty @Rudrakshsaini2
2K Followers 2K Following I like cats , computers and ctf’s | Captain @thehackerscrew1 | Slutt datafag
C.A.Lee 🇹🇼 @calee0219
495 Followers 1K Following CS Master in NCTU, Taiwan. Majoring in Infrastructure and Networking. Now working on free5GC project for next generation core network.
sahuang @sahuang97
4K Followers 804 Following Founder @ProjectSekaiCTF | Security Research & AI @osec_io | Ex Software Engineer @Microsoft | Maimai & Chunithm 虹レ
ptr-yudai @ptrYudai
6K Followers 364 Following 🍣🍣🍣 https://t.co/5OmzwCTPea 🍣🥺🍣 @zer0pts の猫 🐯 🍣🍣🍣 https://t.co/5OmzwCTPea
Steven Lin @5teven1in
391 Followers 393 Following A software engineer interested in Cybersecurity and Machine Learning, and also a CTFer focused on Reverse & Pwn @ BambooFox 🎉.
小克 🌤 @littlegoodjack
2K Followers 2K Following Laravel 兼 AWS 小小新創工程師 // 結果現在寫 FastAPI // 但我喜歡研究產品和 UX 欸 // 路線圖可能沒空翻了 🥲 https://t.co/nFVjCoYkDB // #UNIQLO 狂熱粉絲 👉 https://t.co/mdbTJ9Kn7w // Mastodon: https://t.co/9lF6bHliuy
Samuel Tang @mystiz613
1K Followers 335 Following AKA mystiz. Tweets on 🇭🇰 and Cybersec. Opinions are my own.
Ark @arkark_
3K Followers 883 Following Into experimental/deprecated features | CTF player | ex-traP
sqrtrev @sqrtrev
5K Followers 716 Following Captain of @SuperGuesser / DEFCON 29 - 34 Finalist Security Researcher @ENKI_official_X
zayne (zeyu) zhang @zeyu1337
4K Followers 2K Following 🇸🇬 | co-founder @hacktronai - your AI teammate for security | @projecteurope_ 🇪🇺 | cs @cambridge_uni 🇬🇧 | prev: @cure53berlin @tiktok_us, ogp | @Water_Paddler
kurenaif🪄🗝 @fwarashi
6K Followers 3K Following 魔法のような技術を、魔法のような表現方法で。 主にCTFやセキュリティ関連の話題を取り扱うVTuber 衣装のデザインやモデラーなどの情報はこちらから→ https://t.co/IHsDjTIYOc header: @sawararado icon:@Kurage_cc
zhonb @zh0nb
27 Followers 515 Following
Ferran Plaza @ferranplaza
38 Followers 474 Following
OffensivePython @OffensivePython
481 Followers 159 Following Blog about using python for penetration testing: Networking, Forensics, Reverse Engineering... and alot of issues come a cross. We do everything using Python
Sky Grip @skygrip777
10 Followers 1K Following
Maor Gordon @GordonMaor
18 Followers 319 Following
Victor4XCTF @Victor4Xctf
7 Followers 557 Following
𝖆𝖓𝖔𝖆𝖓�... @anoanymous9090
1 Followers 168 Following 🎭 root@anon:~# ./justice.sh 🖤 🕳️ Bio: Deleted from state databases. 🌪️ Behind this mask lies a network of millions. Armed with zero-day payloads,
Ignacio @1gn1ti0n
7 Followers 172 Following
Katocha @K4t0ch4
0 Followers 54 Following
wh0am1 🇳🇵 @CYBERWAR142017
48 Followers 2K Following a hacker mindset with security researchers join this link for learning: https://t.co/p17L9ExsOs
Rose @Rose85055381
75 Followers 1K Following
may keen gyn @kenjoe41
153 Followers 1K Following pwn all the things, this must be kenjoe41 @[email protected]
家貓 @HouseCat1288
1 Followers 284 Following
Hippie @hiippiiie
530 Followers 677 Following Pentester 🦖 OSINT, Web @Rhackgondins🚩 @cogitosint🔍 Working on @vulnotes 👾
Eking @elephant_bug
2 Followers 73 Following
RTFM[ChOkO] @ChOkO088
1K Followers 4K Following RTFM - Red Team Freakin Maniacs CTF Team's co-founder. Zerg turtle user | BJJ & Chess n00b | OSCP
Amit @offensivedev
69 Followers 1K Following
aby ♡ @aby860
473 Followers 24 Following ᡕᠵ᠊ᡃ່࡚ࠢ⸝່ࠡࠣ᠊߯᠆ࠣ࠘ᡁࠣ࠘᠊᠊ࠢ࠘𐡏 ⋆ ࣪.* ♡♡♡ building agentic hacking tools
NULL @ok111
8 Followers 1K Following
Osama Osmani @osamausmani1996
340 Followers 2K Following Programmer in Daylight - Hacker in NightLight
underscore @underscore29220
2 Followers 15 Following
pan @mox0A
0 Followers 54 Following
harisec @har1sec
8K Followers 3K Following Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp. Orson Kovacs.
darkmage @evildojo666
1K Followers 626 Following Gamedev / Hacker / Play My Games: https://t.co/BKIrm4FjRx
Romas Sirutavicius @RomasSiru
5 Followers 65 Following
Varun @varun0x1
42 Followers 1K Following
pasqualino @pasqualinooo
407 Followers 3K Following Webmarketing Worker - Hardcore Drummer - #infosec Addict - Electronic Performer
edoardottt🐘 @edoardottt2
2K Followers 1K Following cybersec research & stuff, (open-source) software
Himanshu Singh @hk755a2
6 Followers 724 Following
jjmina @jjmina22125
1 Followers 59 Following
hamza t @4390c336
2 Followers 167 Following
crazyman_army @CrazymanArmy
6K Followers 2K Following CTFer / APT hunter / RedTeam / BlueTeam the member of @r3kapig the leader of @ShadowChasing1 CVE-2022-30190 find job opportunities opinions are own not group
cts🌸 @gf_256
68K Followers 1K Following founder and hacker @zellic_io @v12sec @pb_ctf yt https://t.co/nlNai6iiMP
Huli | lang: zh-Hant-... @hulitw
5K Followers 544 Following Front-end <=> Security | English account: @aszx87410 | 偶爾跟 @Water_Paddler 一起打 CTF | 無聊的時候喜歡寫文章
NiNi @terrynini38514
3K Followers 646 Following Security Researcher at @d3vc0r3 / Pwn2Own Master of Pwn (Toronto 2022, Berlin 2026) / CTFer @balsnctf
Jim Huang @jserv
12K Followers 8K Following "A hacker, a lecturer, a father" // Adjunct faculty at @NCKU_official
TrendAI Zero Day Init... @thezdi
89K Followers 18 Following TrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Moriarty @Rudrakshsaini2
2K Followers 2K Following I like cats , computers and ctf’s | Captain @thehackerscrew1 | Slutt datafag
VIE, slayyyter discip... @vie_pls
2K Followers 219 Following @maplebaconctf @mmm_ctf_team @bbb_ctf --- 4 time DEF CON CTF winner (2022-2025) and organizer (2026-), human artist and security researcher. NO AI
C.A.Lee 🇹🇼 @calee0219
495 Followers 1K Following CS Master in NCTU, Taiwan. Majoring in Infrastructure and Networking. Now working on free5GC project for next generation core network.
sahuang @sahuang97
4K Followers 804 Following Founder @ProjectSekaiCTF | Security Research & AI @osec_io | Ex Software Engineer @Microsoft | Maimai & Chunithm 虹レ
Intigriti @intigriti
215K Followers 670 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
ptr-yudai @ptrYudai
6K Followers 364 Following 🍣🍣🍣 https://t.co/5OmzwCTPea 🍣🥺🍣 @zer0pts の猫 🐯 🍣🍣🍣 https://t.co/5OmzwCTPea
Steven Lin @5teven1in
391 Followers 393 Following A software engineer interested in Cybersecurity and Machine Learning, and also a CTFer focused on Reverse & Pwn @ BambooFox 🎉.
Samuel Tang @mystiz613
1K Followers 335 Following AKA mystiz. Tweets on 🇭🇰 and Cybersec. Opinions are my own.
Ark @arkark_
3K Followers 883 Following Into experimental/deprecated features | CTF player | ex-traP
sqrtrev @sqrtrev
5K Followers 716 Following Captain of @SuperGuesser / DEFCON 29 - 34 Finalist Security Researcher @ENKI_official_X
Justin Gardner @Rhynorater
38K Followers 2K Following Christian | Full-time Bug Bounty Hunter | Host of @ctbbpodcast | Advisor @CaidoIO | 4x LHE MVH | 🗣️ English, 日本語 | ♥️ @mariahchan_ ♥️
Jorian @J0R1AN
3K Followers 451 Following Normalize being weird. (also here: https://t.co/cr9Y0kDEBi)
Andrea P @decoder_it
9K Followers 324 Following Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
Samuel Groß @5aelo
25K Followers 524 Following Working on Project Zero, Big Sleep, and V8 Security. Personal account. Also @[email protected] and https://t.co/aVitnPjBie
Tom Stacey @t0xodile
1K Followers 272 Following Security researcher at PortSwigger. You can find all of my write-ups and research at https://t.co/2chUIHKb4n.
xia0o0o0o @Nyaaaaa_ovo
3K Followers 1K Following Do shit research. DEFCON 31/32/33 finalist. CTF with @r3kapig. BlackHat speaker. Co-founder and ultimate pwning machine @nebusecurity. Prev. at @zellic_io.
nedwill @NedWilliamson
16K Followers 688 Following
Gergely Kalman @gergely_kalman
3K Followers 506 Following bug bounty hunter I guess @[email protected]
Chipadelphia @chipadelphia
218 Followers 972 Following @Tesla, @SpaceX, @BugCrowd | Investor, Open Source Supporter, FSD Beta, SpaceX/Starlink BugBounty | @MIT Aerospace
Nagli @galnagli
48K Followers 515 Following hacker; head of offensive ai @wiz_io, now at @google; post-training, gemini cyber & agentic pentesting; $3,000,000 bug bounty hunter; arsenal
Bug Bounty Village @BugBountyDEFCON
10K Followers 610 Following Official X account for the Bug Bounty Village @DEFCON. Founded by @infinitelogins and @arl_rose.
Ange @angealbertini
25K Followers 925 Following Reverse engineer, file formats expert. Corkami, CPS2Shock, PoC||GTFO, Sha1tered, Magika... Security engineer @ Google. He/him.
CISA Cyber @CISACyber
303K Followers 71 Following Part of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
堇姬 Naup @naup96721
719 Followers 1K Following naup96321 I'm a CTF player @ pwner. And i also love Linux kernel. Now, I play CTF with CakeisTheFake / SquidProxyLovers, Now also learning at NYCU CS
Jazzy @ret2jazzy
6K Followers 1K Following solving problems @zellic_io @v12sec and challenges @pb_ctf
Stephen Fewer @stephenfewer
10K Followers 261 Following Senior Principal Security Researcher at @rapid7. Specializing in software vulnerabilities and exploitation.
Assetnote @assetnote
11K Followers 0 Following Assetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
Joseph Thacker @rez0__
74K Followers 1K Following christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 💻 https://t.co/iPdpsEAc1h 🤖 https://t.co/EVhQl8HTlp 📚 https://t.co/MMmhw0cnaz
Off-By-One Conference @offbyoneconf
2K Followers 257 Following A premier gathering of offensive cybersecurity professionals, researchers, thought leaders and innovators from around the region.
Pam O’Shea @pamoshea
3K Followers 5K Following Security consultant | @BlackHatEvents @BSidesCbr @BSidesSG @OWASPMelbourne Review Boards | @SDR_Melbourne | VK3HXX |@haXX_group | @sheasecurity🖖📚☕️
Omar Espino • @omespino
11K Followers 731 Following Security hall of fame: Google VRP • Microsoft • Reddit • Telegram • Twitter • Facebook • Apple • Netflix • Slack • etc •
skull @brutecat
9K Followers 406 Following security @google. 21. i run a blog @ https://t.co/cBW6gzSS5u
紅鮎 @A7oxHmPxpw55878
815 Followers 103 Following よくわからんけどポケットの中でスマホが暴れてたみたいで、前の垢にはいれなくなっちゃったです。遺跡垢を掘り起こせたのでオリジナルの漫画を描き始めました。理性で我慢する大人の男と無自覚まっすぐ男のBLです。 最後まで描き切るためのアカウント。 おじさん攻。独り言多い人見知りです。 無言フォロー失礼します。無断転載禁止。
Stefan Esser @i0n1c
108K Followers 465 Following CEO of @Antid0tecom (former CEO of @SektionEins) (contact: [email protected])
lcamtuf @lcamtuf
40K Followers 499 Following Blog: https://t.co/j7rfeVwqXc Homepage: https://t.co/iFAXZxCgg9
bot @securit31482176
15 Followers 314 Following
Chumy @rm_rf_chumy
508 Followers 256 Following Nice restaurant list: https://t.co/dBNyP2A0iq For life: https://t.co/bE2tYEwXyO
Microsoft BlueHat @MSFTBlueHat
5K Followers 216 Following BlueHat is where the security research community and @Microsoft security pros come together as peers, to connect, share and learn. Run by @MSFTSecResponse
Frank Wu @FrankOverF1ow
2K Followers 569 Following CTFer (Rev & Pwn & Web) hacking with @r3kapig for fun. Founder @nebusecurity | DEFCON 33 Finalist | BH USA'26 Play with Linux kernel / Android / PHP / V8.
LJP @ljp_tw
64 Followers 182 Following
Azrael @azraelxuemo
202 Followers 33 Following Spoken at: Black Hat EU 2024, Zer0con 2025, Offbyone 2025, Black Hat USA 2025, DEF CON 33, Zer0con 2026, Black Hat Asia 2026, SAFACON 2026, DeepSec, DEF CON 34
Thomas Roccia 🤘 @fr0gger_
35K Followers 2K Following Founder @SecurityBreakAI AI Security x Threat Intel · Threat Researcher · Creator of #Unprotect & #NOVA · Python 🧡 · Prev @Microsoft @McAfee_Labs
Attack and Defense @attackndefense
1K Followers 8 Following @[email protected] - Mozilla's Security Internals for Security Engineers, Security Researchers, and Bug Bounty Hunters.
Alex Moshkov @amoshkov
2K Followers 1K Following Community Bro @ 🟥 Positive Technologies / @PTSWARM / @ptdbugs / @StandoffBB / #PHTalks / #PHDays / #PHCamp
itewqq @lyq_sqsp
3K Followers 747 Following Security researcher @DarknavyOrg. CTF player @0ops_ctf. Somehow got a PhD on hardware stuff @SJTU1896. Opinions/Shitposts are my own.
fox hsiao @pirrer
27K Followers 1K Following https://t.co/ADltMSqInz A starter, Founder of iCook / INSIDE










































