Abdulmohsen @cppbruh
OSCP, OSCE, OSEE debugger Joined July 2017-
Tweets5K
-
Followers382
-
Following4K
-
Likes6K
🚨 Mandiant & GTIG have identified active zero-day exploitation of Citrix NetScaler appliances (CVE-2026-88772). Attackers are deploying custom tools like WHIPSHOT. Since edge devices lack EDR, use this hunting checklist to detect compromise. 📋 goo.gle/4dfZzxb
Pack Alert: Arctic Wolf Labs observed active exploitation of Citrix NetScaler CVE-2026-88771 involving payload retrieval, script execution, reverse-shell attempts, and post-exploitation tooling. The objective appears to be long-term access. Learn more: bit.ly/4rJYBiK
1/4 NetScaler exploitation IOCs (CVE-2026-88771 suspected) 🚨 Sharing detection info from a failed exploitation attempt seen on 22 Sep. Unauthenticated, two-stage, fully automated. Shared for detection only, so you can check your own logs. #NetScaler #Citrix #DFIR
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics/th…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar.
Took around 1h to solve all of the challenges with this.... 🤯
The official IDA MCP Server is here. It's free, open source, and works with any LLM. Your agent writes IDAPython, uses ~20% fewer tokens, and can share an IDB with you in real time. 𝚞𝚟𝚡 𝚒𝚍𝚊-𝚑𝚌𝚕𝚒 𝚖𝚌𝚙 𝚒𝚗𝚜𝚝𝚊𝚕𝚕 hex-rays.com/blog/hex-rays-… (copy-paste: uvx ida-hcli
EtherHiding Decrypting ClickFix C2 with CyberChef and obf-io.deobfuscate.io
Can you imagine? Veterans of 8200 working in an Israeli cybersecurity company?! How deep does this go????
Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops high-value exploits: including zero-click tools that break into computers and smartphones and has grown rapidly into a multimillion-euro supplier for governments and spyware makers. An
🥷 Now we can inject a payload into a remote process without using VirtualAllocEx and WriteProcessMemory. No need to suspend the target process New technique to evade EDRs: Github: TwoSevenOneT/InjectSetConsole #redteam #pentest #antimalware
My blog post on the Iran-backed APT group MuddyWater is out. MuddyWater uses tools from TAG-150, a Malware-as-a-Service platform run by Russian-speaking cybercriminals. In this campaign, an MSI package is distributed through Amadey, installs the Deno-based DinDoor agent and runs it in memory. The agent collects browser passwords, cookies and crypto wallet data, and the final stage of the chain connects to a CastleRAT C2 server. medium.com/@Root0ne/muddy…
PoC is public. Internet-facing MikroTik SSH → full admin. No password. No key. MikroTrick: CVE-2026-67279 + CVE-2026-86060. Fresh on CISA KEV. Chain: password auth as `-2` (rejected but left sticky) → pre-auth rekey drops the auth gate → `/nova/bin/login` treats `-2` as “read identity + policy from fd 2” → all-ones mask = full admin. IoC: `login failure for user -2 via ssh` then `user added by ssh:-2@…` PoC: github.com/digiprosec/Mic… Writeup: cert.pl/en/posts/2026/… Patch: 7.23.4 / 7.24.2 / 6.49.21 - then hunt `ops` + Flagged. #MikroTik #RouterOS #CVE #PoC #InfoSec #CyberSecurity
“ Two vulnerabilities - both RCE. Unpatched, 0days. Exploited in-the-wild - discovered during forensics. “
We have been made aware of further info, which we are sharing. We had no idea Citrix sysadmins were like GTA6 fans - so friendly 🤗 Please, direct further questions to Citrix. We are not Citrix PSIRT (despite it occasionally looking that way). Citrix comms & patches are
An additional Chinese APT actor (UTA0565) was observed chaining 0-day exploits in Google Chrome and Microsoft Windows via fake websites SEPTEMBER 21, 2026 volexity.com/blog/2026/09/2…
Insane bug
How I Could've Accessed 17 Trillion Microsoft Records blog.faav.net/how-i-couldve-… :)
How do I reverse engineer these days? I don't, I let coding agents do it.
For instance, if I start from a fresh VM, I simply tell the agent to go clone, build and setup *GhidraSQL* and use it to analyze
ghidrasql 0.0.7 is out: control Ghidra's auto-analysis from SQL. UPDATE program_options to turn analyzers off, INSERT INTO analysis_passes to re-run analysis, DELETE to cancel it. Or skip slow analyzers at import with --analyzers-off. github.com/0xeb/ghidrasql…
👀 NEW | ClearFake / ClickFix (Smart Contract C2) - Observed IOCs [Compromised Injected Hosts (Initial Access)] • ubgeneraltrading[.]com (IP: 162.241.216[.]86) • unitedpowerprojects[.]com (IP: 82.25.127[.]247) • unitedtransport[.]co[.]in (IP: 2a02:4780:11:1427:0:236d:9f44:10) • www[.]vault55[.]com (IP: 69.163.179[.]165) • vbbs[.]edu[.]vn (IP: 103.90.233[.]81) [Injected Script Obfuscation Layer] • In-line Double-XOR + Base64 JavaScript Loader • Technique: fromCharCode(arr[i] ^ k1) -> atob() -> charCodeAt() ^ k2 • Function: Executes decentralized JSON-RPC query to fetch live C2 [Decentralized Blockchain C2 Infrastructure (Polygon MATIC)] • Smart Contract: 0xB6bC9e1D0b2fB96Ab7C47E04Cb0BE477410bC1f2 • Method Hash: 0xb68d1809 • Public RPC: polygon-bor-rpc.publicnode[.]com | 1rpc[.]io/matic [Resolved Live C2 / TDS Infrastructure] • hxxps://idcool[.]codes [Observed TDS / Staging Delivery URLs] • hxxps://idcool[.]codes/api.php?s=a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402 #ClickFix #ClearFake #ThreatIntel #Malware #CyberSecurity #IOC
Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee projectblack.io/blog/bypassing…
I was analyzing the one hash in the context of ShinyHunters-related infrastructure, and one part of the @urlscanio dataset stood out. I couldn’t find any vendor reporting on these domains from when they were active around 6-10 months ago. They appear to have been completely missed at the time, and apparently I missed them too 😅 Three domains in the results appear to mimic legitimate organizations: sso-justeattakeaway[.]com internal-justeattakeaway[.]com fffenterprisesinternal[.]com The first two closely imitate Just Eat Takeaway, whose legitimate corporate domain is justeattakeaway.com. The third appears designed to resemble FFF Enterprises, whose legitimate domain is fffenterprises.com. FFF Enterprises is a major U.S. specialty pharmaceutical and biopharmaceutical distributor serving hospitals, pharmacies and other healthcare providers. #malware #shinyhunters #tracking #threatactors
🕵️ I analysed 151 days of UNC6671 registry activity: 43 domains and 120 hostnames. The pattern? 97.7% weekday provisioning, Friday peaks, micro-batches, recycled labels and a sharp pivot away from “passkey” naming. US workday or European after-hours? 👀 #UNC6671
Another root domain: mfasettings[.]com , #UNC6671 Follows the same identity/MFA-themed naming pattern, no subdomain yet. Registered on Sep 21 via NICENIC, uses Cloudflare NS, and currently resolves to 102.220.163[.]94 (VPS Dedicated LLC).
🚨 UNC6671 INFRA UPDATE New root domain: ssosettings[.]com Observed hostnames reference GoDaddy, Teads, ICANN + Upgrade 👀 More pivots to follow. #UNC6671
WTF
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Pietro Borrello @borrello_pietro
3K Followers 640 Following Security Researcher | PhD @SapienzaRoma | Pwner at @TheRomanXpl0it and @mhackeroni | https://t.co/g77o9Ojdjf | https://t.co/q5KZ4e8wkX
Megatron @TheM3gatr0n
770 Followers 1K Following Just a random cyber guy #ThreatIntelligence | #MalwareAnalysis | #DarkWebResearch | #Geopolitics Student | Views and tweets are my own :)
سامر @SamerAlGhamdi_
93 Followers 74 Following CS Student at @kauedu_sa | #Cybersecurity | #eJPT #eWPT #eWPTX
rebasedaily @rebasedaily
148 Followers 2K Following never leaving home without headphones and a fully charged laptop 🎒🎧 lately
Okan Kurtulus @okan_kurtuluss
2K Followers 480 Following Cyber Security | OSEP | OSWE | OSCP | eMAPT
Maria Schmidt @MariaSchmirv
52 Followers 1K Following
📕「マルウエ�... @MalwareBibleJP
9K Followers 2K Following 「マルウエアの教科書」著者📕吉川孝志/Cyber Intelligence Group(CIG)リーダー/私本人が管理するアカウントです。読者の皆様の温かいご支援に支えられ感謝しています✨ありがとうございます!(ぜひAmazonへも星⭐️評価をいただけると嬉しいです🙇♂️)日経NETWORKでも毎月連載中!
qatux @PwndByQatux
15 Followers 277 Following
cr3ghost @cr3ghost
8K Followers 532 Following Curating security, exploit & vulnerability research, tools & free resources | Reverse engineering | Malware | Threat intel | Red/Blue Team | AI | Game Hacking.
新月 @fubukiyokiyoki
3K Followers 5K Following a.k.a singetu0096 Network | OffensiveSecurity | CTF | BugBounty 白上フブキと蒼宮よづりと羽澄さひろと久々湊るいが好き CTF team:@sknb_ctf , @Water_Paddler icon:@hasikureteruna Thanks!
Dipeua Berthold @_ber1y
108 Followers 462 Following I'm just a person who likes to write code and look for vulnerabilities in applications.
SegunGreat de Dev @segun_great
79 Followers 507 Following Fullstack Engineer • PHP, Laravel, Node.js, NestJS, Vue, React, Flutter, TS & JS. Building web & mobile apps • Sharing dev lessons, systems & random insights 🎹
Ėjaaż @crypt_punk7213_
109 Followers 3K Following Looking for patterns | AI @limitlessFT | @26cryptocapital | Formerly @coinbase @consensys
Emalia @Emalia001
6 Followers 228 Following
tmniosc @tmniosc_system
13 Followers 1K Following
bl4ck4rch @bl4ckarch
288 Followers 439 Following Security Researcher & Pentester at @orangecyberdef | CTF enthusiast | @hackthebox_eu MVP 2025
Zhixin Tu @tu_zhixin
28 Followers 34 Following
Wenxiang Qian @qian_wenxiang
215 Followers 175 Following AI + Software Security Architect | Blackhat USA/DEFCON/HITB Speaker My former account @leonwxqian is suspended by twitter, create this instead.
tsune @e65537
386 Followers 492 Following Your Kernel is ass. Privilege escalated. '25 Codegate Junior, '25 Midnight Flag 🥉, '25 TSG, BlackHat Finalist こんにちは 天才を目指しています
kernullist @kernullist
1K Followers 3K Following Security researcher focused on Windows internals. https://t.co/1hoZxnzccW
VMunProtect @vmunprotect
4 Followers 158 Following
T ⧫ tamjid0x01.eth ... @tamjid0x01
1K Followers 3K Following Security Engineer | Security & Hacking #DeFi #NFT | $ETH Smart contract security 🤖
snappyfeet @snappy_feet
103 Followers 362 Following I like to debug. ps: everything here is my own opinion and not my employers view
monkeontheroof @monke0ntheroof
14 Followers 999 Following https://t.co/lZp8D1suOq https://t.co/5ZquK6h7Qa
Nikhil @Ox4d5a
19K Followers 2K Following Penetration Tester | i XCHG 0's 1's and do hacks | Red Team Sorcery https://t.co/6LUhkvN2hz | #eJPT | #OSCP | #CRTP | #CRTA | #CESP | #CRTE
0ca @francisco_oca
1K Followers 1K Following Developing BoxPwnr to benchmark LLM models against cyber security tasks
Yonadav Noiman @yonadavn
33 Followers 153 Following
Darius Houle (darbonz... @dariushoule
253 Followers 621 Following Hacker, builder, appsec practitioner, security researcher. Probable world championship player of the creative masterpiece: Lemmings (1991)
obscaries ❘ AppSec @obscaries
4K Followers 1K Following ✦ Application Security Researcher ✦ Breaking the modern web stack ✦ Focused on client-side security ✦ Impact-driven tactics ⚡ 🌿 Open to collaborations
🌿المزيونه�... @WASF_1
879 Followers 5K Following
Ricardo Narvaja @ricnar456
6K Followers 2K Following
Lamin Camara @camar8119
122 Followers 3K Following Trust in the Lord with all your heart, and do not lean on your own understanding. In all your ways acknowledge him, and he will make straight your paths.
Rakan Alotaibi - (hx) @hxteam
1K Followers 1K Following
Intigriti @intigriti
216K Followers 670 Following Bug bounty & VDP platform trusted by the world’s largest organisations! 🌍
mRr3b00t @UK_Daniel_Card
126K Followers 8K Following Chief Artificial Intelligence Cyber Security Scientist Superintelligence-grade security former Helpdesk AI infection status: clean Task Force 29
John Hammond @_JohnHammond
327K Followers 3K Following Cybersecurity Researcher @HuntressLabs Just Hacking Training @JustHackingHQ w/ @ethicalhacker https://t.co/UtsNJiyQtS && https://t.co/narO3sz7y6
Sam Curry @samwcyo
102K Followers 1K Following
vx-underground @vxunderground
450K Followers 382 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Nicolas Krassas @Dinosn
162K Followers 791 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
raptor @0xdea
14K Followers 17 Following When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl.
0xor0ne @0xor0ne
94K Followers 508 Following Cybersecurity | Reverse Engineering | Vulnerability Research | Embedded & Silicon Security | My Tweets, My Opinions :)
ippsec @ippsec
125K Followers 372 Following
Mike Felch (Stay Read... @ustayready
18K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ | RE/VR/ED
Gareth Heyes \u2028 @garethheyes
39K Followers 1K Following Web security researcher at PortSwigger. Author of JS for Hackers and Hackvertor. https://t.co/akVN6ZR4C8
Florian Hansemann @CyberWarship
90K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
STÖK ✌️ @stokfredrik
139K Followers 1K Following Hi.. im that hacker / creative that your friends told you about.,
Adam Chester 🏴�... @_xpn_
40K Followers 555 Following TRACE at @SpecterOps | Blog at https://t.co/tjfTOllCEu
Chetan Nayak (Brute R... @NinjaParanoid
32K Followers 0 Following Official account for BruteRatelC4 | Developing the most powerful and sophisticated pentest software for Red Team engagements | DarkVortex founder/CEO
MalwareTech @MalwareTechBlog
271K Followers 1 Following Not here anymore. Profiles: https://t.co/sFoOuGmYK2
OccupytheWeb @three_cube
270K Followers 3K Following Pentester, Forensic investigator, and former college professor. Trained hackers at each US military and intelligence. Visit me at https://t.co/G478wug0p4
Ben Sadeghipour @NahamSec
253K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
Arctic Wolf @AWNetworks
5K Followers 507 Following At Arctic Wolf, our mission is to End Cyber Risk through effective security operations.
Tyler McLellan @tylabs
3K Followers 593 Following Intrusion aficionado. @Google/@Mandiant GTIG Frontline Intelligence Operations
Marius Sandbu @msandbu
5K Followers 2K Following Azure MVP | vExpert NSX | VMware EUC Champion | Author | Speaker | AWS, Google | Blogger | Cloud Evangelist @SopraSteria_no
Maurice @Maurice_Sec
50 Followers 32 Following
!Manan @0xManan
2K Followers 1K Following Security Research & Compliance | 5xCVEs | Trying to live by my standards - i'm weird, i hack🕊️💸
Elias Bachaalany @eliasbchlny
378 Followers 1K Following https://t.co/odQ1t0Qw9k | @binarywizards | https://t.co/dTlbOFZEhN | https://t.co/5miZ3yZbq6
Or Hiltch @_orcaman
20K Followers 5K Following 🧛🏼 @Accomplish_ai. Prev: Co-Founder, CTO @ Skyline AI (acquired by $JLL), StreamRail (acquired by $U), Lecturer @TelAvivUni, security research @AVGFree
masaomi346 @masaomi346
2K Followers 814 Following Baby Cyber Threat Intelligence Researcher / Interested in Malware, Phishing, Scam, etc.
Coral Jasmine @Fact_Finder03
1K Followers 194 Following
Jamf Threat Labs @JamfThreatLabs
381 Followers 35 Following Mac security research and threat hunting team. Sharing findings discovered by @JamfThreatLabs at @JamfSoftware.
João Vitor(Keowu) @keowu
567 Followers 30 Following Reverse & EDR Dev | Jesus Follower | My RE friends discord server: discord dot gg/fWhvHXtzxy | https://t.co/cPfrnwC6jN | I just know that idk anything | 🇯🇵 🇺🇸 🇧🇷
Megatron @TheM3gatr0n
770 Followers 1K Following Just a random cyber guy #ThreatIntelligence | #MalwareAnalysis | #DarkWebResearch | #Geopolitics Student | Views and tweets are my own :)
Adam 'pi3' Zabrocki @Adam_pi3
4K Followers 343 Following Director of Offensive Security @NVIDIA, architecting @RISC_V, @LKRG_org Founder, @BlackHatEvents & @Defcon Speaker, #Phrack author, @PwnieAwards nominee
Eyal Sela @eyalsela
3K Followers 451 Following Director of Threat Intelligence at Gambit Security. Signal: eyalsela.10 , Keybase: eyals
Bert-Jan 🛡️ @BertJanCyber
5K Followers 629 Following Defensive Security Expert | Microsoft Security MVP | https://t.co/Tu1l2ZFe0T
theMiddle @AndreaTheMiddle
1K Followers 273 Following Founder @rev3rsesecurity / Fine-Tuning for cybersecurity
Volexity @Volexity
8K Followers 7 Following Volexity is a cybersecurity firm founded by the pioneers of memory forensics. Volexity delivers solutions & services to governments & organizations worldwide.
Chris Duggan @TLP_R3D
7K Followers 3K Following Full-Time Padel Player | MDS Legendary Finisher | Ultra Endurance | Author- The Intent Model
Austin Larsen @AustinLarsen_
2K Followers 1K Following Principal Analyst - Google Threat Intelligence Group Investigating significant cyber events.
Rolland Maël @mael91620
45 Followers 21 Following
Full Context @fullctx
326 Followers 152 Following 1 line is all it takes. Local models. Open agents. The full context. Building in public.
Joe Security @joe4security
8K Followers 136 Following Deep Malware and Phishing Analysis for Windows, Android, macOS and Linux.
Adam Goss @gossy_84
2K Followers 250 Following I help businesses and individuals enhance their cyber threat intelligence processes, develop their skills, and make CTI actionable.
JangPro @JangPr0
749 Followers 46 Following
clibm079 @clibm079
1K Followers 514 Following Independent Malware Analyst & Researcher,Notes (Philosophy & Poetry) — The Path of Clarity & Poems of Malware Analysis. Blog: https://t.co/DJ3Wxn2OWS
Alex Holovach @alex_holovach
790 Followers 874 Following building the future of observability CTO @Sazabi
Bernardo Quintero @bquintero
25K Followers 269 Following Founder of @virustotal 📖 INFECTED: https://t.co/RRguFlNWKR 📖 INFECTADO: https://t.co/WZ5C2U5ymR
Kimberly @StopMalvertisin
16K Followers 630 Following Security Researcher | Cyber Threat / Malware Analyst | Ex Sr. Threat Analyst @ Proofpoint | Founder of Stop Malvertising
Is Now on VT! @Now_on_VT
5K Followers 830 Following Stay ahead of cyber threats. Get real-time alerts on notable APT/FIN/ORB indicators from VirusTotal. A threat intel project by @craiu.
Aaron Grattafiori @dyn___
6K Followers 3K Following Offensive Security / AI @Umbriel_AI. Ex-AI RT and OffSec at NVIDIA, RT lead @ Meta. Ex-Principal Consultant and Researcher @ NCC Group/iSEC Partners. Neg9//CTF.
Zachi @iam_zachi
5K Followers 274 Following I do cool things at @ActianCorp 38x CVE‘s 📱 https://t.co/wax7xYiQmZ 🐘 https://t.co/tunQiBLBKK 🧩 https://t.co/5g1lrZOh8A
Erik Warfield @warferik
56 Followers 1K Following
Threat Hunting Labs @ThruntingLabs
3K Followers 1 Following Train on raw telemetry from actual breaches. Investigate malware and reconstruct the kill chain from process creation to exfiltration and beyond.
r1cksec @r1cksec
1K Followers 223 Following Data breach revealed, Malware lurks, silent, stealthy - OSINT tracks the thread. URLs I post may contain malware – be careful and check yourself before running
Hoang Nguyen Huy @nhh9905
125 Followers 110 Following
Duty @duty_1g
1K Followers 130 Following Application Security Specialist | Red Teamer | Researcher at Synack Red Team | OSCP-OSEP-OSWE-ECPPT-CRTE/P/O | CTF Player @DeadSecCTF Capturing flags since 2011
Mia @MiaAI_lab
37K Followers 415 Following Building with AI & LLMs // Pushing Local AI Forward // https://t.co/nG8UmAZT9w
peekly @peekly_app
3K Followers 3 Following Find apps that are winning and replicate their strategy.
Renzon @r3nzsec
5K Followers 932 Following IR/Forensics @Unit42_Intel | Contributor/Analyst @TheDFIRReport @XintraOrg | Co-Founder @guidemtraining | CTF member @_hackstreetboys
Quang Vo @smuggiekeplar
951 Followers 962 Following Offensive security engineer and Malware researcher . Tweets are my own
















































