Sign in

Alexandre Borges

@alexandreborges.bsky.social
529 followers 60 following 309 posts

Vulnerability Researcher | Exploit Developer (speaker 3x at DEF CON)

PostsRepliesMedia
Alexandre Borges @alexandreborges.bsky.social · 6h
Exploiting Reversing (ER) Series | Article 10: iOS Security Research (part 01) 223 pages, free. The first article in the series aimed at iOS itself, and the opening of a multi-part sequence. Published on: www.blackstormsecurity.com/research/ Hope you enjoy the read!
Exploiting Reversing (ER) Series | Article 10: iOS Security Research (part 01)

223 pages, free. The first article in the series aimed at iOS itself, and the opening of a multi-part sequence.

Published on:

https://www.blackstormsecurity.com/research/

This article will be published on https://exploitreversing.com/ next week. 

Hope you enjoy the read!

#iOS #VulnerabilityResearch #ExploitDevelopment #ReverseEngineering #KernelSecurity
010
Alexandre Borges @alexandreborges.bsky.social · 9h
Branch Target Reuse, BTR: New Spectre V2 Attack Targeting JIT Compilers: www.vusec.net/projects/btr/ #cybersecurity #infosec #exploitation #vulnerability #jit #cpu
Branch Target Reuse, BTR: New Spectre V2 Attack Targeting JIT Compilers:

https://www.vusec.net/projects/btr/

#cybersecurity #infosec #exploitation #vulnerability #jit #cpu
031
Alexandre Borges @alexandreborges.bsky.social · 29/09/2026
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution: google.github.io/security-res... #cybersecurity #vulnerability #infosec #exploitation #linux #bluetooth #rce
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution:

https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html

#cybersecurity #vulnerability #infosec #exploitation #linux #bluetooth #rce
021
Alexandre Borges @alexandreborges.bsky.social · 29/09/2026
Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: pgj11.com/posts/Window... Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 2: pgj11.com/posts/Window... #cybersecurity #exploit #exploitation #vulnerability #drivers
Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1:

https://pgj11.com/posts/Windows-NCSI-Proxy-Auth-Coercion-Part-1/

Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 2:

https://pgj11.com/posts/Windows-NCSI-Proxy-Auth-Coercion-Part-2/

#cybersecurity #exploit #exploitation #vulnerability #drivers #infosec #informationsecurity #windows
010
Alexandre Borges @alexandreborges.bsky.social · 25/09/2026
VM guest escape via 9p filesystem exploit: gitlab.com/qemu-project... #qemu #exploitation #vulnerability #informationsecurity #infosec #cybersecurity
VM guest escape via 9p filesystem exploit:

https://gitlab.com/qemu-project/qemu/-/work_items/4491

#qemu #exploitation #vulnerability #informationsecurity #infosec #cybersecurity
031
Alexandre Borges @alexandreborges.bsky.social · 22/09/2026
Malwoverview 8.2.0 is out: github.com/alexandrebor... To install it: python -m pip install -U malwoverview[all] New: --nist 6 lists all CVEs associated with a component #malware #cybersecurity #informationsecurity #vulnerability #cve #threathunting #threatintelligence
000
Alexandre Borges @alexandreborges.bsky.social · 21/09/2026
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute: blog.sentry.security/beyond-promp... #apple #vulnerability #cybersecurity #informationsecurity #cve
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute:

https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compute/

#apple #vulnerability #cybersecurity #informationsecurity #cve
121
Alexandre Borges @alexandreborges.bsky.social · 20/09/2026
Qualcomm’s Adreno X2 GPU: chipsandcheese.com/p/qualcomms-... #gpu #infosec #qualcomm #engineering
chipsandcheese.com
Qualcomm’s Adreno X2 GPU
Integrated GPUs have become a crucial component in recent laptop chips, thanks to a push for better graphics performance in ultraportable devices.
011
Alexandre Borges @alexandreborges.bsky.social · 19/09/2026
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill: heyitsas.im/posts/lpe-qu... #cybersecurity #vulnerability #exploit #infosec #linux
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill:

https://heyitsas.im/posts/lpe-quartet/

#cybersecurity #vulnerability #exploit #infosec #linux
000
Alexandre Borges @alexandreborges.bsky.social · 07/09/2026
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining: mrtiz.github.io/cet-callstac... #cybersecurity #programming #infosec #hacking #redteam
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining:

https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline

#cybersecurity #programming #infosec #hacking #redteam
000
Alexandre Borges @alexandreborges.bsky.social · 01/09/2026
The articles already published in the Exploiting Reversing series (ERS) are now hosted on a new website: blackstormsecurity.com/research/ Future articles will be published primarily at this new address, and for a time, I will also publish them on my personal blog. #exploit #vulnerability
The articles already published in the Exploiting Reversing series (ERS) are now hosted on a new website:

https://blackstormsecurity.com/research/

Future articles will be published primarily at this new address, and for a time, I will also publish them on my personal blog.

The series will continue with many more articles, which some are coming soon. Stay tuned.

Have an excellent day.

#exploit #vulnerability
000
Alexandre Borges @alexandreborges.bsky.social · 29/08/2026
[0-Day] Windows USB Print Out-of-Bounds Read Vulnerability - The String Descriptor That Wasn’t zeifan.my/usbtersakiti/ #cybersecurity #windows #vulnerability #infosec #exploitation
[0-Day] Windows USB Print Out-of-Bounds Read Vulnerability - The String Descriptor That Wasn’t

https://zeifan.my/usbtersakiti/

#cybersecurity #windows #vulnerability #infosec #exploitation
000
Alexandre Borges @alexandreborges.bsky.social · 21/08/2026
A "DoS only" bug to LPE and bypass the existing patch to win $10,500 in kernelCTF: nebusec.ai/research/cve... #cybersecurity #infosec #informationsecurity #lpe #linux #kernelctf #exploitation
020
Alexandre Borges @alexandreborges.bsky.social · 20/08/2026
It is with great pleasure that I announce I am a co-author of the Seventh Edition of Gray Hat Hacking, alongside outstanding cybersecurity minds such as Stephen Sims, Valentina Palmiotti, Natalie Silvanovich, Luna Tong, Pavel Yosifovich, Moses Frost, and Huascar Tejeda! Stay tuned!
It is with great pleasure that I announce I am a co-author of the Seventh Edition of Gray Hat Hacking, alongside outstanding cybersecurity minds such as Stephen Sims, Valentina Palmiotti, Natalie Silvanovich, Luna Tong, Pavel Yosifovich, Moses Frost, and Huascar Tejeda! 

We are undoubtedly living through exciting times, and I hope readers appreciate this complete overhaul of modern, completely updated content. Stay tuned!

#cybersecurity #hacking #exploitation #exploit #programming #informationsecurity #infosec
043
Alexandre Borges @alexandreborges.bsky.social · 19/08/2026
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day: www.gendigital.com/blog/insight... #cybersecurity #infosec #informationsecurity #rootkit #vulnerability
Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day:

https://www.gendigital.com/blog/insights/research/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day

#cybersecurity #infosec #informationsecurity #rootkit #vulnerability
000
Alexandre Borges @alexandreborges.bsky.social · 16/08/2026
Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse www.akamai.com/blog/securit... #edr #programming #cybersecurity #informationsecurity
Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse

https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse

#edr #programming #cybersecurity #informationsecurity
000
Alexandre Borges @alexandreborges.bsky.social · 15/08/2026
Linux Bridge STP Timer Use-After-Free: ssd-disclosure.com/linux-bridge... #linux #exploit #exploitation #vulnerability #informationsecurity #cve #patch #cybersecurity
Linux Bridge STP Timer Use-After-Free:

https://ssd-disclosure.com/linux-bridge-stp-timer-use-after-free/

#linux #exploit #exploitation #vulnerability #informationsecurity #cve #patch #cybersecurity
020
Alexandre Borges @alexandreborges.bsky.social · 08/08/2026
Malwoverview version 8.1.0 is available: github.com/alexandrebor... To install it: $ python -m pip install -U malwoverview The number of changes is significant, so it is recommended reading the README.md: #malware #threathunting #vulnerability #informationsecurity #infosec #cybersecurity
Malwoverview version 8.1.0 is available:

https://github.com/alexandreborges/malwoverview

To install it:

$ python -m pip install -U malwoverview


The number of changes is significant, so it is recommended reading the README.md:


#malware #threathunting #vulnerability #informationsecurity #infosec #cybersecurity
152
Alexandre Borges @alexandreborges.bsky.social · 05/08/2026
The WordPress Chain Massacre: blog.calif.io/p/the-wordpr... #cybersecurity #informationsecurity #vulnerability #exploitation #infosec
The WordPress Chain Massacre:

https://blog.calif.io/p/the-wordpress-chain-massacre

#cybersecurity #informationsecurity #vulnerability #exploitation #infosec
020
Alexandre Borges @alexandreborges.bsky.social · 01/08/2026
SPIR-V on ROCm: A Portable IR for AMD GPUs: A follow-up post will discuss a real-world SPIR-V deployment at scale: PyTorch." rocm.blogs.amd.com/software-too... #cybersecurity #informationsecurity #processors #architecture #infosec
SPIR-V on ROCm: A Portable IR for AMD GPUs:

A follow-up post will discuss a real-world SPIR-V deployment at scale: PyTorch."

https://rocm.blogs.amd.com/software-tools-optimization/spir-v-rocm/README.html

#cybersecurity #informationsecurity #processors #architecture #infosec
010
Alexandre Borges @alexandreborges.bsky.social · 29/07/2026
FirmBurn: How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks aleeamini.com/firmburn-fir... #cybersecurity #reverseengineering #informationsecurity #firmware #zeroday #exploitation #infosec
FirmBurn: How Firmware Zero‑Day & SCSI PassThru Burned Iran Banks

https://aleeamini.com/firmburn-firmware-zero-day-scsi-passthru-burned-iran-banks-hack/

#cybersecurity #reverseengineering #informationsecurity #firmware #zeroday #exploitation #infosec
010
Alexandre Borges @alexandreborges.bsky.social · 29/07/2026
CVE-2026-50469 - ProjFS File Delete bad-jubies.github.io/projected-fi... #windows #vulnerability #exploitation #exploit #cve #informationsecurity
CVE-2026-50469 - ProjFS File Delete

https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469

#windows #vulnerability #exploitation #exploit #cve #informationsecurity
010
Alexandre Borges @alexandreborges.bsky.social · 27/07/2026
SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode vanbulck.net/files/woot26... #cybersecurity #smm #platformsecurity #informationsecurity #infosec
SoK: 20 Years of Power, Privilege, and Peril in x86 System Management Mode
000
Alexandre Borges @alexandreborges.bsky.social · 20/07/2026
Frag Gap: blog.qwerty.or.kr/en/posts/cdf... #kernel #network #cybersecurity #informationsecurity #exploitation #vulnerability #cve
Fraggap (CVE-2026-53362) is a bug in the Linux UDPv6 corking path that allows a 15-byte OOB write into skb_shared_info.
010
Alexandre Borges @alexandreborges.bsky.social · 11/07/2026
Hunting Memory Leaks in bsnmpd with DTrace: oshogbo.com/blog/92/ #dtrace #cybersecurity #informationsecurity #infosec #performance
Hunting Memory Leaks in bsnmpd with DTrace:
000
Alexandre Borges @alexandreborges.bsky.social · 10/07/2026
The work continues... a third vulnerability in just a few days, and like the other two, this one also affects iOS 26.5 and iOS 26.5.2. The challenge, as usual, centers on the next steps for exploitation. #ios #vulnerability #apple
The work continues... a third vulnerability in just a few days, and like the other two, this one also affects iOS 26.5 and iOS 26.5.2. The challenge, as usual, centers on the next steps for exploitation.
000
Alexandre Borges @alexandreborges.bsky.social · 09/07/2026
Redis 8.6: Remote Code Execution via Stream PEL Use After Free: zerotistic.blog/posts/redis-... #linux #vulnerability #exploitation #informationsecurity #infosec #cybersecurity
Redis 8.6: Remote Code Execution via Stream PEL Use After Free:
010
Alexandre Borges @alexandreborges.bsky.social · 06/07/2026
Malwoverview 8.0.5 (Revolutions): github.com/alexandrebor... #cybersecurity #malware #threathunting #informationsecurity #dfir
Malwoverview 8.0.5 (Revolutions)
000
Alexandre Borges @alexandreborges.bsky.social · 05/07/2026
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503): research.jfrog.com/post/dissect... #cve #linux #cybersecurity #informationsecurity #exploitation #vulnerability
Dissecting and Exploiting Linux LPE Variant: DirtyClone (CVE-2026-43503)
010
Alexandre Borges @alexandreborges.bsky.social · 03/07/2026
BitLocker downgrade attacks: archives.pass-the-salt.org/Pass%20the%2... #windows #bitlocker #infosec #informationsecurity #cybersecurity #crypto
BitLocker downgrade attacks
000
Alexandre Borges @alexandreborges.bsky.social · 03/07/2026
A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabytes: www.msuiche.com/posts/nanokr... #kernel #infosec #programming #rust #windows #hacking
A Windows Kernel in a Browser Tab, Part I: Cold Boot, Fast Boot, and Four Megabyte
141
Alexandre Borges @alexandreborges.bsky.social · 02/07/2026
TrigonLegacy - Deterministic iOS 7-9 tfp0: therealclarity.github.io/blog/trigon-... #ios #apple #exploitation #informationsecurity #cybersecurity #vulnerability #reverseengineering
therealclarity.github.io
TrigonLegacy - Deterministic iOS 7-9 tfp0 | Clarity
TrigonLegacy exploits an integer overflow in the VM layer when creating memory entries. This allows arbitrary physical memory read/write, which is then used to build a tfp0 primitive. This exploit ...
020
Alexandre Borges @alexandreborges.bsky.social · 02/07/2026
(remember) Introducing usbliter8: ps.tc/pages/blog-u... #cybersecurity #ios #exploitation #exploit #bootrom #iphone #informationsecurity #infosec
010
Alexandre Borges @alexandreborges.bsky.social · 01/07/2026
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215): cyberstan.co.uk/drm-lpe-linux/ #linux #kernel #vulnerability #cybersecurity #exploitation
Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215):
110
Alexandre Borges @alexandreborges.bsky.social · 01/07/2026
Spiteful Fruit - AppleRAID Kernel Heap OOB Write: ret2p.lt/2026/06/30/s... #cybersecurity #informationsecurity #iOS #apple #vulnerability #informationsecurity #infosec #exploitation
Spiteful Fruit - AppleRAID Kernel Heap OOB Write:
020
Alexandre Borges @alexandreborges.bsky.social · 19/06/2026
Another vulnerability in iOS 26.5 with a clear and reproducible crash, registers control, primitive and PoC confirmed, and possibly a working exploit... who knows... ;)
Another vulnerability in iOS 26.5 with a clear and reproducible crash, registers control, primitive and PoC confirmed, and possibly a working exploit... who knows... ;)
010
Alexandre Borges @alexandreborges.bsky.social · 16/06/2026
Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox: blog.exodusintel.com/2026/06/15/z... #vulnerability #exploitation #exploit #virtualbox #cybersecurity #infosec #informationsecurity
blog.exodusintel.com
Zombie COTables: Resurrecting Freed Memory to Escape VirtualBox - Exodus Intelligence
By Luca Ginex Overview This blog post discusses a use-after-free vulnerability that we found in VirtualBox in 2025. This vulnerability was patched on Oracle Critical Patch Update – January 2026. The v...
010
Alexandre Borges @alexandreborges.bsky.social · 02/06/2026
Malwoverview 8.0.2 has been released: github.com/alexandrebor... To install it: python -m pip install -U malwoverview[all] #malware #threathunting #informationsecurity #infosec #vulnerability #cve #dfir
Malwoverview 8.0.2
010
Alexandre Borges @alexandreborges.bsky.social · 31/05/2026
Bypassing SSL Pinning on Play Store AVDs without Frida www.mfumis.com/posts/bypass... #cybersecurity #informationsecurity #frida #mobiledevice #infosec #mobilesecurity #mobile
mfumis.com
Bypassing SSL Pinning on Play Store AVDs without Frida
📲 🔓 Bypassing SSL Pinning on Play Store Android Device Emulators without Frida
121
Alexandre Borges @alexandreborges.bsky.social · 31/05/2026
Authenticated RCE via Argument Injection in Gogs (NOT FIXED): www.rapid7.com/blog/post/ve... #cybersecurity #vulnerability #rce #informationsecurity #exploitation
rapid7.com
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.
020
Alexandre Borges @alexandreborges.bsky.social · 30/05/2026
Striga: Lifting x86 to LLVM IR with Python: secret.club/2026/05/21/s... #python #reversing #llvm #informationsecurity #infosec #cybersecurity
Striga: Lifting x86 to LLVM IR with Python:
041
Alexandre Borges @alexandreborges.bsky.social · 27/05/2026
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip (CVE-2026-48095): securitylab.github.com/advisories/G... #vulnerability #cybersecurity #informationsecurity #exploitation #cve
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip (CVE-2026-48095)
011
Alexandre Borges @alexandreborges.bsky.social · 27/05/2026
Arbitrary Kernel Address Increment via NtQuerySystemInformation: pwn2nimron.com/blog #vulnerability #informationsecurity #exploitation #cybersecurity #exploit #windows
Arbitrary Kernel Address Increment via NtQuerySystemInformation
010
Alexandre Borges @alexandreborges.bsky.social · 21/05/2026
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility: mysk.blog/2026/05/19/c... #macOS #exploitation #infosec #informationsecurity #vulnerability #cve #exploit
mysk.blog
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
Until macOS 26.4, Archive Utility had nearly unrestricted filesystem access. Combined with a drag-and-drop sandbox quirk, this let an attacker bypass App Sandbox data containers, Transparency, Consent...
030
Alexandre Borges @alexandreborges.bsky.social · 21/05/2026
FatGid+4: A four-byte type, an eight-byte stride, one root shell. fatgid.io #vulnerability #exploit #cybersecurity #informationsecurity #freebsd
FatGid+4: A four-byte type, an eight-byte stride, one root shell.
010
Alexandre Borges @alexandreborges.bsky.social · 19/05/2026
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205): (blog) slcyber.io/research-cen... (tool) github.com/assetnote/cp... #cve #vulnerability #cybersecurity #informationsecurity #authentication
slcyber.io
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) › Searchlight Cyber
Times Are Changing These last few months have been super weird. We've ended up in a situation several times where we have learnt that an exploits life cycle has significantly been reduced due to the i...
010
Alexandre Borges @alexandreborges.bsky.social · 18/05/2026
Kernel-Exploit-Dojo: github.com/mito753/Kern... #kernel #ctf #informationsecurity #infosec #exploitation #cybersecurity #vulnerability
Kernel-Exploit-Dojo
020
Alexandre Borges @alexandreborges.bsky.social · 11/05/2026
How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection: s4dbrd.github.io/posts/how-ke... #reverseengineering #informationsecurity #cybersecurity #game #windows #kernel #debugging
How Kernel Anti-Cheats Work: A Deep Dive into Modern Game Protection
052
Alexandre Borges @alexandreborges.bsky.social · 28/04/2026
Today I am releasing the nineth article in the Exploiting Reversing Series (ERS), which I provide a 106-page deep dive and a comprehensive roadmap for vulnerability exploitation: exploitreversing.com/2026/04/28/e... Enjoy the reading and have an excellent day. #exploit #exploitdevelopment
000
Alexandre Borges @alexandreborges.bsky.social · 17/04/2026
Malwoverview 8.0.1 is available: github.com/alexandrebor... To update it: python -m pip install -U malwoverview #threathunting #malware #cve #vulnerability #cybersecurity #informationsecurity #incidentresponse
011