Sign in

Anderson Nascimento

@andersonc0d3.bsky.social
221 followers 567 following 476 posts

Director & Security Researcher @alleleintel.com Blog: blog.andersonc0d3.io

PostsRepliesMedia
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 28/09/2026
Confira os detalhes no link abaixo: Treinamento de Desenvolvimento de Exploits e Segurança de Binários em Linux (Linux Binary Exploitation) – Abril de 2027 allelesecurity.com/treinamento-...
allelesecurity.com
Treinamento de Desenvolvimento de Exploits e Segurança de Binários em Linux (Linux Binary Exploitation) – Abril 2027
Treinamento em Exploração de vulnerabilidades no espaço do usuário do Linux (Linux Binary Exploitation).
011
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 28/09/2026
Nova turma aberta do nosso treinamento Desenvolvimento de Exploits e Segurança de Binários em Linux (Linux Binary Exploitation)! O treinamento ocorrerá na modalidade online em abril de 2027.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 24/09/2026
Introduction to Linux Kernel Exploitation – September 2027 allelesecurity.com/introduction...
allelesecurity.com
Introduction to Linux Kernel Exploitation – September 2027
Treinamento em Exploração de vulnerabilidades no espaço do kernel do Linux (Linux Kernel Exploitation).
011
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 24/09/2026
Would you like to learn about page cache, memory management, and how to attack and defend Linux? We will be teaching all of those topics in our Introduction to Linux Kernel Exploitation training. Limited seats, don't miss this chance.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
Check out the link below for more details and to enroll: Introduction to Linux Kernel Exploitation – September 2027 allelesecurity.com/introduction...
allelesecurity.com
Introduction to Linux Kernel Exploitation - September 2027
Master Linux kernel security in this hands-on training for pros transitioning to kernel space. Demystify internals, CPU modes, and exploitation.
011
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
We also offer corporate group packages. If you have any questions or need assistance with the enrollment process, please let us know—we’re happy to help!
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
Structured & Accessible: Detailed, beginner-friendly documentation that makes complex concepts easy to follow. Registration is open! We have a Super Early Bird discount available for the first 4 students.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
Expert instruction: Taught by an instructor with over 10 years of world-class vulnerability research experience. Flexible learning: Class recordings uploaded within 24 hours so you never miss a lesson.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
What sets our training apart: Direct support: Personalized contact and guidance starting as soon as you enroll. Cutting-edge content: Up-to-date curriculum drawn from public sources and our own internal security research.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
This is your opportunity to gain hands-on experience with computer architecture, kernel debugging, the Linux kernel, exploit development, and modern mitigation bypasses alongside an instructor doing top-tier vulnerability research.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 21/09/2026
After 6 successful runs of our Introduction to Linux Kernel Exploitation training—across both public and in-company cohorts—and a 100% positive rating from our students, we are offering it for the first time in English!
111
Reposted by Anderson Nascimento
Joe Uchill @joeuchill.bsky.social · 07/09/2026
Hey, cyberpeople. Help a PhD student out. Did you recently write or supervise a vendor's research report or release research on a blog? Maybe you dropped a vuln at a conference? In general, did you do something that, if we were in any other industry, would be an academic paper? Let me know.
92626
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 14/09/2026
Check out the full breakdown: allelesecurity.com/open-source-...
allelesecurity.com
Open Source Contributions
This repository highlights the open-source security research, vulnerability reports, and code contributions made by Allele Security Intelligence across core system projects.
021
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 14/09/2026
We compiled a showcase of our open-source contributions. Highlights include: - Linux kernel patches (TCP core, CAN BCM, Fanotify, RxRPC, BTRFS) - Fixes for the crash utility - Research that sparked GLIBC hardening work Much more to come!
111
Anderson Nascimento @andersonc0d3.bsky.social · 28/07/2026
Release 2.47 of the GNU Binutils is now available inbox.sourceware.org/binutils/87o...
000
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
Treinamento de Exploração de Vulnerabilidades no Espaço do Kernel (Linux Kernel Exploitation) – Agosto 2026 allelesecurity.com.br/treinamento-...
allelesecurity.com.br
Treinamento de Exploração de Vulnerabilidades no Espaço do Kernel (Linux Kernel Exploitation) - Agosto 2026
Treinamento de Exploração de Vulnerabilidades no Espaço do Kernel (Linux Kernel Exploitation) - Agosto 2026
011
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
Esta é a última semana para realizar as inscrições. Pensando nisso, estamos oferecendo um desconto especial para pagamentos à vista. Aproveite esta chance, pois não há previsão para novas turmas!
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
* Acesso permanente ao grupo de discussão privado e exclusivo para alunos; * Suporte aos estudos por meio de acesso direto ao instrutor mesmo após o treinamento;
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
A qualidade e os benefícios serão os mesmos presentes em todos os nossos serviços: * Conteúdo atualizado com o que há de mais moderno em pesquisa e exploração de vulnerabilidades no kernel do Linux; * Treinamento totalmente prático (hands-on); * Aulas gravadas e disponibilizadas em até 24 horas;
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
Será mais um mês recheado de conteúdo de alto nível, unindo teoria e muita prática (mão na massa), em que iremos navegar desde o ecossistema até o gerenciamento de memória de um dos maiores softwares já criados.
111
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 27/07/2026
Após o sucesso do treinamento de exploração de vulnerabilidades em binários, realizado em maio deste ano e no qual obtivemos 100% de satisfação no feedback dos alunos, na próxima semana iniciaremos nosso segundo treinamento do ano: exploração de vulnerabilidades no kernel do Linux.
111
Anderson Nascimento @andersonc0d3.bsky.social · 22/07/2026
RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600) seclists.org/oss-sec/2026...
seclists.org
oss-sec: RefluXFS: LPE in the Linux kernel via XFS reflink race (CVE-2026-64600)
000
Anderson Nascimento @andersonc0d3.bsky.social · 20/07/2026
Dnsmasq DNS Remote Heap Buffer Overflow blog.exodusintel.com/2026/07/20/d...
blog.exodusintel.com
Dnsmasq DNS Remote Heap Buffer Overflow - Exodus Intelligence
By David Barksdale In this blog post, we discuss a heap buffer overflow vulnerability that we found in Dnsmasq. This vulnerability was fixed in version 2.92rel2 and 2.93 on 11 May 2026 and assigned CV...
000
Anderson Nascimento @andersonc0d3.bsky.social · 11/07/2026
perf/x86/amd/brs: Fix kernel address leakage git.kernel.org/pub/scm/linu... perf/x86/amd/lbr: Fix kernel address leakage git.kernel.org/pub/scm/linu...
git.kernel.org
Making sure you're not a bot!
000
Reposted by Anderson Nascimento
Bluesky @bsky.app · 09/07/2026
v1.127 is live! We're rolling out improvements to search over the coming weeks. You'll get more relevant results and more ways to find what you're looking for. The new "Filters" button lets you query and filter by keywords, people, date range, language and more. You can even share your searches!
A rendering of the new "Filters" button and option fields, which allow you to query and filter by keywords, people, date range, language and more.
2573484576
Anderson Nascimento @andersonc0d3.bsky.social · 10/07/2026
Debugging with CHERI CHERI is designed to improve the security of both existing and future software. freebsdfoundation.org/our-work/jou...
freebsdfoundation.org
Debugging with CHERI | FreeBSD Foundation
Debugging with CHERI CHERI is designed to improve the security of both existing and future software. John Baldwin CHERI is a new security-oriented processor technology. Applying principles from histor...
011
Anderson Nascimento @andersonc0d3.bsky.social · 08/07/2026
kern: add pddupfd(2) github.com/freebsd/free... pdfork.2: document pddupfd() github.com/freebsd/free...
github.com
kern: add pddupfd(2) · freebsd/freebsd-src@1ad21a6
Reviewed by: markj Tested by: pho Sponsored by: The FreeBSD Foundation MFC after: 1 week Differential revision: https://reviews.freebsd.org/D57163
000
Anderson Nascimento @andersonc0d3.bsky.social · 07/07/2026
FreeBSD has added the pdopenpid() system call. It is the FreeBSD equivalent of pidfd_open() on Linux. kern: add pdopenpid(2) github.com/freebsd/free... pdfork.2: document pdopenpid(2) github.com/freebsd/free... sys: add pdopenpid(2) reviews.freebsd.org/D57124
github.com
kern: add pdopenpid(2) · freebsd/freebsd-src@5c32aa7
Reviewed by: markj Tested by: pho Sponsored by: The FreeBSD Foundation MFC after: 1 week Differential revision: https://reviews.freebsd.org/D57124
100
Anderson Nascimento @andersonc0d3.bsky.social · 07/07/2026
OpenSSH 10.4 released seclists.org/oss-sec/2026...
000
Anderson Nascimento @andersonc0d3.bsky.social · 05/07/2026
‪Modify pages_map() to support mapping uncommitted virtual memory.‬ ‪https://github.com/jemalloc/jemalloc/commit/c2f970c32b527660a33fa513a76d913c812dcf7c‬ ‪work around heuristic overcommit causing fork failure + improve behaviour with no overcommit‬ ‪https://github.com/jemalloc/jemalloc/issues/193‬
010
Anderson Nascimento @andersonc0d3.bsky.social · 05/07/2026
vm.overcommit_memory=2 is always the right setting for servers ariadne.space/2025/12/16/v... vm.max_map_count growing steadily when vm.overcommit_memory is 2 #1328 github.com/jemalloc/jem...
ariadne.space
vm.overcommit_memory=2 is always the right setting for servers
The Linux kernel has a feature where you can tune the behavior of memory allocations: the vm.overcommit_memory sysctl. When overcommit is enabled (sadly, this is the default), the kernel will typicall...
100
Anderson Nascimento @andersonc0d3.bsky.social · 04/07/2026
‪It seems my wifi card is newer than the models supported by iwx. After disabling if_iwlwifi, the sysctl net.wlan.devices doesn't show anything.‬
000
Anderson Nascimento @andersonc0d3.bsky.social · 04/07/2026
Found it. I am gonna try it now, thanks
110
Anderson Nascimento @andersonc0d3.bsky.social · 04/07/2026
Thanks, do you know what I need to do to get that driver on FreeBSD? It's not there by default as far as I can tell.
100
Anderson Nascimento @andersonc0d3.bsky.social · 04/07/2026
rcd(8) - new service manager daemon for FreeBSD lists.freebsd.org/archives/fre...
lists.freebsd.org
rcd(8) - new service manager daemon
000
Anderson Nascimento @andersonc0d3.bsky.social · 03/07/2026
Now my issues are with FreeBSD and WiFi. I’ve tried FreeBSD 15.1 and 16-CURRENT. The network gets down after a while and the kernel crashes.
120
Anderson Nascimento @andersonc0d3.bsky.social · 01/07/2026
fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() git.kernel.org/pub/scm/linu...
git.kernel.org
Making sure you're not a bot!
000
Anderson Nascimento @andersonc0d3.bsky.social · 01/07/2026
Brave New Trusted Boot World 0pointer.de/blog/brave-n...
0pointer.de
Brave New Trusted Boot World
Posts and writings by Lennart Poettering
000
Anderson Nascimento @andersonc0d3.bsky.social · 01/07/2026
Much ado about SBAT lwn.net/Articles/938...
lwn.net
Much ado about SBAT
Sometimes, the shortest patches lead to the longest threads; for a case in point, see this thre [...]
000
Anderson Nascimento @andersonc0d3.bsky.social · 24/06/2026
kern: add a security knob to disable unprivileged access to kenv github.com/freebsd/free...
000
Anderson Nascimento @andersonc0d3.bsky.social · 23/06/2026
Bug 221383 - ideapad_laptop: Fn hotkeys stop emitting after s2idle resume on IdeaPad Slim 3 14ARP10 (Ryzen 7735HS) bugzilla.kernel.org/show_bug.cgi... [PATCH v6 0/4] amd_pmc: Delay s2idle suspend for some devices lore.kernel.org/all/20260611...
000
Anderson Nascimento @andersonc0d3.bsky.social · 18/06/2026
Lawfare Archive: The Return of the Syrian Civil War shows.acast.com/lawfare/epis... Lawfare Daily: How Escalations in Lebanon May Prolong the Iran War, with Joel Braunold shows.acast.com/lawfare/epis...
shows.acast.com
Lawfare Archive: The Return of the Syrian Civil War | The Lawfare Podcast
000
Anderson Nascimento @andersonc0d3.bsky.social · 17/06/2026
Saab invests in Comand AI to strengthen European defence sector news.cision.com/saab/r/saab-...
news.cision.com
Saab invests in Comand AI to strengthen European defence sector
Saab has announced a strategic investment of 11.1 MEUR for a 10% equity stake in Paris-based
000
Anderson Nascimento @andersonc0d3.bsky.social · 11/06/2026
I really enjoyed learning these nuances and writing about them, especially since this deep dive wasn't originally planned!
000
Anderson Nascimento @andersonc0d3.bsky.social · 11/06/2026
You can understand how things work in theory, but it’s always fascinating to see the challenges that crop up when implementing them in practice. I knew a mature debugger like GDB would be complex, but I didn't expect these specific issues and their solutions.
100
Anderson Nascimento @andersonc0d3.bsky.social · 11/06/2026
I wrote this post. As I mention in it, I’ve been using GDB almost daily for about 10 years, but I had never actually looked at its source code. I finally started digging into it to make sense of some quirky behaviors, and I ended up uncovering some fascinating details.
100
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 11/06/2026
Did you know there's a way to hit a breakpoint without using hardware or software breakpoints? Or how GDB patches the binary to execute an instruction? Learn more about how GDB works under the hood. Why is my shellcode being corrupted? allelesecurity.com/why-is-my-sh...
allelesecurity.com
Why is my shellcode being corrupted?
Explore the illusion GDB creates in Linux Binary Exploitation, uncovering issues with breakpoints and stack memory behavior in this detailed analysis.
012
Reposted by Anderson Nascimento
Allele Security Intelligence @alleleintel.com · 11/06/2026
We started analyzing a classic case where GDB creates the illusion that code in writable memory is corrupted. We ended up discovering two interesting behaviors of GDB.
112
Anderson Nascimento @andersonc0d3.bsky.social · 10/06/2026
CVE-2026-45257: FreeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root seclists.org/oss-sec/2026...
seclists.org
oss-sec: CVE-2026-45257: FreeBSD kTLS-RX in-place AES-GCM decrypt over sendfile(2) EXTPG mbufs to page-cache write / local root
010
Anderson Nascimento @andersonc0d3.bsky.social · 06/06/2026
[PATCH] target/i386: helper_sysret(): Check that RCX contains a canonical address when emulating an Intel CPU lore.kernel.org/qemu-devel/2...
000