Sign in

Frycos

@frycos.bsky.social
770 followers 131 following 35 posts

Private account! Red teamer @codewhitesec. @frycos@infosec.exchange @frycos@X

PostsRepliesMedia
Frycos @frycos.bsky.social · 23/09/2026
Happy announcement: My colleague and me will present a talk at hardwear.io NL 2026, "Vulnerabilities That Get Under Your Skin: Targeting the World’s Best-Selling Infusion Pumps". 100% human-brain VR 😛
hardwear.io
Join Hardwear.io NL 2026 – The Ultimate Hardware Security Event
Connect with hardware security experts and hackers at Hardwear.io NL 2026 in Amsterdam. Experience trainings, talks, CTFs, and the HardPwn challenge this November.
042
Frycos @frycos.bsky.social · 04/09/2026
It has always been a problem to expect proper credit in blog posts and the like. With AI, it's hit rock bottom. 😕
000
Frycos @frycos.bsky.social · 09/07/2026
You all know I like backup solution. Some time ago, I looked at Vinchin Backup & Recovery. Most known vulns seemed targeting the web interfaces. My CVE-2026-60094 and CVE-2026-60095 tell a different story: plenty of mem corruptions in other remote services.
140
Frycos @frycos.bsky.social · 02/05/2026
Infosec community right now…
030
Frycos @frycos.bsky.social · 07/02/2026
Fortunately, humans still learn to walk first, even though the car has been invented.
010
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/02/2026
Highly recommend the writeup from our @fl0mb.bsky.social and congrats on this well-deserved achievement!
043
Reposted by Frycos
buherator @buherator.bsky.social · 24/01/2026
[RSS] [Blog] Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive code-white.com -> CVE-2025-34164, CVE-2025-34165 Original->
022
Frycos @frycos.bsky.social · 23/01/2026
Crazy work by my colleague Fabian. High impact target: one might be amazed at how widespread this product is in industrial networks.
032
Frycos @frycos.bsky.social · 20/12/2025
In 2025 my colleague and me pwned several widespread medial devices. Check our vuln list for some impressions and get ready for cool blog posts and hopefully conference talks in 2026. 🤞🏻 code-white.com/public-vulne...
code-white.com
CODE WHITE | Public Vulnerability List
Public list of vulnerabilities, found by CODE WHITE
121
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/12/2025
Our 2024 applicants challenge is officially #roasted: the full BeanBeat × Maultaschenfabrikle walkthrough is now online. Unwrap the write-up at apply-if-you-can.com/walkthrough/... and revisit the hacks that escalated from cold brew to full breach.
apply-if-you-can.com
CODE WHITE - Applicants Challenge
Applicants Challenge! Face real-world vulns, earn trophies, First Bloods & epic swag!
066
Frycos @frycos.bsky.social · 15/11/2025
Just sayin‘ 🤷
042
Frycos @frycos.bsky.social · 29/10/2025
A somewhat wild internal story from the last few weeks
000
Reposted by Frycos
m1tz @m1tzzz.bsky.social · 07/10/2025
Did you encounter the Supabase? Might wanna try my newest tooling or have a read about quickwins? There you go: blog.m1tz.com/posts/2025/1...
blog.m1tz.com
A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
It all started with my good colleague @schniggie who’s got my attention with an X post earlier that year. Until then I rarely heared of Supabase, but let us start from the scratch. Firebase changed th...
021
Frycos @frycos.bsky.social · 24/09/2025
On your way to @brucon! Are you interested in technical discussions or would you like to know what makes our company so unique? Just talk to us.
031
Frycos @frycos.bsky.social · 15/09/2025
Tired of dull, standard interviews? Talk to Kurt. Also, a few of my colleagues and I will be attending BruCON next week. Feel free to come and talk to us.
061
Frycos @frycos.bsky.social · 03/09/2025
New AI-generated "technical" blog posts are stealing my time. 🤬
020
Reposted by Frycos
Scary "Grampus" Jerry 👻 @jerry.infosec.exchange.ap.brid.gy · 29/08/2025
Yes, there’s another phishing campaign contacting fediverse users to fill out a form to avoid being suspended or whatever. Stay calm and just report them and be sure to check the option to inform their home instance so the account gets suspended for everyone. Also, please consider enabling […]
infosec.exchange
Original post on infosec.exchange
3844
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/08/2025
We always love a good challenge. That’s why we’re sponsoring the 10th FAUST CTF. Game on at 2025.faustctf.net
2025.faustctf.net
FAUST CTF 2025 | FAUST CTF 2025
FAUST CTF 2025 is an online attack-defense CTF competition run by FAUST, the CTF team of Friedrich-Alexander University Erlangen-Nürnberg
076
Reposted by Frycos
joern @jrn.bsky.social · 19/08/2025
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/4]
1422
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/08/2025
We've added a new demo to NewRemotingTricks that makes deploying a MarshalByRefObject (e.g., WebClient) even easier: System.Lazy<T> creates an instance of T on serialization, which is probably more likely to be allowed than a XAML gadget getting through. github.com/codewhitesec...
github.com
GitHub - codewhitesec/NewRemotingTricks: New exploitation tricks for hardened .NET Remoting servers
New exploitation tricks for hardened .NET Remoting servers - codewhitesec/NewRemotingTricks
044
Frycos @frycos.bsky.social · 29/07/2025
Wow, I wrote with an author of a cool VR blog post yesterday. Just asked for some more explanations and maybe references. Tl;dr: he couldn’t explain or elaborate because exactly this part of the blog was written by GPT…
020
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 14/07/2025
We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg (on X) to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to @mwulftange.bsky.social
145
Frycos @frycos.bsky.social · 17/06/2025
A quick-and-dirty late night blog post on discovering an nday variant in Zyxel NWA50AX Pro devices frycos.github.io/vulns4free/2...
frycos.github.io
Zyxel NWA50AX Pro - Discovery of an Nday Variant
Today was an eventful day thanks to many interesting blog posts, e.g. from my friends at watchTowr. So I thought, why not publish a small quick-and-dirty blog post myself about a story from last week?...
032
Frycos @frycos.bsky.social · 16/06/2025
Oh no, it's a variant of CVE-2024-29974...I accidentally found that a similar vuln affected Zyxel NWA50AX (Pro) and tested against devices (obviously) lacking the latest patches. This CVE was never publicly related to NWA50AX, though. Well, nice nday exercise then.
040
Frycos @frycos.bsky.social · 14/06/2025
B03701066A0F762E75BAA67816EDB223F8681C9444C34E0B768DE518268025A0 Am I on vacation in the mountains? Yes. Do they have network equipment there? Yes. Can I refrain from doing VR? No. You know the drill: disclosure and blog post planned. 😄
050
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 13/05/2025
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-...
code-white.com
CODE WHITE | Analyzing the Attack Surface of Ivanti's DSM
Ivanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized dis...
088
Reposted by Frycos
halvarflake.bsky.social @halvarflake.bsky.social · 03/05/2025
If you are in the US and upset at the AfD being subject to more surveillance now: The bar to be declared "in conflict with the democratic order" is *very* high. It is literally the AfD definition of "Germanness" by your ancestry, declaring ppl of other ancestries inferior, that did it, justifiedly.
1607
Frycos @frycos.bsky.social · 28/04/2025
My blog post on some vulns in GFI MailEssentials frycos.github.io/vulns4free/2...
frycos.github.io
GFI MailEssentials - Yet Another .NET Target
What is this product GFI MailEssentials all about? We’re living the future, right? So let’s ask the GFI AI.
077
Reposted by Frycos
Matt Johansen @mattjay.com · 18/04/2025
🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read. He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords Media's coverage wasn't detailed enough so I dug into his testimony:
324139377304
Frycos @frycos.bsky.social · 16/04/2025
That sums up my week's vacation pretty well. And I have to say, I like it.
020
Reposted by Frycos
Stephen Fewer @stephenfewer.bsky.social · 10/04/2025
We have just published our AttackerKB @rapid7.com Analysis of CVE-2025-22457, an unauthenticated stack based buffer overflow in Ivanti Connect Secure. Difficult to exploit due to severe character restrictions, we detail our full RCE technique here: attackerkb.com/topics/0ybGQ...
attackerkb.com
CVE-2025-22457 | AttackerKB
On April 3, 2025, Ivanti published an advisory for CVE-2025-22457, an unauthenticated remote code execution vulnerability due to a stack based buffer overflow.…
134
Reposted by Frycos
Flomb @fl0mb.bsky.social · 31/03/2025
blog.flomb.net/posts/ingres...
blog.flomb.net
Exploiting IngressNightmare: A Deep Dive
Wiz recently discovered an unauthenticated remote code execution (RCE) vulnerability in the Ingress NGINX admission controller. I found the exploit chain particularly intriguing and decided to recreat...
043
Frycos @frycos.bsky.social · 30/03/2025
This was a pretty cool online course by @voidstarsec I can recommend.
020
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/03/2025
Our crew members @mwulftange.bsky.social & @frycos.bsky.social discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam 's blacklist for CVE-2024-40711 & CVE-2025-23120 + further entry points after @sinsinology.bsky.social & @chudypb.bsky.social 's blog. Replace BinaryFormatter!
096
Frycos @frycos.bsky.social · 12/03/2025
If you think code audits are driving you to the brink of insanity, try hardware hacking...
060
Reposted by Frycos
codewhitesec.bsky.social @codewhitesec.bsky.social · 21/02/2025
Ever wondered how Kurts Maultaschenfabrikle got hacked in 2023? The full story, all technical details, out now ;-) apply-if-you-can.com/walkthrough/...
apply-if-you-can.com
Walkthrough 2023
0710
Frycos @frycos.bsky.social · 07/02/2025
This is a very unique, nice and small conference I can recommend. Good networking opportunities. ✌️
061
Frycos @frycos.bsky.social · 05/02/2025
First blog post draft for 2025 queued for release. Waiting for patches then…
1110
Reposted by Frycos
Steve Syfuhs @syfuhs.net · 24/01/2025
Q: have you heard of this math theorum? No? Okay well intuit how it will work in code anyway. Me: ......no. Dodged that bullet.
371
Reposted by Frycos
Michael Stepankin @artsploit.com · 22/01/2025
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! github.blog/security/vul...
12916
Reposted by Frycos
Stephen Fewer @stephenfewer.bsky.social · 16/01/2025
I wrote a PoC for the recent Ivanti Connect Secure stack buffer overflow, CVE-2025-0282, based on the exploitation strategy watchTowr published, along with an assessment of exploitability given the lack of a suitable info leak to break ASLR: attackerkb.com/assessments/...
1118
Reposted by Frycos
Kathryn Tewson @kathryntewson.bsky.social · 06/01/2025
Marc Rogers aka cjunkie, head of security at Defcon and responsible for modernizing their enforcement against harassment and assault, has suffered a devastating spinal cord injury and faces catastrophic medical expenses. Please donate if you can & share regardless. www.gofundme.com/f/support-ma...
gofundme.com
Donate to Support Marc Rogers' Road to Recovery, organized by Katie Vogel
cjunkie (Marc Rogers) is an invaluable and beloved member of our hacker community: a… Katie Vogel needs your support for Support Marc Rogers' Road to Recovery
5177136
Reposted by Frycos
Nicolas Grégoire @agarri.fr · 03/01/2025
Given that simps0n isn’t on Bluesky, allow me to post a link to his excellent weekly ezine 💎 Here’s today’s edition, "AppSec Ezine - 568th" 📚 pathonproject.com/zb/?47a5c4d2...
pathonproject.com
AppSec Ezine
02211
Reposted by Frycos
Assetnote @assetnote.io · 19/12/2024
Last month, our Security Research team discovered and disclosed a critical pre-authentication RCE in CraftCMS (CVE-2024-56145). You can read our blog post on the issue here: assetnote.io/resources/re... #attacksurfacemanagement
095
Frycos @frycos.bsky.social · 16/12/2024
img-getpocket.cdn.mozilla.net/96x96/filter... SSRF as a Service
img-getpocket.cdn.mozilla.net
120
Frycos @frycos.bsky.social · 16/12/2024
CVE-2024-55969 CVE-2024-55970
020
Reposted by Frycos
Piotr Bazydło @chudypb.bsky.social · 12/12/2024
I wrote a fun, little blog post. Remote pre-auth file deletion in SolarWinds ARM allowed to achieve LPE on AD machines 🙃
196
Reposted by Frycos
Justin Elze @handle.invalid · 13/12/2024
Stay ready this holiday season
5456
Reposted by Frycos
Steve Syfuhs @syfuhs.net · 06/12/2024
Oh by the way
NTLM v1 is removed from the latest version of Windows
910035
Reposted by Frycos
Catalin Cimpanu @campuscodi.risky.biz · 05/12/2024
watchTowr researchers have identified a new unauthenticated path traversal vulnerability in the Mitel MiCollab VoIP platform - CVE-2024-41713 - 9.8/10 score labs.watchtowr.com/where-theres...
labs.watchtowr.com
Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day
It is not just APTs that like to target telephone systems, but ourselves at watchTowr too. We can't overstate the consequences of an attacker crossing the boundary from the 'computer system' to the '...
072