Sign in

HexNomad

@hexnomad.bsky.social
91 followers 252 following 5 posts

Infosec nerd

PostsRepliesMedia
HexNomad @hexnomad.bsky.social · 22/06/2026
Had a great time, as always, at @reconmtl.bsky.social Lots of great talks, lots of great people and lots of fun!!
011
Reposted by HexNomad
Joe Tidy BBC News @joetidy.bsky.social · 27/05/2026
Champion ethical hacker warns AI tools like Mythos will make competing harder. Valentina 'Chompie' Palmiotti won $70,000 for finding 2 serious bugs at the prestigious Pwn2Own Berlin contest. She said she had to enter full 'zombie hacker mode' to work through the night www.bbc.co.uk/news/article...
bbc.co.uk
Top ethical hacker Chompie warns AI tools could put her out of business
Chompie, one of the world's tops ethical hackers, says AI like Claude Mythos will make it harder for people like her to compete.
172
Reposted by HexNomad
OffensiveCon @offensivecon.bsky.social · 16/05/2026
IRON GIANT: When The Vault Becomes The Victim by @hexnomad.bsky.social
011
Reposted by HexNomad
halvarflake.bsky.social @halvarflake.bsky.social · 13/05/2026
www.faz.net/premium/digi... I wrote a FAZ guest article.
faz.net
Thomas Dullien zu Anthropics Mythos: Software war nie auf perfekte Sicherheit ausgelegt - das rächt sich
Schwachstellen in Computern wurden lange hingenommen. Denn sie auszunutzen war technisch komplex und teuer. KIs ändern das nun. Damit zwingen sie uns, Altlasten schneller anzugehen.
33111
HexNomad @hexnomad.bsky.social · 16/04/2026
Going to be doing a webinar next week talking about Anthropic’s Mythos model, what we know so far and how it might affect defenders. get.fieldeffect.com/webinar-myth...
get.fieldeffect.com
[Webinar] Mythos and Project Glasswing: A Practical Look at the Future
Field Effect experts unpack Anthropic's Project Glasswing and Mythos, exploring AI-driven vulnerability discovery and what it means for security teams.
111
Reposted by HexNomad
SSD Secure Disclosure @ssd-disclsoure.bsky.social · 23/03/2026
LSASS under the microscope at TyphoonCon 2026! Erik Egsgard joins our lineup to uncover how even Windows’ most protected process can be turned into an attack surface: typhooncon.com/2026-agenda/
031
Reposted by HexNomad
Natalie Silvanovich @natashenka.bsky.social · 26/01/2026
No security feature is perfect. @tiraniddo.dev reviewed Windows’ new Administrator Protection and found several bypasses. projectzero.google/2026/26/wind...
projectzero.google
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
065
Reposted by HexNomad
Filippo Valsorda @filippo.abyssdomain.expert · 27/12/2025
At the gpg.fail talk and omg #39c3 You can just put a \0 in the Hash: header and then newlines and inject text in a cleartext message. Won’t even blame PGP here. C is unsafe at any speed. gpg has not fixed it yet.
4431108
Reposted by HexNomad
Natalie Silvanovich @natashenka.bsky.social · 12/12/2025
An analysis of a recent 0-click exploit targeting Samsung devices: googleprojectzero.blogspot.com/2025/12/a-lo...
googleprojectzero.blogspot.com
A look at an Android ITW DNG exploit
Posted by Benoît Sevens, Google Threat Intelligence Group Introduction Between July 2024 and February 2025, 6 suspicious image files were ...
184
Reposted by HexNomad
Samuel Groß @saelo.bsky.social · 03/12/2025
We derestricted a number of vulnerabilities found by Big Sleep in JavaScriptCore today: issuetracker.google.com/issues?q=com... All of them were fixed in the iOS 26.1 (and equivalent) update last month. Definitely some cool bugs in there!
issuetracker.google.com
Google Issue Tracker
064
Reposted by HexNomad
Samuel Groß @saelo.bsky.social · 29/10/2025
We derestricted crbug.com/382005099 today which might just be my favorite bug of the last few years: bad interaction between WebAudio changing the CPU's handling of floats and V8 not expecting that. See crbug.com/382005099#co... for a PoC exploit. Also affected other browsers
0177
Reposted by HexNomad
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 23/10/2025
NEW: The U.S. govt accused Peter Williams, ex general manager of hacking tool maker L3Harris Trenchant, of stealing trade secrets and selling them to buyer in Russia. As we reported earlier, Trenchant investigated a leak of internal tools this year. It's unclear if that investigation is related.
techcrunch.com
U.S. government accuses former L3Harris cyber boss of stealing trade secrets | TechCrunch
The U.S. Department of Justice accused Peter Williams, former general manager of L3Harris’ hacking division Trenchant, of stealing trade secrets and selling them to a buyer in Russia.
12320
Reposted by HexNomad
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/10/2025
SCOOP: A man who worked on developing hacking and surveillance tools for defense contractor L3Harris Trenchant was notified by Apple that his iPhone was targeted with mercenary spyware. The developer believes he was targeted after he was wrongly accused of leaking zero-days developed by Trenchant.
techcrunch.com
Exclusive: Apple alerts exploit developer that his iPhone was targeted with government spyware
A developer at Trenchant, a leading Western spyware and zero-day maker, was suspected of leaking company tools and fired. Weeks later, Apple notified him that his personal iPhone was targeted with spy...
22624
Reposted by HexNomad
Natalie Silvanovich @natashenka.bsky.social · 16/10/2025
Serious bugs often occur in third-party components integrated by other software. Ivan Fratric and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click. project-zero.issues.chromium.org/issues/42807...
project-zero.issues.chromium.org
Project Zero
1101
Reposted by HexNomad
Stephen Fewer @stephenfewer.bsky.social · 23/07/2025
We now have a (draft) @metasploit-r7.bsky.social exploit module in the pull queue for the recent Microsoft SharePoint Server unauthenticated RCE zero-day (CVE-2025-53770), based on the in-the-wild exploit published a few days ago. Check it out here: github.com/rapid7/metas...
1118
Reposted by HexNomad
Zack Whittaker @zackwhittaker.com · 09/06/2025
New: A security researcher found a bug that revealed the private recovery phone number of almost any Google account. TechCrunch verified the bug w/ the researcher, who quickly brute-forced the phone number of a test Google account we had set up.
techcrunch.com
Google fixes bug that could reveal users' private phone numbers | TechCrunch
The bug allowed a researcher to uncover recovery phone numbers of nearly any Google account.
16423
Reposted by HexNomad
Natalie Silvanovich @natashenka.bsky.social · 28/05/2025
The final part of Mateusz’s Windows Registry series is live! Contains all the hive memory corruption exploitation you’ve been waiting for googleprojectzero.blogspot.com/2025/05/the-...
googleprojectzero.blogspot.com
The Windows Registry Adventure #8: Practical exploitation of hive memory corruption
Posted by Mateusz Jurczyk, Google Project Zero In the previous blog post , we focused on the general security analysis of the registry a...
064
HexNomad @hexnomad.bsky.social · 26/03/2025
Great write-up, as usual, from Project 0 going into even more detail on the BlastPass iOS zero click exploit from 2023: googleprojectzero.blogspot.com/2025/03/blas...
googleprojectzero.blogspot.com
Blasting Past Webp
An analysis of the NSO BLASTPASS iMessage exploit Posted by Ian Beer, Google Project Zero On September 7, 2023 Apple issued  an out-...
000
Reposted by HexNomad
Marc-André Moreau @awakecoding.com · 12/03/2025
"Windows App to replace Remote Desktop app for Windows" There's a lot of confusion about what this means, so let me clarify: This only affects the Remote Desktop App on the *Microsoft Store*, which you most likely don't use Most system administrators use mstsc, the Windows built-in RDP client
151
Reposted by HexNomad
Jacob T. Levy @jacobtlevy.bsky.social · 06/03/2025
We will never know— we will never have the faintest idea— how much money is getting made in insider trading windfalls from people in Trump's and Musk's circles who have an hour of notice about the daily swings in tariff policy or the occasional announced *expectations* of such swings.
411982642
Reposted by HexNomad
LaurieWired @lauriewired.bsky.social · 06/02/2025
Ghidra 11.3 is OUT! 
PyGhidra is the new feature to be excited about.

It’s a Python library providing direct access to the Ghidra API. 

 I expect this to massively increase Reverse Engineering tool development, as it significantly reduces the barrier to entry for Ghidra interaction.
13516
Reposted by HexNomad
Kim Zetter @kimzetter.bsky.social · 04/02/2025
A 25-year-old DOGE worker named Marko Elez who has admin privileges on Treasury dept systems that control about 95% of payments made by the gov, including Social Security checks, tax refunds and contract payments "has already made extensive changes to the code base for these critical payment system"
talkingpointsmemo.com
Musk Cronies Dive Into Treasury Dept Payments Code Base
Overnight, Wired reported that, contrary to published reports that DOGE operatives at...
33560340
Reposted by HexNomad
Robert Graham @erratarob.bsky.social · 03/02/2025
1223
Reposted by HexNomad
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Reposted by HexNomad
OffensiveCon @offensivecon.bsky.social · 21/01/2025
To all our Bluesky friends, feel free to follow us here as we will be posting regular updates as the conference gets closer. See you in May!
083
Reposted by HexNomad
Natalie Silvanovich @natashenka.bsky.social · 10/01/2025
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium.org/issues/36869...
project-zero.issues.chromium.org
Project Zero
13816
Reposted by HexNomad
halvarflake.bsky.social @halvarflake.bsky.social · 09/01/2025
Around 2008 I was in Ottawa and some MoD person mentioned that only a few years ago they stopped wargaming against a US invasion, and I joked "just wait until they run out of water for their golf courses in Arizona"...
2235
Reposted by HexNomad
Catalin Cimpanu @campuscodi.risky.biz · 09/01/2025
Someone is using a fake PoC for the LDAPNightmare exploit to infect researchers and threat actors with an infostealer www.trendmicro.com/en_us/resear...
12810
Reposted by HexNomad
Taggart @taggart-tech.com · 30/07/2024
Another Chompie banger: securityintelligence...
securityintelligence.com
Racing round and round: The little bug that could
Get the straightforward approach to bug hunting — from an IBM X-Force Red expert.
021
Reposted by HexNomad
Dashiell Bennett @dashiell.bsky.social · 29/07/2024
Brazil's Gabriel Medina with the best touchdown celebration I've ever seen (Photo: Jerome Brouillet/Getty)
Surfer Gabriel Media leaping from his surfboard at the top of the wave so the he appears to be floating in the air above the water, completely upright, with one arm extended above his head, holding out one finger, his surfboard trailing behind and also floating in the air
833297
Reposted by HexNomad
soul nate @mnateshyamalan.bsky.social · 07/09/2023
in the 90’s, computers would scream every time you went online. that‘s called foreshadowing
5685823103
HexNomad @hexnomad.bsky.social · 07/09/2023
Video of the talk I gave at Recon on hunting for bugs in the Windows TCP/IP stack is now up! youtu.be/jzA5aLrK4OY
youtu.be
Recon2023 Erik Egsgard HuntForRedOctober
The windows networking stack has been the source of various vulnerabilities over the years, a few of which could lead to remote code execution. This talk wil...
091