Nad @nadsec.online · 7hMythos 5.1 review after having used it for exploit dev: Is the the best at surfacing new vulns and chaining exploits? YES Is it economical? NO it literally would cost more than paying people to do the work by hand by an order of magnitude unless you get really lucky. Nothing special. Heap of shit.. 000
Nad @nadsec.online · 05/10/2026open.spotify.com/track/7d23Mh...open.spotify.comDisparate YouthSantigold · Master of My Make-Believe · Song · 2012 000
Nad @nadsec.online · 02/10/2026Which ever country made this junk malware.. Ya'll should be ashamed. 4/10 only cause it does actually work and somehow evades EDR.. Whichever EDR vendor this was, just don't. Don't anymore. www.nadsec.online/blog/majlis-...nadsec.onlineMajlis 2026 Invitation RAT: OTP 123456 and a Snowy Village | NadSecRobert pulls apart the Majlis 2026 invitation RAT: a WebDAV and FTP delivery chain, two command channels, nine tested commands, a screenshot bug, and one deeply unhelpful holiday photo. 010
Nad @nadsec.online · 02/10/2026open.spotify.com/track/591GsK...open.spotify.comPoppyMac Miller · K.I.D.S. (Deluxe) · Song · 2010 000
Nad @nadsec.online · 02/10/2026open.spotify.com/track/591GsK...open.spotify.comPoppyMac Miller · K.I.D.S. (Deluxe) · Song · 2010 000
Nad @nadsec.online · 30/09/2026This the one I been waiting for.. shout out to Xi and da boiz watchtowr.com/intelligence...watchtowr.comCisco Catalyst SD-WAN Manager Vulnerability FAQ: CVE-2026-76504CVE-2026-76504: Authentication Bypass vulnerability in Cisco Catalyst SD-WAN Manager. Exploited in the wild per CISA KEV. 030
Nad @nadsec.online · 26/09/2026Found dupe glitch in an gringo currency type web3 type bs thing. The robot out here printing it's own money. 010
Nad @nadsec.online · 14/09/2026Three Buddy Problem: less therapy, more rants™️ @ryanaraine.bsky.social @craiu.bsky.social @jags.bsky.social 021
Nad @nadsec.online · 14/09/2026If Claude was a person, he’d be riding a Surron electric motorcycle through a school zone at 150kmph at 3PM on a weekday. 010
Nad @nadsec.online · 13/09/2026open.spotify.com/track/74uyfE...open.spotify.comMake 'Em ProudD.I.T.C., A.G., Fat Joe, Diamond D · Sessions · Song · 2016 011
Nad @nadsec.online · 09/09/2026New Cisco zero day finna drop in the next month. Gonna start being used for in the wild exploitation in 2 weeks and will be publically disclosed within 2-3 weeks following. Good luck out there. 121
Nad @nadsec.online · 08/09/2026Watching botnets smack my honeypot infra is pure art. Unfiltered, aggressive, unrelenting yet beautifully creative. The chaos of human intent encapsulated in automated fighting robots. A digital terrarium of nerds wading through a sea of shit nobody asked for, simply because they can. 011
Nad @nadsec.online · 06/09/2026youtu.be/7KWKIdwt7Ro?...youtu.beJisoe - Australian graffiti artist documentaryYouTube video by dickies docos 000
Nad @nadsec.online · 01/09/2026open.spotify.com/track/7sqk5H...open.spotify.comLove Times Pie Recurring..Layla · Australian Hip Hop Supports CanTeen · Song · 2011 000
Nad @nadsec.online · 31/08/2026open.spotify.com/track/0vhiGS...open.spotify.comCatch a Bad OneDel The Funky Homosapien · No Need For Alarm · Song · 1993 000
Nad @nadsec.online · 13/08/2026CVE-2026-66804 - Windows Cross Device Service LPE - Writeup & PoC Found another cool one! www.nadsec.online/blog/cve-202... Not sure who found it first, but shoutout to them. Despite not being FTF, my mom thinks this one is cool, which is the only important metric 😎nadsec.onlineCVE-2026-66804: Cross Device Virtual Camera to SYSTEM | NadSecA missing ProgramData COM path lets a standard user plant the Cross Device virtual-camera DLL, reach LOCAL SERVICE, and obtain SYSTEM. 021
Nad @nadsec.online · 11/08/2026open.spotify.com/track/4GGbJ6...open.spotify.comOld School2Pac · Me Against The World · Song · 1995 000
Reposted by NadCatalin Cimpanu @campuscodi.risky.biz · 04/08/2026Also this: www.artsprofessional.co.uk/news/breakin... And this: www.cse.org.uk/news/beacon-... 021
Nad @nadsec.online · 04/08/2026open.spotify.com/track/1oTo3i...open.spotify.comI Miss Youblink-182 · blink-182 · Song · 2003 000
Nad @nadsec.online · 28/07/2026I like this one :) github.com/Rat5ak/fried... Try it out for yourself: friedbrowser.com -disclaimer, this will crash your browser and likely cause your phone to heat up for a significant period of time before crashing the device.github.comGitHub - Rat5ak/friedbrowser: WebGL 2 UBO browser denial-of-service researchWebGL 2 UBO browser denial-of-service research. Contribute to Rat5ak/friedbrowser development by creating an account on GitHub. 100
Nad @nadsec.online · 16/07/2026CVE-2026-50343 - InstallService Windows local privilege Escelation - Writeup and POC Found another cool one! www.nadsec.online/blog/cve-202... Not sure who first to find was, but shoutout to them. Despite not being FTF, my mom thinks it's cool and that's all that matters 😎nadsec.onlineCVE-2026-50343: InstallService StaticPluginMap to SYSTEM | NadSecA standard user controls plugin state consumed by Microsoft InstallService, then uses a public WinRT trigger to reach SYSTEM DLL loading. 012
Reposted by NadCatalin Cimpanu @campuscodi.risky.biz · 12/07/2026No. I did it. That's why I took next week off from work 1182
Nad @nadsec.online · 08/07/2026I’m so 30 that I’ve started drinking oat milk in my coffee. I didn’t sign up for this. 010
Nad @nadsec.online · 05/07/2026github.com/Rat5ak/CVE-2... A kwl 1github.comGitHub - Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover: QNAP password reset URL injection writeup + PoC.QNAP password reset URL injection writeup + PoC. Contribute to Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover development by creating an account on GitHub. 000
Nad @nadsec.online · 05/07/2026open.spotify.com/track/5Vnx5i...open.spotify.com一翦梅Fei Yu-ching · 天之大 · Song · 2010 010
Nad @nadsec.online · 04/07/2026July 2026 update.. Hoverboards nowhere to be seen. Snake still un-oiled. 010
Nad @nadsec.online · 15/06/2026Linus Torvalds is the original vibe coder. That guy's been vibe coding for atleast a decade. Legit, he been prompting humans this whole time. Barely writes any code himself. Crazy 111
Nad @nadsec.online · 06/06/2026open.spotify.com/track/7hdOch...open.spotify.comThings Done Changed - 2005 RemasterThe Notorious B.I.G. · Ready to Die (The Remaster) · Song · 1994 030
Reposted by NadCatalin Cimpanu @campuscodi.risky.biz · 03/06/2026Another researcher drops a zero-day without disclosure because they're tired of dealing with MSRC blog.ammaraskar.com/github-token... 13210
Nad @nadsec.online · 02/06/2026open.spotify.com/track/22AbXx...open.spotify.comWelcome To JamrockDamian Marley · Welcome to Jamrock · Song · 2005 010
Nad @nadsec.online · 30/05/2026The irony of using a non-deterministic robot with system level privileges, an internet connection and a track record of flying off the rails to find software vulnerabilities in the name of security… I was promised hoverboards. That’s all I have to say. 030
Nad @nadsec.online · 14/05/2026I just realised old school C2s in the command line are about to come back. AI ain’t all bad. 000
Nad @nadsec.online · 05/05/2026Presenting, for absolutely no reason at all, CVE-2026-31431 as a 587-byte x86_64 static ELF: github.com/Rat5ak/CVE-2...github.comGitHub - Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC: 587-byte x86_64 LPE for CVE-2026-31431587-byte x86_64 LPE for CVE-2026-31431. Contribute to Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC development by creating an account on GitHub. 010
Nad @nadsec.online · 05/05/2026If ya didn’t want me to order parts for an F18 to my house yall shouldn’t have put the damn portal on the internet. No idea where I’m gonna store all these ejector seats! 010
Nad @nadsec.online · 05/05/2026Shoutout Tupac open.spotify.com/track/0NzNKU...open.spotify.comSo Many Tears 000
Nad @nadsec.online · 01/05/2026Pro tip: always test on the wrong operating system, then manually recreate every byte-level platform quirk yourself. Trust me, triagers absolutely love this method. 010
Nad @nadsec.online · 01/05/2026You think this is bad.. give it a couple weeks. It gets much worse. 🤣 000
Nad @nadsec.online · 30/04/2026The people in Sydney severely over estimate how much I care about running them over on my BMX. Same with cars, I’ve bunny hopped on and off of atleast 3 car bonnets so far 🤣 000
Nad @nadsec.online · 28/04/2026Rat spec bug bounty methodology 2026: CVE Any% WR attempt. No keyboard. Pre-stage robot flick legal. Maintainer aggro manipulation allowed. Embargo skip allowed. 000
Nad @nadsec.online · 23/04/20262003, Arizona iced out boys. Emotional Shawties in this biatch, Makaveli. 000
Nad @nadsec.online · 22/04/2026Another1 - CVE-2026-41285 - OpenBSD nvd.nist.gov/vuln/detail/... (Project asswing was not involved)nvd.nist.govNVD - CVE-2026-41285 012
Nad @nadsec.online · 20/04/2026Is “Robofuzzing” taken? If not this new bug hunting should now be called robofuzzing. 010