Sign in

Nad

@nadsec.online
68 followers 121 following 181 posts

Hacker (the good kind[mostly]). Breaking things, fixing them, then breaking them again. AI, robotics, honeypots, and whatever else keeps me up at night github.com/Rat5ak medium.com/@Nadsec x.com/Nadsec11

PostsRepliesMedia
Nad @nadsec.online · 7h
Mythos 5.1 review after having used it for exploit dev: Is the the best at surfacing new vulns and chaining exploits? YES Is it economical? NO it literally would cost more than paying people to do the work by hand by an order of magnitude unless you get really lucky. Nothing special. Heap of shit..
000
Nad @nadsec.online · 07/10/2026
Dey gib me angry robot
010
Nad @nadsec.online · 05/10/2026
open.spotify.com/track/7d23Mh...
open.spotify.com
Disparate Youth
Santigold · Master of My Make-Believe · Song · 2012
000
Nad @nadsec.online · 02/10/2026
Which ever country made this junk malware.. Ya'll should be ashamed. 4/10 only cause it does actually work and somehow evades EDR.. Whichever EDR vendor this was, just don't. Don't anymore. www.nadsec.online/blog/majlis-...
nadsec.online
Majlis 2026 Invitation RAT: OTP 123456 and a Snowy Village | NadSec
Robert pulls apart the Majlis 2026 invitation RAT: a WebDAV and FTP delivery chain, two command channels, nine tested commands, a screenshot bug, and one deeply unhelpful holiday photo.
010
Nad @nadsec.online · 02/10/2026
open.spotify.com/track/591GsK...
open.spotify.com
Poppy
Mac Miller · K.I.D.S. (Deluxe) · Song · 2010
000
Nad @nadsec.online · 02/10/2026
open.spotify.com/track/591GsK...
open.spotify.com
Poppy
Mac Miller · K.I.D.S. (Deluxe) · Song · 2010
000
Nad @nadsec.online · 30/09/2026
This the one I been waiting for.. shout out to Xi and da boiz watchtowr.com/intelligence...
watchtowr.com
Cisco Catalyst SD-WAN Manager Vulnerability FAQ: CVE-2026-76504
CVE-2026-76504: Authentication Bypass vulnerability in Cisco Catalyst SD-WAN Manager. Exploited in the wild per CISA KEV.
030
Nad @nadsec.online · 29/09/2026
Rascals
000
Nad @nadsec.online · 27/09/2026
Sandwhich > Sandbox
000
Nad @nadsec.online · 27/09/2026
There it is.. one day ppl gonna listen to me 🤣🤣🤣🤣
010
Nad @nadsec.online · 26/09/2026
Found dupe glitch in an gringo currency type web3 type bs thing. The robot out here printing it's own money.
010
Nad @nadsec.online · 25/09/2026
I miss asking people for directions
000
Nad @nadsec.online · 14/09/2026
Three Buddy Problem: less therapy, more rants™️ @ryanaraine.bsky.social @craiu.bsky.social @jags.bsky.social
021
Nad @nadsec.online · 14/09/2026
If Claude was a person, he’d be riding a Surron electric motorcycle through a school zone at 150kmph at 3PM on a weekday.
010
Nad @nadsec.online · 13/09/2026
open.spotify.com/track/74uyfE...
open.spotify.com
Make 'Em Proud
D.I.T.C., A.G., Fat Joe, Diamond D · Sessions · Song · 2016
011
Nad @nadsec.online · 09/09/2026
New Cisco zero day finna drop in the next month. Gonna start being used for in the wild exploitation in 2 weeks and will be publically disclosed within 2-3 weeks following. Good luck out there.
121
Nad @nadsec.online · 08/09/2026
chatgpt robot say: "Stimky as hell 😭 absolute cache-poison goblin activity."
-no context
000
Nad @nadsec.online · 08/09/2026
Watching botnets smack my honeypot infra is pure art. Unfiltered, aggressive, unrelenting yet beautifully creative. The chaos of human intent encapsulated in automated fighting robots. A digital terrarium of nerds wading through a sea of shit nobody asked for, simply because they can.
011
Nad @nadsec.online · 06/09/2026
youtu.be/7KWKIdwt7Ro?...
youtu.be
Jisoe - Australian graffiti artist documentary
YouTube video by dickies docos
000
Nad @nadsec.online · 01/09/2026
open.spotify.com/track/7sqk5H...
open.spotify.com
Love Times Pie Recurring..
Layla · Australian Hip Hop Supports CanTeen · Song · 2011
000
Nad @nadsec.online · 31/08/2026
open.spotify.com/track/0vhiGS...
open.spotify.com
Catch a Bad One
Del The Funky Homosapien · No Need For Alarm · Song · 1993
000
Nad @nadsec.online · 13/08/2026
CVE-2026-66804 - Windows Cross Device Service LPE - Writeup & PoC Found another cool one! www.nadsec.online/blog/cve-202... Not sure who found it first, but shoutout to them. Despite not being FTF, my mom thinks this one is cool, which is the only important metric 😎
nadsec.online
CVE-2026-66804: Cross Device Virtual Camera to SYSTEM | NadSec
A missing ProgramData COM path lets a standard user plant the Cross Device virtual-camera DLL, reach LOCAL SERVICE, and obtain SYSTEM.
021
Nad @nadsec.online · 11/08/2026
open.spotify.com/track/4GGbJ6...
open.spotify.com
Old School
2Pac · Me Against The World · Song · 1995
000
Reposted by Nad
Catalin Cimpanu @campuscodi.risky.biz · 04/08/2026
Also this: www.artsprofessional.co.uk/news/breakin... And this: www.cse.org.uk/news/beacon-...
021
Nad @nadsec.online · 04/08/2026
open.spotify.com/track/1oTo3i...
open.spotify.com
I Miss You
blink-182 · blink-182 · Song · 2003
000
Nad @nadsec.online · 28/07/2026
I like this one :) github.com/Rat5ak/fried... Try it out for yourself: friedbrowser.com -disclaimer, this will crash your browser and likely cause your phone to heat up for a significant period of time before crashing the device.
github.com
GitHub - Rat5ak/friedbrowser: WebGL 2 UBO browser denial-of-service research
WebGL 2 UBO browser denial-of-service research. Contribute to Rat5ak/friedbrowser development by creating an account on GitHub.
100
Nad @nadsec.online · 16/07/2026
CVE-2026-50343 - InstallService Windows local privilege Escelation - Writeup and POC Found another cool one! www.nadsec.online/blog/cve-202... Not sure who first to find was, but shoutout to them. Despite not being FTF, my mom thinks it's cool and that's all that matters 😎
nadsec.online
CVE-2026-50343: InstallService StaticPluginMap to SYSTEM | NadSec
A standard user controls plugin state consumed by Microsoft InstallService, then uses a public WinRT trigger to reach SYSTEM DLL loading.
012
Reposted by Nad
Catalin Cimpanu @campuscodi.risky.biz · 12/07/2026
No. I did it. That's why I took next week off from work
1182
Nad @nadsec.online · 08/07/2026
I’m so 30 that I’ve started drinking oat milk in my coffee. I didn’t sign up for this.
010
Nad @nadsec.online · 05/07/2026
github.com/Rat5ak/CVE-2... A kwl 1
github.com
GitHub - Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover: QNAP password reset URL injection writeup + PoC.
QNAP password reset URL injection writeup + PoC. Contribute to Rat5ak/CVE-2025-59382-QNAP-Password-Reset-Account-Takeover development by creating an account on GitHub.
000
Nad @nadsec.online · 05/07/2026
open.spotify.com/track/5Vnx5i...
open.spotify.com
一翦梅
Fei Yu-ching · 天之大 · Song · 2010
010
Nad @nadsec.online · 04/07/2026
July 2026 update.. Hoverboards nowhere to be seen. Snake still un-oiled.
010
Nad @nadsec.online · 15/06/2026
Linus Torvalds is the original vibe coder. That guy's been vibe coding for atleast a decade. Legit, he been prompting humans this whole time. Barely writes any code himself. Crazy
111
Nad @nadsec.online · 06/06/2026
open.spotify.com/track/7hdOch...
open.spotify.com
Things Done Changed - 2005 Remaster
The Notorious B.I.G. · Ready to Die (The Remaster) · Song · 1994
030
Reposted by Nad
Catalin Cimpanu @campuscodi.risky.biz · 03/06/2026
Another researcher drops a zero-day without disclosure because they're tired of dealing with MSRC blog.ammaraskar.com/github-token...
13210
Nad @nadsec.online · 02/06/2026
open.spotify.com/track/22AbXx...
open.spotify.com
Welcome To Jamrock
Damian Marley · Welcome to Jamrock · Song · 2005
010
Nad @nadsec.online · 30/05/2026
The irony of using a non-deterministic robot with system level privileges, an internet connection and a track record of flying off the rails to find software vulnerabilities in the name of security… I was promised hoverboards. That’s all I have to say.
030
Nad @nadsec.online · 14/05/2026
I just realised old school C2s in the command line are about to come back. AI ain’t all bad.
000
Nad @nadsec.online · 09/05/2026
Dablinkenlichts.exe
000
Nad @nadsec.online · 05/05/2026
Presenting, for absolutely no reason at all, CVE-2026-31431 as a 587-byte x86_64 static ELF: github.com/Rat5ak/CVE-2...
github.com
GitHub - Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC: 587-byte x86_64 LPE for CVE-2026-31431
587-byte x86_64 LPE for CVE-2026-31431. Contribute to Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC development by creating an account on GitHub.
010
Nad @nadsec.online · 05/05/2026
Snakelang > Python
000
Nad @nadsec.online · 05/05/2026
If ya didn’t want me to order parts for an F18 to my house yall shouldn’t have put the damn portal on the internet. No idea where I’m gonna store all these ejector seats!
010
Nad @nadsec.online · 05/05/2026
Shoutout Tupac open.spotify.com/track/0NzNKU...
open.spotify.com
So Many Tears
000
Nad @nadsec.online · 01/05/2026
Pro tip: always test on the wrong operating system, then manually recreate every byte-level platform quirk yourself. Trust me, triagers absolutely love this method.
010
Nad @nadsec.online · 01/05/2026
You think this is bad.. give it a couple weeks. It gets much worse. 🤣
000
Nad @nadsec.online · 30/04/2026
The people in Sydney severely over estimate how much I care about running them over on my BMX. Same with cars, I’ve bunny hopped on and off of atleast 3 car bonnets so far 🤣
000
Nad @nadsec.online · 28/04/2026
Rat spec bug bounty methodology 2026: CVE Any% WR attempt. No keyboard. Pre-stage robot flick legal. Maintainer aggro manipulation allowed. Embargo skip allowed.
000
Nad @nadsec.online · 23/04/2026
2003, Arizona iced out boys. Emotional Shawties in this biatch, Makaveli.
000
Nad @nadsec.online · 22/04/2026
Another1 - CVE-2026-41285 - OpenBSD nvd.nist.gov/vuln/detail/... (Project asswing was not involved)
nvd.nist.gov
NVD - CVE-2026-41285
012
Nad @nadsec.online · 20/04/2026
Is “Robofuzzing” taken? If not this new bug hunting should now be called robofuzzing.
010