Sign in

Mikhail Shcherbakov

@yu5k3.bsky.social
732 followers 171 following 87 posts

Doing security research. For fun and profit...

PostsRepliesMedia
Mikhail Shcherbakov @yu5k3.bsky.social · 26/11/2025
The photo is from the conferment of new PhDs at Stockholm City Hall. Perfect final point before fully switching back from academia to industry 👋 3/3
010
Mikhail Shcherbakov @yu5k3.bsky.social · 26/11/2025
For the same reason I paused systematic BB and my monthly reports here. Now most of the work on my side is finally done, and I'm waiting for some big (and positive) changes ahead ✈️🧳🌍 Share all the details soon. 2/x
110
Mikhail Shcherbakov @yu5k3.bsky.social · 26/11/2025
Bet you haven't seen a hacker aka bug hunter in a tailcoat in your feed. Now you have 😜 I disappeared a bit in the last few months because of a lot of urgent stuff to close. 1/x
120
Mikhail Shcherbakov @yu5k3.bsky.social · 23/07/2025
Also planning to finally drop those promised threads in the coming weeks: my V8 exploit dev journey, some client-side #bugbountytips, and maybe more depending on what I dig up from my old notes ✍️
020
Mikhail Shcherbakov @yu5k3.bsky.social · 23/07/2025
Due to vacation, June (and probably July) don't bring many reports: - 1 Crit reported; - 1 Crit 9.9 😎 ( @elastic.co fixed the #RCE chain behind my CVE-2025-2135 exploit discuss.elastic.co/t/kibana-7-1... and CVE-2025-25012 discuss.elastic.co/t/kibana-7-1...); - 1 new Medium closed as Informative.
discuss.elastic.co
100
Mikhail Shcherbakov @yu5k3.bsky.social · 23/07/2025
Looks like now's the right time to finally dive in! The threat model for extensions looks promising for BB. postMessage() alone opens up new attack variations that don't exist in classic client-side apps 💡 Let's see what I can find in this space 👀
100
Mikhail Shcherbakov @yu5k3.bsky.social · 23/07/2025
🌊 2025 YTD #BugBounty stats update, June: 📄 13 issues Reported (5 Crit, 2 High, 6 Medium) 💰 10 issues Paid ⚪ 1 Informative Late update this time, just came back from vacation and started digging for new targets to research. I've had my eye on browser extensions for a while.
110
Mikhail Shcherbakov @yu5k3.bsky.social · 13/06/2025
@shaunau.bsky.social If you haven't seen my previous talk about Kibana RCEs (it doesn't cover these ones), you might find it interesting, especially if you're into tricky Prototype Pollution exploits. Check it out youtu.be/H-bhmSwnRdY?...
youtu.be
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov
YouTube video by DEFCONConference
120
Mikhail Shcherbakov @yu5k3.bsky.social · 13/06/2025
Yeah, many Kibana RCEs I reported are beautiful. They implemented a lot of mitigations I had to bypass 😁 I'd love to share details, but for this bug it's too early. I'm also too lazy for blog posts, usually just drop stuff at conferences. Definitely need to do one more talk on Kibana RCEs.
120
Mikhail Shcherbakov @yu5k3.bsky.social · 11/06/2025
If there's interest, I might write a thread on the resources that I used to dev my own Chrome RCE exploit. Also, if you have an SSRF in Chrome 134 in a BBP, DM me. It could be a great collab to turn the report into a full RCE 🤝 #bugbounty #infosec #rce #chromium #v8
000
Mikhail Shcherbakov @yu5k3.bsky.social · 11/06/2025
- Open-source repo = easy diffs for n-days - Regression tests (if you're lucky) help a lot - Controlled JS = powerful primitives, e.g., heap- & jit- spraying - V8 sandbox adds that spicy edge 🌶️
110
Mikhail Shcherbakov @yu5k3.bsky.social · 11/06/2025
I played with Chrome vulns back in Jan, mostly trying to reproduce n-days. In May, I found promising targets and developed an RCE from scratch to reverse shell in Chromium 134. Low-level exploits are real fun 🔥 and Chromium is an awesome playground for them:
110
Mikhail Shcherbakov @yu5k3.bsky.social · 11/06/2025
🤓 2025 YTD #BugBounty stats update, May: 📄 11 issues Reported (4 Crit, 2 High, 5 Medium) 💰 9 issues Paid A new month means 2 more RCEs reported 👌 This time I hit Chromium headless browser for the first time in BBPs.
120
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
So yeah, I've started thinking about switching back to industry and ending the full-time BB experiment. Don't be surprised if that happens in the next couple of months, it'll just mean the dark side with cookies and performance reviews won this round 😅
000
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
Hitting my Q1 milestone of earning the same as I would've by signing my last job offer definitely gives me motivation to push even harder. That said, my current efforts haven't led to any big breakthroughs in my BB methodology.
110
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
Still, it opens up more opportunities that I'm trying to take advantage of. I'm investing time into researching new types of attacks and building out automation. This is really the kind of life I enjoy: taking risks and being fully responsible for everything that happens!
110
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
The first financial goal, reaching income comparable to a full-time IT job, is achieved! Two RCEs with a bit of "collateral damage" per month has been enough to make it work, though I won't lie, it's way more stressful.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
In April, I reported 2 #RCE (consistency 😎), and once again, one of them was classified as Medium. Fine, move on. Many previously reported vulns also got paid this month 💸 I've been doing BB full-time since late last year, so it's a good moment to sum things up.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
If I have extra time, I go through old notes and mine a few more, usually with less critical severity. As you can see, some RCEs end up being classified as Medium due to BBP restrictions... but even then, the bounties were not too bad.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 13/05/2025
👌 2025 YTD #BugBounty stats update, April: 📄 9 issues Reported (2 Crit, 2 High, 5 Medium) 💰 8 issues Paid Switched to monthly updates instead of weekly. Why? I don't drop new vulns every week 😅 My stats from the last months confirm my "capacity": ~2 RCEs per month.
140
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
RCE in Elastic Kibana via Prototype Pollution (CVSS 9.9) 🚀 www.cve.org/CVERecord?id...
cve.org
150
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
RCE in Elastic Kibana via Prototype Pollution (CVSS 8.7) 🤔 Curious about the A:N in the vector for the RCE... typo or did I miss something?.. www.cve.org/CVERecord?id...
cve.org
120
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
Unrestricted File Upload in Elastic Kibana (CVSS 5.4). Part of another chain ending in XSS and showing ATO impact. I shared some details at my last DEF CON, but the deep dive is still in the vault. Looks like I've hoarded enough CVEs for the next talk 😅 www.cve.org/CVERecord?id...
cve.org
110
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
Unrestricted File Upload in Elastic Kibana. Part of the most beautiful and non-trivial chain I've built. I'm excited to get a chance to share the full story in a con talk someday 🤞 www.cve.org/CVERecord?id...
cve.org
120
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
RCE in Elastic Kibana via Prototype Pollution (CVSS 9.1) 🔥 www.cve.org/CVERecord?id...
cve.org
120
Mikhail Shcherbakov @yu5k3.bsky.social · 07/05/2025
Just noticed @elastic.co shipped a bunch of CVEs for the 0-days I reported. Threading them here for memory and tipping my hat to the Elastic Security Team ❤️ top-tier BBP and meticulous triage. Highly recommended for Bug Hunters 😎 #bugbounty #0day #rce
120
Mikhail Shcherbakov @yu5k3.bsky.social · 02/04/2025
🫡 2025 YTD #BugBounty stats update, March: 📄 7 issues Reported (2 Crit, 1 High, 4 Medium) 💰 2 issues Paid Reported 2 RCEs and some "collateral damage" for March. Still investigating new targets and developing my own tools.
010
Mikhail Shcherbakov @yu5k3.bsky.social · 26/02/2025
I also agree that there are cases where RCE can be an expected issue,eg via ffmpeg in an isolated container. My concern is about changing the reported CVSS without any clarification. An RCE can be paid as Medium if it affects a non-priority target (and BBP says it),but this fact does not affect CVSS
110
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
I agree. I remember @ajxchapman.bsky.social had an even worse case where an RCE was classified as Low, right? Did you try requesting mediation/support from the platform? Did it help?
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
That’s an open source web app in the BB scope of a big corporation 😶 I cann’t say exactly since it’s not fixed yet. Once it’s patched, I definitely want to share the details. Let’s see how it ends up! Still hoping they’re open to discussion and will fix not just the bug but its severity as well 😀
110
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
- DDay was right: "Finding Bugs is Easy – Finding Scope is Hard." If you haven't read one of the best BB stories yet, go enjoy it: douglas.day/2024/12/13/H...
douglas.day
How I Became The Most Valuable Hacker
This January, I found myself under Miami’s sun, hacking for Capital One at HackerOne’s H1-305 live hacking event (LHE). Imagine this: 50-100 of the world’s best hackers flown to a fun destination on a...
020
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
- Time to expand beyond classic web app targets. Need to invest in learning new threat models, technologies, and attack surfaces. Balancing BBPs with learning new things is hard, but gotta keep pushing!
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
Need to figure out how to leverage H1/Bugcrowd/Immunefi APIs to pull new targets for analysis automatically instead of wasting time on it.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
Takeaways: - Definitely need more automation. Right now, I use static analysis to detect vulns and suspicious code patterns but still search for targets manually. That takes way too much time, and 50 apps per week is not enough to find gems.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
Other than that, just the usual routine: small updates to my automation, re-testing previously reported cases, and frustration over the lack of new results 🤦‍♂️
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
Luckily, over the weekend, I found a few promising cases, quickly analyzed them yesterday, and hopefully will exploit them this week.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
Most of the week was spent hunting for new targets. Ran my analysis tools on 50+ apps and got... nothing. No new reports, no exploitable cases, just a few FPs and some edge cases unlikely to be accepted due to their threat models.
100
Mikhail Shcherbakov @yu5k3.bsky.social · 25/02/2025
😵‍💫 2025 YTD #BugBounty stats update, Week 8: 📄 2 issues Reported (1 Crit, 1 Medium) As you can see, the stats became even worse this week 😆 One RCE got classified as Medium for the first time in my life 🤯 Trying to negotiate and explain its impact, let's see how it goes...
230
Mikhail Shcherbakov @yu5k3.bsky.social · 17/02/2025
Now I'm trying to expand my methodology to more programs. Let's see how it pays off by the end of the month!
000
Mikhail Shcherbakov @yu5k3.bsky.social · 17/02/2025
😐 2025 YTD #BugBounty stats update, Weeks 6-7: 📄 2 issues Reported (2 Crit) Reported 2 RCEs and sticking to my plan of focusing on Criticals. Not too much for two weeks, but chaining vulns takes more time than expected.
130
Mikhail Shcherbakov @yu5k3.bsky.social · 06/02/2025
This week, I got my first payments for reports from Nov-Dec. Looks like a ~2-month wait from report to payment is what to expect when going full-time in BB 💰 The goal for the next few weeks is simple: report as much as possible 😎
000
Mikhail Shcherbakov @yu5k3.bsky.social · 06/02/2025
For staying up to date on the latest "suspicious" Chromium commits and getting ideas for n-days, I really recommend following x.com/xvonfers. It's short summaries for discovering the hidden corners of V8 and finding inspiration for new exploits!
100
Mikhail Shcherbakov @yu5k3.bsky.social · 06/02/2025
If you want to dive into Chrome exploitation and modern attack surfaces, I highly recommend checking out x.com/0x10n research. Many of his issues are public, making them a great way to study WASM internals and elegant exploitation techniques.
110
Mikhail Shcherbakov @yu5k3.bsky.social · 06/02/2025
In my free time, I started learning something new: binary vulnerabilities and browser exploitation. Writing the first n-day Chrome exploit is actually a lot of fun!
100
Mikhail Shcherbakov @yu5k3.bsky.social · 06/02/2025
🚀 2025 YTD #BugBounty stats update, Week 5: 📄 0 issues Reported I took the last days of my parental leave in Jan and spent most of the time with kids and family. No reports, no vulns, just quality time 👨‍👩‍👧‍👦
140
Reposted by Mikhail Shcherbakov
PortSwigger Research @portswiggerres.bsky.social · 04/02/2025
The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
26636
Mikhail Shcherbakov @yu5k3.bsky.social · 25/01/2025
If you want to hear cool BB stories about how I used these gadgets, check out the #DEFCON talk youtu.be/H-bhmSwnRdY
youtu.be
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov
YouTube video by DEFCONConference
012
Reposted by Mikhail Shcherbakov
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/01/2025
Server-Side Prototype Pollution gadget collection github.com/KTH-LangSec/server-side-… #BBRENewsletter87
1111
Mikhail Shcherbakov @yu5k3.bsky.social · 15/01/2025
I presented this at @defcon.bsky.social this year. If you're into #BugBounty stories and tricky exploits, check out the slides, watch the video youtu.be/H-bhmSwnRdY, and vote for your favorite web hacks of the year!
youtu.be
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov
YouTube video by DEFCONConference
010
Mikhail Shcherbakov @yu5k3.bsky.social · 15/01/2025
Now's the time to vote for the Top 10 Web Hacking Techniques of 2024! I'm excited to see my research "Exploiting the Unexploitable Insights from the Kibana Bug Bounty" nominated this year! 😎
110