I built a universal silicon loader that runs on Apple A12+ DFU (no bootrom exploit exists), Qualcomm EDL, MediaTek BROM, and 8+ SoC families.

72KB. 20+ commands. USB4 80Gbps. ChaCha20/AES. Auto-watchdog disable. Auto-DFU boot.

Checkm8 died at A11. QSLCL works on A12-A18+ via RAM execution.

github.com/Sharif-bot-cmd/Quantum-Silicon-Core-Loader

19yo from Philippines. No team. Just code.

#infosec #reverseengineering #hardwaresecurity #jailbreak #dfu #exploitdevelopment #lowlevel #firmware #iossecurity #qualcomm #mediatek #applesecurity #cybersecurity #research

Drupal Rushes Security Fix to Plug High-Risk Bug

Drupal is rushing out a critical security update today to fix a high-risk bug that could be exploited by hackers within hours of the patch being released. The update is a core security release aimed at plugging a vulnerability that poses a significant threat to users.

https://osintsights.com/drupal-rushes-security-fix-to-plug-high-risk-bug?utm_source=mastodon&utm_medium=social

#DrupalSecurityUpdate #HighRiskVulnerability #CoreSecurityRelease #EmergingThreats #ExploitDevelopment

Drupal Rushes Security Fix to Plug High-Risk Bug

Learn about Drupal's urgent security fix for a high-risk bug and take immediate action to protect your site from potential exploits, update now.

OSINTSights

Security Researchers Uncover 47 Zero-Days at Pwn2Own Berlin

In a thrilling three-day competition, security researchers at Pwn2Own Berlin uncovered a staggering 47 zero-day vulnerabilities, raking in nearly $1.3 million in prize money, with the Devcore Research Team taking home a whopping $505,000. The top prizes included a $200,000 award for a VMware ESXi exploit and a $100,000 prize for a…

https://osintsights.com/security-researchers-uncover-47-zero-days-at-pwn2own-berlin?utm_source=mastodon&utm_medium=social

#ZeroDay #Pwn2ownBerlin #VulnerabilityResearch #ExploitDevelopment #Trendai

Security Researchers Uncover 47 Zero-Days at Pwn2Own Berlin

Discover 47 zero-days uncovered at Pwn2Own Berlin, learn about the winners and prizes. Read now and stay updated on cybersecurity vulnerabilities.

OSINTSights

Remediation Programs Often Fail to Validate Fixes

The alarming truth is that remediation programs often fall short, with a staggering mismatch between the speed of exploits and fixes - Mandiant's report reveals a mean time to exploit of just -7 days, while Verizon's data shows a median remediation time of 32 days.

https://osintsights.com/remediation-programs-often-fail-to-validate-fixes?utm_source=mastodon&utm_medium=social

#VulnerabilityManagement #ExploitDevelopment #RemediationPrograms #Mtrends #Dbir

Remediation Programs Often Fail to Validate Fixes

Boost your remediation strategy with expert insights on validating fixes and speeding up response times to stay ahead of exploits and enhance cybersecurity effectively now.

OSINTSights

Autonomous Teaming Closes Defenders' Speed Gap

The alarmingly rapid pace of cyber threats has left defenders scrambling to keep up, with the time from vulnerability disclosure to working exploit dwindling from 56 days in 2024 to a staggering 10 hours in 2026. Meanwhile, defenders are still stuck on human time, struggling to match the lightning-fast speed of attackers who now operate…

https://osintsights.com/autonomous-teaming-closes-defenders-speed-gap?utm_source=mastodon&utm_medium=social

#VulnerabilityManagement #ExploitDevelopment #AutonomousTeaming #Cve #EmergingThreats

Autonomous Teaming Closes Defenders' Speed Gap

Close the defenders' speed gap with autonomous teaming and stay ahead of attackers by learning how to accelerate your security response now.

OSINTSights

Exploiting Reversing (ER) series: article 09 | Exploitation Techniques: CVE-2024-30085 (part 03)

Today I am releasing the nineth article in the Exploiting Reversing Series (ERS). In “Exploitation Techniques | CVE-2024-30085 (Part 09)” I provide a 106-page deep dive and a comprehensive roadmap for vulnerability exploitation:

https://exploitreversing.com/2026/04/28/exploiting-reversing-er-series-article-09/

Key features of this edition:

[+] Dual Exploit Strategies: Two distinct exploit editions built on the cldflt.sys heap overflow.
[+] PreviousMode Edition: Exploit cldflt.sys via WNF OOB + Pipe Attributes + ALPC + _KTHREAD.PreviousMode flip: elevation of privilege of a regular user to SYSTEM.
[+] PPL Bypass Edition: Exploit cldflt.sys via WNF OOB + PreviousMode flip + _EPROCESS.Protection strip + MiniDumpWriteDump: elevation of regular user to SYSTEM.
[+] Solid Reliability: Two complete, stable exploits, including a multi-step cleanup phase that restores the corrupted pipe attribute Flink and _KTHREAD.PreviousMode before process exit, preventing crash on cleanup.

This article guides you through two additional techniques for exploiting the CVE-2024-30085 Heap Buffer Overflow. While demonstrated here, these methods can be adapted as exploitation techniques for many other kernel targets.

I hope this serves as a definitive resource for your research. If you find it helpful, please feel free to share it or reach out with your feedback!

The following articles will continue the miniseries about iOS and Chrome, which are my areas of research.

Enjoy the reading and have an excellent day.

#exploit #exploitdevelopment #windows #exploitation #vulnerability #minifilterdriver #kernel #heapoverflow

Today I am releasing the nineth article in the Exploiting Reversing Series (ERS). In “Exploitation Techniques | CVE-2024-30085 (Part 09)” I provide a 106-page deep dive and a comprehensive roadmap for vulnerability exploitation:

https://exploitreversing.com/2026/04/28/exploiting-reversing-er-series-article-09/

The following articles will continue the miniseries about iOS and Chrome, which are my areas of research.

Enjoy the reading and have an excellent day.

#exploit #exploitdevelopment #windows #exploitation #vulnerability #kernel #heapoverflow

AI Models Accelerate Vulnerability Research, Raising Cybersecurity Risks

Commercial AI models are rapidly advancing vulnerability research and exploit development, cutting the time from discovery to exploitation and significantly raising the stakes for cybersecurity. This emerging trend poses new and heightened risks for the industry.

https://osintsights.com/ai-models-accelerate-vulnerability-research-raising-cybersecurity-risks?utm_source=mastodon&utm_medium=social

#AiModels #VulnerabilityResearch #CybersecurityRisks #EmergingThreats #ExploitDevelopment

AI Models Accelerate Vulnerability Research, Raising Cybersecurity Risks

Learn how commercial AI models accelerate vulnerability research, raising cybersecurity risks, and discover strategies to protect your organization now.

OSINTSights

AI Models Accelerate Vulnerability Discovery, Pressing Defenders to Adapt

The double-edged sword of AI: while it's being used to help developers, it's also become a powerful tool for attackers to rapidly discover and exploit software flaws, forcing defenders to scramble to keep up. As AI-powered vulnerability discovery accelerates, the pressure is on for defenders to adapt and…

https://osintsights.com/ai-models-accelerate-vulnerability-discovery-pressing-defenders-to-adapt?utm_source=mastodon&utm_medium=social

#VulnerabilityDiscovery #AiModels #EmergingThreats #ExploitDevelopment #ThreatIntelligence

AI Models Accelerate Vulnerability Discovery, Pressing Defenders to Adapt

AI models accelerate vulnerability discovery, empowering attackers to exploit flaws faster. Learn how defenders can adapt and stay ahead of emerging threats now.

OSINTSights

"Our internal evaluations showed that Opus 4.6 generally had a near-0% success rate at autonomous #ExploitDevelopment But #MythosPreview is in a different league.

For example, Opus 4.6 turned the vulnerabilities it had found in Mozilla’s Firefox 147 JavaScript engine—all patched in Firefox 148—into JavaScript shell exploits only two times out of several hundred attempts. We re-ran this experiment as a benchmark for Mythos Preview, which developed working #exploits 181 times, and achieved register control on 29 more."

https://red.anthropic.com/2026/mythos-preview/

Claude Mythos Preview \ red.anthropic.com