HaifeiLi's profile picture. For contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.

Haifei Li

@HaifeiLi

For contact in the security community. NOTE: All the tweets are totally my personal opinions, not about any of my current employer stuff.

Pinned

🔥🔥Announcement: Opening EXPMON for Everyone. justhaifei1.blogspot.com/2024/04/openin… EXPMON is a sophisticated exploit detection (and analytics) system specifically designed and built for detecting zero-day/unknown file-based exploits. pub.expmon.com


A fun fact: CVE-2025-62562 (msrc.microsoft.com/update-guide/v…) was an Outlook RCE/UAF that can be only triggered by.. replying to a crafted email. A very close to a "0-click Outlook RCE".. of course, I found that by accident.. :) x.com/HaifeiLi/statu…

Due to vacations, I didn't post about the Office bugs I found that were patched in the November Patch Tuesday. As today is the December Patch Tuesday and it seems to me that Microsoft has patched all my remaining bugs, I'm posting the CVEs in these two months here together.…



Well, I've almost lost tracking on this one hehe. Good memories for this finding I did at CPR. I recall that initially MSRC refused to patch the issue as well. I pushed back simply because I thought that allowing a .url file to launch the "retired" IE browser is wrong, and that…


Got back from a long vacation, oh all the pending emails and messages..


Haifei Li reposted

Congratulations to all the researchers recognized in this quarter’s MSRC 2025 Q3 Security Researcher Leaderboard! Thanks to all the researchers who partnered with us for your hard work and continued dedication to securing our customers. Learn more in our blog post:…

msftsecresponse's tweet image. Congratulations to all the researchers recognized in this quarter’s MSRC 2025 Q3 Security Researcher Leaderboard! Thanks to all the researchers who partnered with us for your hard work and continued dedication to securing our customers.

Learn more in our blog post:…

Haifei Li reposted

I had good initial feedback so I'm going to turn my lightning talk from Hexacon on "Agentic Adventures in Bug Hunting" into a full talk.. where should I send it?


Microsoft continues to patch bugs found through my Office fuzzing project. Today they have patched: - Microsoft Word Remote Code Execution Vulnerability (CVE-2025-59221) msrc.microsoft.com/update-guide/v… - Microsoft Word Remote Code Execution Vulnerability (CVE-2025-59222)…


For real? This can shake the earth a bit if true.

Based on StatCounter data from September 2025, Windows 10 holds about 41% of the Windows market share (72% of all desktops globally). With an estimated 2 billion active PCs worldwide, this suggests roughly 600 million are still running Windows 10.



I am going to buy all the stocks who haven’t announced partnership with OpenAI yet.

Walmart $WMT and OpenAI just announced a partnership that will "Start with allowing customers and members to soon shop Walmart through ChatGPT using Instant Checkout"

StockMKTNewz's tweet image. Walmart $WMT and OpenAI just announced a partnership  that will

"Start with allowing customers and members to soon shop Walmart through ChatGPT using Instant Checkout"


Now it gets a bit harder to track which of my Office bugs were patched today (reported ~28 Office bugs since I started the Office fuzzing project one year ago)..


Come on @dustin_childs - why is your blog coming late today? I know I’m impatient, but I got bugs to read and fun to enjoy! #PatchTueday

Come on @AdobeSecurity - why are your bulletins so late these days? I know I'm impatient, but I gots blogs to publish and such! #PatchTuesday



What the F. Now I have concluded AI is in a bubble.

💣 We caught @ycombinator–backed @gecko_sec stealing two of our CVEs, one on @ollama , one on @Gradio. They copied our PoCs, claimed CVE IDs, and even back-dated their blog posts. Here’s the full story 👇

FuzzingLabs's tweet image. 💣 We caught @ycombinator–backed @gecko_sec  stealing two of our CVEs, one on @ollama , one on @Gradio.
They copied our PoCs, claimed CVE IDs, and even back-dated their blog posts.
Here’s the full story 👇


As this is a stock Friday and Tavis is leaving Google, I’m going to share a thing about @taviso. Many years ago there was a fake cybersecurity story about Super Micro motherboard and Tavis pointed that out on Twitter and said he was buying the dip of the stock to prove his point.…


Loading...

Something went wrong.


Something went wrong.