xiosec's profile picture. Security Researcher

~ xio

@xiosec

Security Researcher

Pinned

The last vulnerability I found was related to the driver of one of the Asus services that allowed reading and writing on the physical memory. This vulnerability was patched and I will probably publish a writeup about it in the future. #vulnerability #0day #zeroday

xiosec's tweet image. The last vulnerability I found was related to the driver of one of the Asus services that allowed reading and writing on the physical memory. This vulnerability was patched and I will probably publish a writeup about it in the future.
#vulnerability #0day #zeroday

~ xio reposted

120+ diagrams done: memory, goroutine stack, garbage collection, all visualized. Coming soooon!

func25's tweet image. 120+ diagrams done: memory, goroutine stack, garbage collection, all visualized. Coming soooon!
func25's tweet image. 120+ diagrams done: memory, goroutine stack, garbage collection, all visualized. Coming soooon!

~ xio reposted

LPE exploiting of a Windows NTFS vulnerability swarm.ptsecurity.com/buried-in-the-… Credits @immortalp0ny #Windows #infosec

0xor0ne's tweet image. LPE exploiting of a Windows NTFS vulnerability

swarm.ptsecurity.com/buried-in-the-…

Credits @immortalp0ny

#Windows #infosec
0xor0ne's tweet image. LPE exploiting of a Windows NTFS vulnerability

swarm.ptsecurity.com/buried-in-the-…

Credits @immortalp0ny

#Windows #infosec

~ xio reposted

Beginners intro to Linux kernel fuzzing and vulnerability research by @slava_moskvin_ Part 1: slavamoskvin.com/hunting-bugs-i… Part 2: slavamoskvin.com/finding-bugs-i… Part 3: slavamoskvin.com/finding-bugs-i… #Linux #cybersecurity

0xor0ne's tweet image. Beginners intro to Linux kernel fuzzing and vulnerability research by @slava_moskvin_

Part 1: slavamoskvin.com/hunting-bugs-i…
Part 2: slavamoskvin.com/finding-bugs-i…
Part 3: slavamoskvin.com/finding-bugs-i…

#Linux #cybersecurity
0xor0ne's tweet image. Beginners intro to Linux kernel fuzzing and vulnerability research by @slava_moskvin_

Part 1: slavamoskvin.com/hunting-bugs-i…
Part 2: slavamoskvin.com/finding-bugs-i…
Part 3: slavamoskvin.com/finding-bugs-i…

#Linux #cybersecurity

~ xio reposted

A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023- 20869) exploit by Alex Zaviyalov has just been published!

alexjplaskett's tweet image. A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!
alexjplaskett's tweet image. A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!
alexjplaskett's tweet image. A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!
alexjplaskett's tweet image. A great write-up of a VMware Workstation guest-to-host escape (CVE-2023-20870/CVE-2023-34044 and CVE-2023-
20869) exploit by Alex Zaviyalov has just been published!

~ xio reposted

Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days William Liu @cor_ctf posted an article about exploiting a slab object overflow (CVE-2023-52440) and remote infoleak (CVE-2023-4130) in the kernel SMB3 daemon to gain RCE willsroot.io/2025/09/ksmbd-…

linkersec's tweet image. Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days

William Liu @cor_ctf posted an article about exploiting a slab object overflow (CVE-2023-52440) and remote infoleak (CVE-2023-4130) in the kernel SMB3 daemon to gain RCE

willsroot.io/2025/09/ksmbd-…

~ xio reposted

Bootchain exploit for MediaTek devices PoC exploit for a vulnerability in the Nothing Phone (2a) / CMF Phone 1 secure boot chain (and possibly other MediaTek devices). github.com/R0rt1z2/fenrir

blackorbird's tweet image. Bootchain exploit for MediaTek devices 

PoC exploit for a vulnerability in the Nothing Phone (2a) / CMF Phone 1 secure boot chain (and possibly other MediaTek devices).

github.com/R0rt1z2/fenrir

~ xio reposted

Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130) willsroot.io/2025/09/ksmbd-… Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration!


~ xio reposted

ksmbd - Fuzzing Improvements and Vulnerability Discovery Another article by @73696e65 about fuzzing the ksmbd module with syzkaller. blog.doyensec.com/2025/09/02/ksm…

linkersec's tweet image. ksmbd - Fuzzing Improvements and Vulnerability Discovery

Another article by @73696e65 about fuzzing the ksmbd module with syzkaller.

blog.doyensec.com/2025/09/02/ksm…

~ xio reposted

Terminator Evade All Detection: PowerShell Script for Terminating Protected Processes with In-Memory Execution and HVCI Bypass (AV|EDR|XDR Evasion Technique) - POC in CrowdStrike" @xiosec #TerminatorScript #AVEDRXDR #POCinCrowdStrike #cybersecurity #avevasion #EDR #Crowdstrike


The #POC published in this repository for the vulnerability with ID #CVE-2023-23415 is actually a #Trojan! #> Repository: hxxps://github.com/wh-gov/CVE-2023-23415 #> IP: 106.12.252. 10 #APT #CVE_2023_23415

xiosec's tweet image. The #POC published in this repository for the vulnerability with ID #CVE-2023-23415 is actually a #Trojan!

#> Repository: hxxps://github.com/wh-gov/CVE-2023-23415

#> IP: 106.12.252. 10

#APT #CVE_2023_23415

Loading...

Something went wrong.


Something went wrong.