Последние посты

Order of Six Angles
22 сент., 07:02
Windows Exploitation Techniques: Dangling COM Object Registrationshttps://projectzero.google/2026/09/windows-dangling-com.htmlprojectzero.googleWindows Exploitation Techniques: Dangling COM Object RegistrationsThis short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
Order of Six Angles
22 сент., 06:37
анонс на Apsara Conference 2026. Alibaba заявила, что сейчас тренирует следующее поколение Qwen 4. Дальше по дорожной карте идут Qwen 4.5 и Qwen 5 с масштабом 5–10 трлн параметров


Order of Six Angles
22 сент., 06:11
Infecting android applications - The new way (English version) https://orderofsixangles.com/en/2020/04/07/android-infection-the-new-way.html Новый способ внедрения вредоносного кода в андроид приложения (Русская версия) https://orderofsixangles.com/ru/GitHubGitHub - thatskriptkid/apk-infector-Archinome: Apk infectorApk infector. Contribute to thatskriptkid/apk-infector-Archinome development by creating an account on GitHub.
Order of Six Angles
21 сент., 15:40
Working, tested code for every chapter of the book The Art of Exploit Development: Vulnerability Research and Exploitation on Today's Hardened Systems.https://github.com/KazamaDono/taoxdGitHubGitHub - KazamaDono/taoxd: The Art of Exploit Development companion code.The Art of Exploit Development companion code. Contribute to KazamaDono/taoxd development by creating an account on GitHub.
Order of Six Angles
21 сент., 04:57
Android 1-day exploit by LLM (GLM-5.3)15 числа вышло сентябрьское обновление безопасности для Pixel. У меня как раз имеется Pixel 6a, который все еще обновляется (2022 года, срок поддержки 5 лет), и он обновлен до июля 2026 года (августовского обновления не существует, пропущено гуглом). Я решил проверить, способна ли LLM написать 1-day exploit, имея только смутное публичное описание уязвимости в вышедшем бюллетене.Я попросил Grok 4.6 xhigh (Cursor) сделать дифф двух прошивок (Google Factory Images). Он их скачал, распаковал, сравнил по хэшам каждый компонент, выявил те, которые теоритически получили патч. Затем реверс (декомпиляция) каждого бинарника кандидата, для выявления изменений в каждой конкретной функции. Затем маппинг находок с публичными CVE. После верификации мной находок наиболее достижимым показалась уязвимость уровня High в компоненте BigWave (аппаратный
3,370Открыть в Telegram
Order of Six Angles
20 сент., 05:43
A snapshot of arXiv's metadata, version history, submission files and rendered documents. It covers 3,148,796 papers and includes file contents, paths, sizes and SHA-256 digests.https://huggingface.co/datasets/secemp9/arxiv-completehuggingface.cosecemp9/arxiv-complete · Datasets at Hugging FaceWe’re on a journey to advance and democratize artificial intelligence through open source and open science.
Order of Six Angles
18 сент., 11:57
в ios будет edr?https://x.com/C2IRIS/status/2100692307250938322?s=20X (formerly Twitter)IRIS C2 (@C2IRIS) on XNEW: Apple is preparing to implement a kernel level EDR system in iOS When activated, the watchdog, known as https://t.co/dohCGrRsH1.iokit.EndpointSecuritySE, which is still in beta, will monito…1,180Открыть в Telegram
Order of Six Angles
18 сент., 03:55

1,210Открыть в Telegram
Order of Six Angles
17 сент., 14:22
Golang loader that uses vulnerable drivers to terminate EDR and antivirus processes before dropping Formbookhttps://youtu.be/Wz6ROkJ3AZg?si=cO8uan3vRo7NTZZsYouTubeGolang BYOVD Malware Loader and Vulnerable Driver Analysis (Stream - 08/09/2026)In this stream we analyze a Golang loader that drops and exploits drivers (also known as Bring Your Own Vulnerable Driver or BYOVD) to terminate antivirus and EDR processes prior to downloading and executing a Formbook payload. We also analyze the drivers…1,880Открыть в Telegram
Order of Six Angles
17 сент., 11:16изменён
Из размышлений дипсика
Order of Six Angles
14 сент., 16:46
Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkithttps://github.com/Idov31/SilversealGitHubGitHub - Idov31/Silverseal: Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkitSilverseal is a Linux framework containing a bootkit, rootkit loader and a rootkit - Idov31/Silverseal1,520Открыть в Telegram
Order of Six Angles
14 сент., 15:31
Vibe Exploitation
1,450Открыть в Telegram
Order of Six Angles
14 сент., 12:31
Flicker and fall: rooting the Philips Hue Bridge both remotely and wirelesslyhttps://blog.thalium.re/posts/rooting-the-philips-hue-bridge-remotely-and-wirelessly/THALIUMFlicker and fall: rooting the Philips Hue Bridge both remotely and wirelesslyThe Philips Hue Bridge is the control center of the Hue lighting system. As part of Pwn2Own Ireland 2025, we identified several bugs which allowed fully compromising the bridge locally or remotely, including a vulnerability chain in the HomeKit component…1,480Открыть в Telegram
Order of Six Angles
14 сент., 12:24
The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast radius, tests-to-run, quality deltas. Signatures at 74.7% fewer bytes than bodies; every guess labelled, every loss published. Paddle out with a map.https://github.com/redhat-et/ripwireGitHubGitHub - redhat-et/ripwire: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you…The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast radius, tests-to-run,...1,380Открыть в Telegram
Order of Six Angles
14 сент., 09:15
A Year of Hacking with LLMshttps://sites.google.com/site/zhiniangpeng/blogs/Hacking-with-LLMs-EngGoogleA Year of Hacking with LLMsThis blog is a summary of my talk at the Offbyone 2026 cybersecurity conference. It records some of my thoughts as a cybersecurity researcher after spending a year using LLMs for research. Slides: https://github.com/edwardzpeng/presentations/tree/main/offbyone%202026…1,540Открыть в Telegram
Order of Six Angles
14 сент., 04:38
"Я переписал runtime Modern Warfare 2: уже можно побегать с оружиями из MW3 и Black Ops" https://www.playground.ru/call_of_duty_modern_warfare_2/opinion/ya_perepisal_runtime_modern_warfare_2_uzhe_mozhno_pobegat_s_oruzhiyami_iz_mw3_i_black_ops-1869386GitHubGitHub - vladtrc/iw4L: Standalone experimental Call of Duty runtime in Rust, built on bevy and wgpuStandalone experimental Call of Duty runtime in Rust, built on bevy and wgpu - vladtrc/iw4L1,460Открыть в Telegram
Order of Six Angles
11 сент., 12:51
Победил Qwen 😻1,690Открыть в Telegram
Order of Six Angles
11 сент., 12:42
На данный момент, для offensive security я использую связку grok 4.6 (cursor) + deepseek v4 pro (hermes + openrouter). Грок делает ресерч, документирует поверхность атаки, ищет имеющиеся инструменты, читает статьи, строит первоначальные поки. Затем это все
1,830Открыть в Telegram
Order of Six Angles
11 сент., 10:58
Пол дня работал у меня DeepSeek V4.1 Flash, потратил 6.62$. Результат мне нравится. (Hermes + openrouter)
Order of Six Angles
10 сент., 12:59
