Justin Elze (@hackinglz) 's Twitter Profile
Justin Elze

@hackinglz

CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars

ID: 14539104

calendar_today26-04-2008 03:27:52

52,52K Tweet

61,61K Followers

5,5K Following

neils (@midwestneil) 's Twitter Profile Photo

Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:

Brian Armstrong (@brian_armstrong) 's Twitter Profile Photo

A white unmarked van pulled up to my house yesterday and dropped off a mysterious package. (I was out of town) My security team x-rayed it and it had a battery, wires, and cylinder inside. The Bomb Squad was called in to investigate. In the end they discovered it was a gift

A white unmarked van pulled up to my house yesterday and dropped off a mysterious package. (I was out of town)

My security team x-rayed it and it had a battery, wires, and cylinder inside. The Bomb Squad was called in to investigate.

In the end they discovered it was a gift
Klaas (@forgebitz) 's Twitter Profile Photo

you really start finding the limits of LLMs once you go beyond the training data react todo apps are easy, but as soon as you start working on more complex stuff, they don't really "know" what they are doing (even when giving docs, mcp, etc.) which is very normal, because if

Justin Elze (@hackinglz) 's Twitter Profile Photo

Back on the hunt for 3d scanner I never pulled trigger before. Looks like a Raptor or Einstar. The plan is printing a bunch of aftermarket car electronics for mockup on friends cars or ones I wire.

Justin Elze (@hackinglz) 's Twitter Profile Photo

This especially if you’re planning to use things for offense. The 5 year old blogs it’s pulling from might not cut it.

Mathy Vanhoef (@vanhoefm) 's Twitter Profile Photo

Our research on open tunneling servers got nominated for the Most Innovative Research award :) The work will be presented by Angelos Beitis at Black Hat and also at USENIX Security Brief summary and code: github.com/vanhoefm/tunne… Paper: papers.mathyvanhoef.com/usenix2025-tun…

Rob Joyce (@rgb_lights) 's Twitter Profile Photo

Wow. Spain is putting salt typhoon out of business. They are just going to hand it all to them: Huawei contracted to manage their wiretaps…. therecord.media/spain-awards-c…

Dominic Chell 👻 (@domchell) 's Twitter Profile Photo

The one tip I will give to anyone starting out in any pentest / red team role is the one thing after 20 years of it I still never manage to do properly…. Report as you go ✅✅✅ That way you don’t end up spending your Sundays writing reports. Writing a report on a 3.5 month

rootsecdev (@rootsecdev) 's Twitter Profile Photo

So this was a very well intentioned blog but it’s also pretty neat if you need a persistence feature to send out phishing emails via graph API blog.icewolf.ch/archive/2025/0…

Matt Zorich (@reprise_99) 's Twitter Profile Photo

New in the Defender XDR advanced hunting platform, GraphApiAuditEvents - any blue team, threat hunter or those working on detections should make sure they get familiar with this data, it can be key for detecting malicious activity in your environment. It shows information about