Gergely Kalman (@gergely_kalman) 's Twitter Profile
Gergely Kalman

@gergely_kalman

bug bounty hunter I guess
@[email protected] | gergelykalman.bsky.social

ID: 1245425475180277772

linkhttps://gergelykalman.com/ calendar_today01-04-2020 18:59:22

2,2K Tweet

1,1K Followers

361 Following

clearbluejar (@clearbluejar) 's Twitter Profile Photo

"Running #Ghidra on the same platform as the binaries you’re analyzing isn’t just convenient — it’s strategic." medium.com/@clearbluejar/


"Running #Ghidra on the same platform as the binaries you’re analyzing isn’t just convenient — it’s strategic."
medium.com/@clearbluejar/

LaurieWired (@lauriewired) 's Twitter Profile Photo

Bush hid the facts
about UTF-16 Encoding. It’s 2004, you fire up your Zune-themed WinXP rig. A friend tells you to type a string into notepad.exe. Save. Close. Reopen. Now it's nonsensical Chinese. This wasn't some NSA conspiracy; it's a horrible Unicode bug.

Bush hid the facts
about UTF-16 Encoding.

It’s 2004, you fire up your Zune-themed WinXP rig. A friend tells you to type a string into notepad.exe.

Save. Close. Reopen. Now it's nonsensical Chinese.

This wasn't some NSA conspiracy; it's a horrible Unicode bug.
Attila Szasz (@4ttil4sz1a) 's Twitter Profile Photo

Amid all the hype I despise, let’s not forget: Chaos Theory (2006) by Hungarian team Conspiracy—a mind-blowing 64k (!!) demoscene prod—remains the greatest feat ever with GPUs. LLMs might contend, but this just wins. bit.ly/4jf8LlQ

Olivia Gallucci ✹ (@oliviagalluccii) 's Twitter Profile Photo

I wrote a post on #macOS internals for detection engineers! 🔎 In this post, I focus on versioning quirks, system logging, and the historical context of macOS security features. I'd love to do a series on this soon—focusing on how I learned ARM basics, and how folks from

I wrote a post on #macOS internals for detection engineers! 🔎

In this post, I focus on versioning quirks, system logging, and the historical context of macOS security features.

I'd love to do a series on this soon—focusing on how I learned ARM basics, and how folks from
Gergely Kalman (@gergely_kalman) 's Twitter Profile Photo

Training submitted for OBTSv8, wish me luck. It's called "File-oriented vulnerability discovery and exploitation on iOS/macOS", which pretty much sums it up.

Gergely Kalman (@gergely_kalman) 's Twitter Profile Photo

I'm sad to say, #OBTS rejected my filesystem training, which is pretty discouraging. Considering how many of you reached out to me and found bugs because of my blogposts I will still do it, but I'm not sure where. Do you guys have conferences that you recommend?

LaurieWired (@lauriewired) 's Twitter Profile Photo

Major new QEMU update released. The coolest part? Paravirutalized Apple GPUs. You can now spin up disposable macOS VMs *with* hardware acceleration. macOS guests now expose a thin vGPU (apple-gfx-mmio). very useful for CI, reverse engineering, gfx research, etc

Major new QEMU update released. The coolest part? Paravirutalized Apple GPUs.

You can now spin up disposable macOS VMs *with* hardware acceleration.

macOS guests now expose a thin vGPU (apple-gfx-mmio).

very useful for CI, reverse engineering, gfx research, etc
Gergely Kalman (@gergely_kalman) 's Twitter Profile Photo

Monday dopamine detox over courtesy of the Spanish electric grid. Need to upgrade my ups setup as 8 hours without power and thus no comms is a little unnerving

Ryan Dowd (@_rdowd) 's Twitter Profile Photo

I didn't have enough time to weaponise this beyond a simple dos but a neat example of bypassing TCC and SIP to nuke a user's files and brick a macOS device. Only managed unlink() unfortunately, and not full rootless ent's. Requires priv'd user to succeed.

Oligo Security (@oligosecurity) 's Twitter Profile Photo

Oligo Security researchers uncovered critical vulnerabilities in Apple's AirPlay protocol, affecting billions of devices—allowing zero-click remote attacks, privilege escalation, MITM, and more. Update immediately to iOS 18.4 & MacOS 15.4. oligo.security/blog/airborne #CyberSecurity