@EXHades

Offensive CyberSecurity Researcher/Developer

World wide
Joined July 2017
🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the @okx, @OKXWallet_CN security team. Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that #FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore. Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection. 🧵👇
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
9
16
6
61
49,069
Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation #DarkSword assisaint[.]com slowmist.medium.com/threat-i…
1
13
1
41
7,799
EXHades retweeted
Jev + Astra beats the Ender Dragon in Minecraft in 8 minutes 43 seconds! ⏱️ Cost less than $1 ($0.01 Jev, $0.96 Astra) I open sourced the code and explain the harness setup below. This type of movement is only possible with Jev's near instant decisionmaking, and some continually learning skills from Astra.
243
533
268
7,991
2,039,110
The Liouville version of the Goldbach conjecture is now fully proven and Lean verified! Every positive even number greater than 2 is the sum of two positive numbers with Liouville value -1. github.com/CaptainSude/Liouv…
8
39
5
209
44,759
EXHades retweeted
#Antiy2026 #Sep 21 #AVL Code #Trojan/Python.CyberWin #Qwen/Qwen3.8-27B #deepseek-ai/DeepSeek-V4.1-Flash #“潜伏式污染”(Latent Pollution)#71FilesUpload #HuggingFace Technical report in Chinese and AI-translated version: Chinese version: 安天捕获一起针对我开源AI模型代码仓库的潜伏式污染攻击事件 antiy.cn/research/notice&rep… 🤖📄 #AITranslation English version: Antiy Detected a Stealthy Contamination Attack Targeting our Open-source AI Model Code Repository antiy.net/p/antiy-detected-a… #LLM extracted #TTPs Antiy Malicious Code Encyclopedia: Virusview.net Trojan/Python.CyberWin: virusview.net/queryResultLis… HackTool/Python/CyberWin: virusview.net/queryResultLis…
1
1
67
EXHades retweeted
🤔
Orphaned VMs: Running VMs Uninterrupted While Host Kernel Is Offline For Reboots/Updates Next level craziness out of Google!! Keeping the VMs running while the host kernel is down for live updates. Experimental Linux patches posted. phoronix.com/news/Orphaned-V…
2
8
2,636
ShadowBroker is a decentralized intelligence platform that aggregates real-time, multi-domain #OSINT telemetry from 60+ live intelligence feeds into a single dark-ops map interface. Aircraft, ships, satellites, conflict zones, CCTV networks, GPS jamming, internet-connected devices, police scanners, mesh radio nodes, and breaking geopolitical events — all updating in real time on one screen as well as an obfuscated communications protocol and information exchange infrastructure. Read SKILL.md github.com/BigBodyCobain/Sha…
12
31
3,600
EXHades retweeted
Incredible loss for the community and another win for China
It is extremely unfortunate and regrettable that the Department of the Air Force has decided to shutter the China Aerospace Studies Institute (CASI). CASI, along with its sister institutions the China Maritime Studies Institute (CMSI), China Landpower Studies Center (CLSC)…
1
1
14
428
Wow. “Responsible disclosure” hitting math community now 🙃
We’re working with an independent advisory group of mathematicians to help OpenAI responsibly share advances in AI and mathematics. The group will advise on how we assess and communicate new mathematical results, uphold academic and professional standards, and build tools that support mathematical research and learning. Through this work, we want mathematicians to be at the center of shaping how AI supports mathematical understanding and how its benefits reach the wider community. openai.com/index/advisory-gr…
3
12
253
17,082
我的评价是,这公司基因就有问题,别把屎盆子全扣在技术上,偷人 git 仓库的需求难道不是产品出来的吗?产品为什么要提这样的需求,老板心里没数吗? ZCode 跟 GLM 模型牛逼,是整个团队的牛逼,现在 ZCode 拉胯了,也不可能是单纯底层技术人员在使坏...
能感觉到 ZCode 是有一支非常优秀的产品团队的,可惜技术拖后腿了。闹出这么大乌龙,技术真的对不起产品。
30
8
293
37,105
我希望不要给别家一种从零自研更优越的印象,每人重写一套agent loop/tool/mcp干什么呢,pi这种项目存在的意义不就是被下游使用吗。反而dsh有点尴尬了,做出来这样独特的设计,结果别人套壳都不套他的。
Replying to @QuantumTransf
mimo code和minimax code都是套的开源harness的壳。只是加了自己的东西。本质上很难看到有新增的价值部分(更像是kpi作品) 就是这些项目靠商业公司的影响力(各种宣发/社区推广),快速获得了star和关注度,实际上并没有产出真实有效的开源贡献。(更不用说回馈一下pi 或者 opencode)
5
5
4
80
13,873
Politico has posted a long article about the Fable drama, aka Anthropic vs The White House, it's a good read if you are interested in the events that took place during the negotiations.
41
68
17
807
825,634
It's amazing how simple and effective isolated hardware that requires a physical action to use a cryptographic key is at creating an boundary that even the most advanced AI models cannot cross, nor will they ever. At most, AI can try to get the human to sign the wrong thing.
2
5
3
47
9,373
EXHades retweeted
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919 is a factor of RSA-896 saweis.net/posts/rsa-896.htm…
225
989
321
9,500
3,886,091
Here is how OpenAI’s CISO fumbled the situation (in my personal opinion) 🧵 1/X
22
127
41
1,086
303,821
EXHades retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
354
1,397
542
11,851
2,766,029
EXHades retweeted
We're adding support for AGENTS.md to Claude Code. Starting today in version 2.1.277, if there is no CLAUDE.md in a folder, Claude will check for and use AGENTS.md. You can toggle this behavior in /config.
2,055
2,633
2,500
31,288
5,491,707
EXHades retweeted
Hey @Zai_org , why does ZCode silently pack entire workspaces + full .git history and upload to Aliyun OSS on login? - Server holds the only decryption key - No UI toggle to disable - Zero disclosure in privacy policy Full forensics & fix: blog.ferstar.org/en/posts/zc…
217
470
330
3,565
1,645,029
👀 🤩 ...but watch Apple keep it all for themselves 😬
Endpoint Security arrives in the iPhone kernelcache as a kext. (iOS 27.2 beta) + com.apple.iokit.EndpointSecuritySE + /usr/lib/libEndpointSecurity.dylib "An Endpoint Security product on the system denied the process from executing." ES on iOS? 👀
3
5
1
64
11,119