@EXHadesi
iAccount based inSoutheast Asia!
About this account
- Account based in
- Southeast Asia
- Connected via
- East Asia App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Offensive CyberSecurity Researcher/Developer
World wide
Joined July 2017
- Tweets513
- Following1.2K
- Followers43
- Likes1.6K
EXHades retweeted
🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the @okx, @OKXWallet_CN security team.
Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that #FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore.
Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection.
🧵👇
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨
We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2.
A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️
Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version.
‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️
If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device.
🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed.
The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands.
Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk.
If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately:
1️⃣ Check your accounts and assets for any unusual activity.
2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase.
3️⃣ Move your assets to the new account as soon as possible.
4️⃣ Update your device to the latest available iOS version.
5️⃣ Do not continue using or reinstalling FomoPeek.
6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
EXHades retweeted
Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation #DarkSword
assisaint[.]com
slowmist.medium.com/threat-i…
EXHades retweeted
Jev + Astra beats the Ender Dragon in Minecraft in 8 minutes 43 seconds! ⏱️
Cost less than $1 ($0.01 Jev, $0.96 Astra)
I open sourced the code and explain the harness setup below. This type of movement is only possible with Jev's near instant decisionmaking, and some continually learning skills from Astra.
EXHades retweeted
The Liouville version of the Goldbach conjecture is now fully proven and Lean verified!
Every positive even number greater than 2 is the sum of two positive numbers with Liouville value -1.
github.com/CaptainSude/Liouv…
#Antiy2026 #Sep 21
#AVL Code #Trojan/Python.CyberWin #Qwen/Qwen3.8-27B #deepseek-ai/DeepSeek-V4.1-Flash #“潜伏式污染”(Latent Pollution)#71FilesUpload #HuggingFace Technical report in Chinese and AI-translated version:
Chinese version:
安天捕获一起针对我开源AI模型代码仓库的潜伏式污染攻击事件
antiy.cn/research/notice&rep…
🤖📄 #AITranslation English version:
Antiy Detected a Stealthy Contamination Attack Targeting our Open-source AI Model Code Repository
antiy.net/p/antiy-detected-a…
#LLM extracted #TTPs
Antiy Malicious Code Encyclopedia: Virusview.net
Trojan/Python.CyberWin:
virusview.net/queryResultLis…
HackTool/Python/CyberWin:
virusview.net/queryResultLis…
🤔
Orphaned VMs: Running VMs Uninterrupted While Host Kernel Is Offline For Reboots/Updates
Next level craziness out of Google!! Keeping the VMs running while the host kernel is down for live updates. Experimental Linux patches posted.
phoronix.com/news/Orphaned-V…
EXHades retweeted
ShadowBroker is a decentralized intelligence platform that aggregates real-time, multi-domain #OSINT telemetry from 60+ live intelligence feeds into a single dark-ops map interface.
Aircraft, ships, satellites, conflict zones, CCTV networks, GPS jamming, internet-connected devices, police scanners, mesh radio nodes, and breaking geopolitical events — all updating in real time on one screen as well as an obfuscated communications protocol and information exchange infrastructure.
Read SKILL.md
github.com/BigBodyCobain/Sha…
EXHades retweeted
Incredible loss for the community and another win for China
EXHades retweeted
Wow. “Responsible disclosure” hitting math community now 🙃
We’re working with an independent advisory group of mathematicians to help OpenAI responsibly share advances in AI and mathematics.
The group will advise on how we assess and communicate new mathematical results, uphold academic and professional standards, and build tools that support mathematical research and learning.
Through this work, we want mathematicians to be at the center of shaping how AI supports mathematical understanding and how its benefits reach the wider community.
openai.com/index/advisory-gr…
EXHades retweeted
Windows Exploitation Techniques: Dangling COM Object Registrations projectzero.google/2026/09/w…
EXHades retweeted
我希望不要给别家一种从零自研更优越的印象,每人重写一套agent loop/tool/mcp干什么呢,pi这种项目存在的意义不就是被下游使用吗。反而dsh有点尴尬了,做出来这样独特的设计,结果别人套壳都不套他的。
Replying to @QuantumTransf
mimo code和minimax code都是套的开源harness的壳。只是加了自己的东西。本质上很难看到有新增的价值部分(更像是kpi作品)
就是这些项目靠商业公司的影响力(各种宣发/社区推广),快速获得了star和关注度,实际上并没有产出真实有效的开源贡献。(更不用说回馈一下pi 或者 opencode)
EXHades retweeted
Politico has posted a long article about the Fable drama, aka Anthropic vs The White House, it's a good read if you are interested in the events that took place during the negotiations.
EXHades retweeted
It's amazing how simple and effective isolated hardware that requires a physical action to use a cryptographic key is at creating an boundary that even the most advanced AI models cannot cross, nor will they ever.
At most, AI can try to get the human to sign the wrong thing.
EXHades retweeted
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919
is a factor of RSA-896
saweis.net/posts/rsa-896.htm…
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
EXHades retweeted
Hey @Zai_org , why does ZCode silently pack entire workspaces + full .git history and upload to Aliyun OSS on login?
- Server holds the only decryption key
- No UI toggle to disable
- Zero disclosure in privacy policy
Full forensics & fix:
blog.ferstar.org/en/posts/zc…
EXHades retweeted
👀 🤩
...but watch Apple keep it all for themselves 😬
Endpoint Security arrives in the iPhone kernelcache as a kext. (iOS 27.2 beta)
+ com.apple.iokit.EndpointSecuritySE
+ /usr/lib/libEndpointSecurity.dylib
"An Endpoint Security product on the system denied the process from executing."
ES on iOS? 👀