@Ivanklydz

Security researcher with deep focus on vulnerability detection. CTO and lead researcher at https://nitter.cf/t.co/n3BQO59nz7 Contact: ivan@klydz.net @vulonehq

Joined April 2025
Our product (back track ai) at @vulonehq was able to uncover a threat actor who goes by the alias (quake3) a most wanted fugitive in less than 5 minutes. when me and my friend started vulone we never expected the platform to advance this fast nor this good, it pushed every limit we ever expected, I'm not hyping it up, I'm genuinely left stunned and low-key scared of what this thing is capable of doing. I'll visit GISEC conference this month to meet sponsors and investors, we really have the golden ticket for success, we are only missing enough funding for storage servers. vulone.com/blog/quake3-the-x… cc @wall3ss @vulonehq
2
2
23
3,882
Ivan (Adem El Adeb) retweeted
Replying to @banthisguy9349
Your talking crap about a guy that helps many people. He was young and stupid and that shit happens but people change and he changed for the good. So why talking crap from the past about someone that didn’t do shit to you? That’s a L move!!
1
1
2
110
Ivan (Adem El Adeb) retweeted
Stupidest take, people make mistakes especially young and assuming they will always be that way is toxic. Encourage redemption instead of looking down on it.
Of course Pryx is “clean”. And now attention seeking through Reuters. Let me make something clear here. This dude is a cybercriminal should be arrested as well.
2
5
1
11
1,052
Ivan (Adem El Adeb) retweeted
Someone put this larping fursack in a gulag for electroshock therapy
Of course Pryx is “clean”. And now attention seeking through Reuters. Let me make something clear here. This dude is a cybercriminal should be arrested as well.
1
2
1
10
1,086
هاذ مبزرة؟ @xabdul
1
6
664
Ivan (Adem El Adeb) retweeted
When they have follow up questions about sources and methods.
4
8
1
76
4,733
We built a LiteLLM Compromise Checker to help you verify whether your secrets appear in the exfiltrated data by TeamPCP. @IceSolst you might wanna check this out vulone.com/litellm-checker/
2
4
17
1,343
solution is easy: we all use @kernelstub's platform to host code someone should cover the costs for hosting though
Another security researcher account taken down, just 404s now Are we going to have to move all infosec repos off github? Maybe smelly @vxunderground can host our instance and we just have an infosec git server and move away from github to solve this bs permanently?
1
12
961
Ivan (Adem El Adeb) retweeted
my github account just got shadow banned, i already submitted a ticket, if anyone can pull strings to get github to look at why it was shadow banned that would be nice. here's the ticket number: #4841776
11
9
2
61
11,670
Did you know that shodan doesn't index their scanners IPs
2
2
7
1,012
Ivan (Adem El Adeb) retweeted
CWP maintainers/devs have a root backdoor in all CWP instances world wide.. why? isn't that illegal? @vxunderground @404mediaco @MikaelThalen @joetidy
Oh yeah, this is the allowed host for the CWP backdoor. 151.80.90.202 Whoever gets access to it literally has ssh access and priv keys to all the CWP instances in the world :). Support backdoor :)
1
2
11
1,080
what? I just said hi...
3
1
13
2,202
Time to get back to windows
10
815
In Western samples, lower scores on cognitive tests and numeracy are associated with stronger right-wing authoritarianism. Just saying.
1
3
669
I was able to reconstruct the vulnerability, this took me an entire day. yes the vulnerability exist, what paris is saying is true and makes complete sense, dread servers weren't compromised. @vxunderground @vxdb @DailyDarkWeb @xenumonero @solminingpunk @DoingFedTime
🚨 Dread admin confirms critical GoBalance zero-day vulnerability behind recent .onion hijackings Dread administrator "HugBunter" says a vulnerability in GoBalance allows attackers to derive Tor onion private keys from publicly available service descriptors, potentially enabling them to impersonate legitimate onion services. The vulnerability reportedly affects all released versions of GoBalance, with multiple darknet markets also impacted. Key points: • No Dread server or database compromise, according to the administrator. • Attackers can potentially recover onion identity signing capabilities without accessing the server. • The attacker reportedly used AI to discover the vulnerability. • Dread plans to release a patched version of GoBalance shortly. • Dread is working to recover affected onion addresses and redirect users to legitimate services. HugBunter also claims the attacker attempted extortion but provided no evidence of possessing Dread's database. https://dreadohblesmagfagqup24vw7catlvmqhhce5itz7wxr4vffgemjzaad[.]onion/post/f8c46a6418adcbbbd3da
2
8
92
5,010
1/ vulone actor watch | 6 Oct PM Everest claims Flydubai. ASOS app users got an extortion push. ShinyHunters claims H&M as the FBI portal story names Accenture. Atlassian drops a critical unauth bug. 🧵 2/ CLAIM: Everest says it took 4.36GB across 16,517 files from Flydubai (UAE aviation): flight ops, crew-training docs, personnel records. Unverified. 3/ ASOS (UK retail): app users got an unauthorized push carrying an extortion message (REPORTED). The hackers claim they "fully compromised" ASOS's Snowflake instance (CLAIM). Snowflake-era tactics are back. 4/ ShinyHunters claims H&M Group (SE): internal production and logistics DBs (CLAIM). FBI portal follow-up (REPORTED): multiple arrests across several countries, contractor named as Accenture, entry via Oracle PeopleSoft + WAF bypass tied to CVE-2026-35273. 5/ CONFIRMED: Atlassian disclosed CVE-2026-21589, a critical unauthenticated path traversal hitting 8 Data Center products. Patch before PoCs land. 6/ Ransomware CLAIMS: Everest: Kennametal (US machinery), publish in 7 to 8d Qilin: Inova Semiconductors (DE) ThreeAM: Fleetworks Inc (US truck repair) 7/ Forum CLAIMS: pink_cyber_bf: Laboratorio Clínico Rey Fals (CO) 10M+, Iquique Hospital (CL) 10K patients nathan0303: 9M records tied to CAF, Darty, Boulanger (FR) Hacktivists: LUNARISSEC + SILENT TRACE alliance; NoName057 DDoS on Italian sites
1
5
1,211
CWP maintainers/devs have a root backdoor in all CWP instances world wide.. why? isn't that illegal? @vxunderground @404mediaco @MikaelThalen @joetidy
Oh yeah, this is the allowed host for the CWP backdoor. 151.80.90.202 Whoever gets access to it literally has ssh access and priv keys to all the CWP instances in the world :). Support backdoor :)
1
2
11
1,080
The terms do not mention, authorize, or require users to accept a vendor-controlled root SSH key or an allow-list entry for IP 151.80.90.202. CWP do not document or mention this anywhere.
4
341
both are gone now, should we speak freely?
As my colleague @xpl0itrs stated here, Just some hours ago @pcpcats was maliciously targeted and wrongfully banned. This was a Petty and quite frankly childish attack originating from the Threat actor Known as "Rey". this is just a small glimpse into the personality type of the aforementioned Person.. Do better bruh. @xpl0itrs @xploitrsturtle2 @pcpcats #Freethecats #FreePCP #TeamPCP #Bitwarden #Checkmarx #SupplyChain
3
313
What if your hacking workstation was reproducible, hardened, themed, and left no traces on disk? Meet pwnbox: NixOS + Home Manager for hacking, reverse engineering, Active Directory, and networking. 26 tool categories. One declarative setup. Zero disk traces. Credits to @wall3ss for the whole website and hosting! pwnbox.one
4
20
102
4,158