Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Ovi

@0v1@infosec.exchange
  • Open on infosec.exchange

security researcher
founder @barghest@infosec.exchange
{ disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice }

i mostly dump my thoughts here

0 Followers
0 Following
15 Posts
Joined November 14, 2022
Website:
https://0x0v1.com
BARGHEST:
https://Barghest.asia

Posts

Open post
0v1
Ovi @0v1@infosec.exchange · 6d ago
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @starchy@infosec.exchange
@starchy@infosec.exchange 😂😂😂
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Aug 07, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @starchy@infosec.exchange
@starchy@infosec.exchange this should be in a gallery
0
1
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 28, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @drwhax@infosec.exchange
@drwhax@infosec.exchange not my find, just patch diff and repo'd to pull bugreport data. would be curious if we see this in the wild
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 28, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @0v1@infosec.exchange
@drwhax@infosec.exchange off by default though.
0
1
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 28, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @drwhax@infosec.exchange
@drwhax@infosec.exchange also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.
0
1
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 28, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
CVE-2026-0149
0
1
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 18, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Always hated wordpress
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 18, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
The only thing good about fedcon was meeting friends and CTFs. Now it's just a meeting place!
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 14, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @CryogenicNighthawk@4d2.social
@CryogenicNighthawk@4d2.social there is no broadly reliable method satisfying all those constraints
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 09, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @ErikUden@mastodon.de
@ErikUden@mastodon.de please make it happen
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · Jul 07, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Nearly FEDCON time. Beautiful time for corpos and LE to get together and larp as hackers fighting the good fight.
0
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · May 13, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange
Replying to @tek@todon.eu
@tek@todon.eu hope this reaches other OEMs eventually. Pixel lock in is becoming unruly
1
0
0
0
Open post
0v1
Ovi @0v1@infosec.exchange · May 05, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange

Today we are disclosing CVE-2026-0073:

A critical no-interaction proximal/adjacent remote code execution vulnerability in adbd's ADB-over-TCP authentication path.

Full technical write-up + exploit flow:

https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/

0
1
2
0
Open post
0v1
Ovi @0v1@infosec.exchange · Apr 24, 2026
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange

amongst bugs this year, i found two bugs in particular that LLMs are just totally failing at finding yet on the surface are super easy.

1 is a critical rce in android and also a high sev persistence chain with it. both resulted from manual code review, no fuzzing (android is so heavily fuzzed anyways)

most of my methodology atm is looking for logic bugs in trust boundaries. ones with big topology. for these bugs I been testing opus 4.7 + gpty in finding it, opus has been running on auto mode (we have a *cyber* approved account) for hours and still not caught it. neither is picking it up. the bug is clear if you read the code and understand the context of the component, but the agent just fails to understand the context or topology.

i can't see how the hype around mythos solves this. it feels like an architecture & compression issue. ultimately llms think in lists and have a small context window, attackers don't. we think in graphs and control flow. what they need to be effective is triage compression and graphing, which a human can do with enough experience. they need a map of the territory at a scale that fits in their context window. till that changes my view on LLMs in vuln research isn't changing.

1
0
1
0
Open post
0v1
Ovi @0v1@infosec.exchange · Aug 17, 2024
Ovi
@0v1@infosec.exchange

security researcher founder @barghest { disrupting APT, authoritarian gov, surveillance, privacy violations & corporate injustice } i mostly dump my thoughts here

infosec.exchange

We are mostly not hackers - we are the hacked.

"Schneier, a security expert, broadens the category of "hacker" to include anyone who studies systems with an eye to finding and exploiting their defects. Under this definition, the more fearsome hackers are "working for a hedge fund, finding a loophole in financial regulations that lets her siphon extra profits out of the system." Hackers work in corporate offices, or as government lobbyists.

As Henry says, hacking isn't intrinsically countercultural ("Most of the hacking you might care about is done by boring seeming people in boring seeming clothes"). Hacking reinforces – rather than undermining power asymmetries ("The rich have far more resources to figure out how to gimmick the rules"). We are mostly not the hackers – we are the hacked."

https://pluralistic.net/2024/04/17/panama-papers-fanfic/#the-1337est-h4x0rs

- @pluralistic@mamot.fr

40
2
29
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 00:07:25 UTC