Alexandre Borges
banner
alexandreborges.bsky.social
Alexandre Borges
@alexandreborges.bsky.social
Vulnerability Researcher | Exploit Developer (speaker 3x at DEF CON)
LANDFALL: New Commercial-Grade Android Spyware in Exploit Chain Targeting Samsung Devices:

unit42.paloaltonetworks.com/landfall-is-...

#exploitation #spyware #rce #infosec #cybersecurity #mobilesecurity #samsung #android #rce #vulnerability
November 8, 2025 at 12:25 AM
November 7, 2025 at 11:14 PM
Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer:

starlabs.sg/blog/2025/11...

#cybersecurity #exploitation #printer #exploit #vulnerability
November 7, 2025 at 1:14 AM
Operation South Star: 0-day Espionage Campaign Targeting Domestic Mobile Phones:

ti.qianxin.com/blog/article...

#exploitation #exploit #threathunting #infosec #vulnerability #mobile #0day #dfir
November 4, 2025 at 1:38 PM
October 31, 2025 at 1:58 PM
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236):

slcyber.io/assetnote-se...

#infosec #cybersecurity #deserialization #rce #exploit #exploitation #cve
October 24, 2025 at 4:00 PM
Implementing a Persistent Key-Value Store in a Tamper-Resistant Device for SGX Enclave Applications:

dl.acm.org/doi/abs/10.1...

#sgx #cybersecurity #dataprotection #enclave #informationsecurity
October 23, 2025 at 1:48 AM
September 23, 2025 at 9:02 PM
September 22, 2025 at 5:38 PM
September 13, 2025 at 2:36 PM
September 8, 2025 at 11:08 PM
Secondary Context Path Traversal in Omnissa Workspace ONE UEM:

slcyber.io/assetnote-se...

#cybersecurity #vulnerability #hacking #securecode #exploitation
September 8, 2025 at 2:02 PM
A Novel Technique for SQL Injection in PDO’s Prepared Statements:

slcyber.io/assetnote-se...

#cybersecurity #hacking #websecurity #webapp #pentest #sql
September 7, 2025 at 4:27 PM
August 14, 2025 at 12:03 AM
So far, I have already written 15 articles (1045 pages), which have been published on my blog:

blog: exploitreversing.com

Series:

[+] ERS: Exploiting Reversing Series
[+] MAS: Malware Analysis Series

Enjoy reading and have a great day.

#windows #iOS #macOS #chrome #kernel #vulnerability
August 11, 2025 at 2:12 PM
Malwoverview version 6.2 has been released:

github.com/alexandrebor...

Read the project page to learn how to adapt the configuration file to the changes.

Note: Updating Malwoverview using pip is not enough.

#threathunting #dfir #malware #incidentresponse
July 27, 2025 at 5:22 PM
[CVE-2025-38001] Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: A RBTree Family Drama (Part One: LTS & COS):

syst3mfailure.io/rbtree-famil...

#cybersecurity #informationsecurity #exploitation #google #kernel #linux #cybersecurity #zeroday
July 12, 2025 at 2:06 PM
Pwning Solana for Fun and Profit - Exploiting a Subtle Rust Bug for Validator RCE and Money-Printing:

anatomi.st/blog/2025_06...

#cybersecurity #exploiting #exploitation #infosec #informationsecurity #rce #web3 #rust
June 30, 2025 at 11:31 PM
June 17, 2025 at 1:51 PM
Hypervisors for Memory Introspection and Reverse Engineering:

secret.club/2025/06/02/h...

#reverveengineering #infosec #hypervisor #memoryanalysis #windows #rust
June 3, 2025 at 4:40 PM
Analysis of CVE-2024-38063 - Exploiting The Kernel Via IPv6 [EN]:

0xreverse.com/analysis-of-...

#cve #kernel #cybersecurity #vulnerability #ipv6 #infosec #windows
April 27, 2025 at 3:37 AM
Technical analysis of CVE-2025-31201: reverse engineering the diff between iOS 18.4 and 18.4.1 to study the changes made to RPAC.:

blog.epsilon-sec.com/cve-2025-312...

#iOS #apple #cybersecurity #reversing #pac #security #cve #vulnerability
April 20, 2025 at 3:22 PM
April 7, 2025 at 4:50 PM