TGViewer
Channel Public Channel
zerodayalpha

zerodayalpha

@zerodaytraining

Official Telegram channel of Zero Day Engineering Research & Intelligence - zerodayengineering.com
Subscribers
1.49K
Photos
119
Videos
2
Links
127
Recent Posts 12 shown
Post #231 651
⚡️ 0-Day Alert: Chrome v8 RCE exploited in the wild

CVE-2026-85046: v8 array-builtin callback side-effect to elements-kind transition confusion.
Affects both Turbofan and Maglev.

Exploit will work in default config but requires multiple other bugs to achieve arbitrary code execution on the system. The bug alone without helpers could do for an UXSS.

Patched in Chrome 152.0.7977.82/.83
Post #230 776
Browser Exploit Surface model + bug overlay

CVE callouts: randomly picked exploitable bug samples from historical records

@alisaesage
Post #229 888
Mastery container: Multi-Specialization Essentials

A curated course of foundational webinars and hands-on masterclasses taught by @alisaesage, covering the introductory essentials of the three classic specializations at Zero Day Engineering: vulnerability discovery, hypervisor and browser exploitation.

Made for self-paced study with minimal prerequisites that can be taken over a weekend as orientation in the field or initialization of multi-specialized work with AI.

Details: https://zerodayengineering.com/training/multi-essentials.html

Purchase within 21 September 2026 to get a reduced price for any full training of your choice.
Zerodayengineering Training: Multi-Specialization Essentials — Zero Day Engineering Multi-Specialization Essentials — a curated bundle of foundational masterclasses on vulnerability discovery, hypervisor and browser exploitation
Post #227 910
⚡️ 0-Day Alert: IBM LangFlow OSS RCE

LangFlow deployments have been under active exploitation since May.

CVE-2025-34291: CORS misconfiguration + SameSite=None
CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter
CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID
CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse
CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain

Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist.

Majority pattern: takes input from an API endpoint variable and executes it directly on the OS.

Attack pattern suggests that LangFlow has not seen appropriate security hardening from the vendor, and shouldn't be deployed in environments where an arbitrary code execution poses a risk.

* Attached: 33017 diff and code trace to exec()
Post #226 1.1K
"In an era where autonomous AI agents are increasingly being used for vulnerability hunting, this course was a great reminder that deep vulnerability research still depends on a unique methodology, analytical thinking, and understanding systems at their core not just automation." – Malik Kurbanov, Founder & CEO
  • ❤ 15
  • 🔥 2
Post #224 972
⚡️ Linux Kernel just issued a single-fix security update for stable LTS branches, addressing CVE-2026-64560.

We were able to exploit the bug and independently confirm that it's serious.

The impact is kernel code execution and EoP from unpriveleged user with no CAPs/userns, io_uring disable + BPF JIT hardening. The use-after-free primitive is reliable despite the race (<1m to exploit).

No wild attacks were seen yet. They are likely, given our technical picture.

Majority of Android devices are affected. Exploitability on Android wasn't empirically confirmed yet.
Post #223 883
zerodayalpha VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remote attack on vCenter – CVE-2026-59309: auth bypass via network access CVE-2026-59310: directory traversal RCE An exploit would allow…
vmxnet3 is a ESXi-specific network card emulator. We've done some research on binary diffing and exploitation of it previously: https://zerodayengineering.com/research/vmware-esxi-vmxnet3-from-patch-to-poc.html

It is included as a hands-on case study in Hypervisor Vulnerability Research training: https://zerodayengineering.com/training/hypervisor-vulnerability-research.html

Alpha Exploit Intelligence subscription offers an experienced human practitioner advisory on current threat landscape – join the next cohort: https://zerodayengineering.com/intelligence/alpha/index.html
Zerodayengineering Alpha Intelligence — Zero Day Engineering Alpha Intelligence. Exploit alerts, deep technical analysis, and apex offensive judgment for defensive decision makers.
  • ❤ 2
Post #222 853
VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006).

Two attack vectors:

1. Remote attack on vCenter –
CVE-2026-59309: auth bypass via network access
CVE-2026-59310: directory traversal RCE

An exploit would allow control of entire ESXi infrastructure.

2. A VM-escapable set of two bugs –
CVE-2026-59310: vmxnet3 OOBW
CVE-2026-41703: core OOBR

These are likely chainable to break out of VM and achieve code execution on hypervisor OS, as a privileged guest OS user.

Diffing and exploiting (1) is straightforward and should be patched promptly.
  • ❤ 4
Post #220 1.18K
"About three months ago I started the Browser Exploit Design training of Zero Day Engineering.

A very interesting self-paced course where a combination of browser internals, realistic exploit development workflows and hands-on exercises based on modern browser 0-days is discussed. It includes topics such as DOM use-after-free bugs, JavaScript engine type confusion and sandbox escapes in Chrome, Firefox and Safari/WebKit.

It is without a doubt the most challenging course I have followed so far in the field of (browser) exploitation. And I still have a lot to learn in this. But much more insight into how browsers work and how browser exploits are done in practice. To be continued." – Ian van der Wurff, Hacker || OSCE3 | OSCP
Post #219 1.08K
New Certification System https://zerodayengineering.com/training/certification/

Zero Day Engineering now issues a Certificate of Competence — proof of integrating the training and applying it to current frontier challenges in scope. Project-based, evaluated for honest merit.
Older posts →

About this channel

How can I read @zerodaytraining without a Telegram account?
TGViewer shows the public web preview Telegram publishes for zerodayalpha: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does zerodayalpha have?
zerodayalpha (@zerodaytraining) has 1.49K subscribers on Telegram, refreshed roughly every 30 minutes.
Does zerodayalpha know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →