1. X
  2. Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
Log inSign up
Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
647 posts
Jaroslav Lobačevski 🇱🇹🇺🇦jaras@infosec.exchange profile banner
user avatar

Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]

@yarlob
Researcher at GitHub Security Lab. Tweets are my own. And BTW, russian warship go f.ck yourself.
[email protected]
jarlob.github.io
Joined November 2017
311
Following
476
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·US TIDA·Ads Info·© 2026 X Corp.
  • user avatar
    Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
    @yarlob
    Jun 18
    Safer pull_request_target defaults for GitHub Actions checkout - GitHub Changelog
    From github.blog
  • user avatar
    Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
    @yarlob
    May 31
    This article didn't receive the attention it deserves. No wonder I have noticed it only now...
    I Read Every Mythos Primary Source. The Media Got Almost Everything Wrong
    From machine-learning-made-simple.medium.com
  • user avatar
    Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
    @yarlob
    May 30
    "...generating a proof-of-concept (PoC) exploit is required for defenders. Theoretical vulnerabilities identified through static analysis inevitably produce a high volume of false positives."
    user avatar
    Matt Johansen
    @mattjay
    Apr 30
    Replying to @mattjay
    He began by replicating Mythos findings with his specialized harness. Then went on to find more critical novel zero days in open source code that he can't share yet because they're not fixed. TL;DR - harnesses are where the magic is. provos.org/p/finding-zero…
  • user avatar
    Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
    @yarlob
    May 27
    PoC for CVE-2026-48095 in 7-Zip 26.00 on Linux without ASLR bypass.
    GIF
  • user avatar
    Jaroslav Lobačevski 🇱🇹🇺🇦[email protected]
    @yarlob
    Apr 4
    A zero-permission Android app could read every photo, video, voice note, and document in your Signal chats. Skipped Google Play for privacy? You were vulnerable.
    GHSL-2026-102: Unauthorized exfiltration of decrypted attachments in Signal through Intent redire...
    From securitylab.github.com