@thdxr@daveaitel Kind of similar to scanning for proxies back in the day β I imagine weβll see something similar for abusing misconfigured llm endpoints and agents?
Three Buddy Problem x Ekoparty Miami: Perri Adams of DARPA AIxCC fame joins the show to chat about proof engines, formal methods, and why LLMs just made a once-niche corner of computer science suddenly essential.
@perribus@juanandres_gs@ekoparty
We get into why verifiers and proof engines are the key to effective AI, why vulnerability research is so far ahead of threat intel, and the case for baking security checks directly into code generation tools like Claude Code and Codex.
Plus, designing a multi-million dollar challenge that's allowed to fail, the Mythos "too dangerous to release" debate, and musings on every LLM-discovered bug being a public bug by default.
https://t.co/sMf7Pzva0W
@GoogleVRP Personal take: The lower payouts seems acceptable and logical. The barrier to entry has been lowered. Supply vs Demand is still at play here.
when react2shell hit last year, i think vercel handled it brilliantly.
to protect their users, they paid $50,000 for every bypass researchers could find. we decided to participate, and ended up earning $170,000.
read how we did it here: https://t.co/2dM6Mf9PHU
Took a break from LDAP, fell down the dMSA rabbit hole with @YuG0rd, and watched the snake eat its own tail.
dMSA Ouroboros: self-sustaining credential extraction on patched Server 2025. Six commands. Survives attacker account deletion.
https://t.co/D9412vJAu0
Movie Idea - Johnny 5: Reflashed
Background: a security engineer revives this icon with used gpus and a custom-tuned model. Johnny 5 later taps into Mythos and becomes the Herald of Skynet