We are excited to announce our first speaker for https://t.co/NSdktUM8QC: Valentina Palmiotti (@chompie1337), who will be presenting BinChomp - her autonomous n-day exploit generation pipeline!
Registration for #SekaiCTF 2026 is now open: https://t.co/GzovO60S6Y
Our prize pool features USD$8,000 in cash and prizes worth over $10,000! Additionally, the top team will be invited to the 11th XCTF Finals.
P.S. Make sure to bring your essentials...
Last summer I was learning about RL implementation and tried to make an AI that plays Pokémon Red. One year later you don’t even need RL, and even more - you can build an entire Pokémon Red clone.
thank you everyone who attended my @OrangeCon_nl talk! also a big shout out to the OrangeCon orga team for another successful event! 🍊
if you want to hear me yap for 30 minutes about tokens, plastic and 0day:
https://t.co/noErpjVXz1
I recently had an interview with @jstrosch on the Behind the Binary podcast about @natashenka and I's Pixel 9 exploit chain with a bit of a bonus conversation about vulnerability research and security in the age of AI! You can find the whole episode here🎧
https://t.co/nH9ZJGKSAX
Big news: @lcamtuf has joined us.
Michal has been advising us since the earliest days of the company, helping us navigate everything from difficult strategic decisions to situations that were difficult primarily because we created them ourselves.
As the business has grown, so has the number of problems that can only be solved by asking, "What would Michal think of this?" We're delighted that he has now joined us officially and can no longer pretend not to see our messages.
We're also excited to share that Michal has granted us an exclusive world-wide license to commercialize his groundbreaking C/C++ remote dependency technology.
Existing customers are encouraged to begin planning their migration to our next-generation implementation, which has been carefully re-engineered with Claude in PHP to maximize nostalgia value for some of our hackers.
Welcome aboard, Michal!
Happy to finally share my Redis research from https://t.co/Pqbc7l20D8 2025! DarkReplica (CVE-2026-23631) is a Use-After-Free in Redis's built-in Lua engine.
Full technical writeup: https://t.co/NNvKuXW7WT
I am really happy to announce that my research on adobe sandbox escape exploiting a windows CVE has been published on the Exodus Intelligence's blog
https://t.co/BFtXsTpWOj
Since I sold $ADBE at $414 in May last year, I no longer have a position.
But I may re-enter as a SHORT TERM TRADE if it can break and close above the $259 resistance, which will confirm the 1-2-3 trend reversal.
Update: ended the CTF with 30/35 challenges solved. I don't know what challenges I did, nor did I ever manually download any challenge files or open them on my computer.
The 5 challenges it didn't solve: an AI challenge with 0 solves, a forensics challenge where it messed up on the OCR and interpreted the flag wrongly (but it produced the right images), and 3 challenges where I ran out of Claude Max and Codex Pro usage limits.
I have mixed feelings about this. On one hand, what's the point of CTFs anymore if it becomes an AI token-maxing pay-to-win game? On the other hand, I never really cared tooooo much about the competitive element of CTFs - the odds were always skewed anyway with variable team sizes at DEF CON.
I think CTFs can remain a valuable place for people curious about the scene to learn and have genuine fun solving challenges. But online CTFs should definitely not be treated as a competitive sport anymore. I've already seen so many cracked CTF players leave the scene because of this...
There is probably also an argument to be made that if most of VR work today is babysitting Claude, then maybe it's fine that CTFs mimic real-world work? But the thing that attracted many of my friends and me to CTF was the fact that it was accessible to anyone. Will $200 subscriptions be the new barrier to entry?
4 RCE chains across 4 LiteLLM versions, each patched within days of working.
What started as #Pwn2Own Berlin prep turned into a race against the vendor’s commit log.
https://t.co/OFB7GBIosm
By @bestswngs & @bruce30262