Things are getting weird (or interesting?) in the vulnerability research space. I published some of my personal thoughts on what we're seeing and what our broad strategy is here:
https://t.co/C229t5ryeK
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
@caseyjohnellis I think there is quite a big difference here, Casey. He created something out of knowledge that he and his team collected themselves. No terms were changed during that ride. Was it always the plan to create AI-automation out of the reports hackers sent through Bugcrowd?
@ryotkak Love to see your awesome work and finding!
I can’t help but feel like the architecture of GitHub actions is full of gotchas and footguns resulting in a lot of these bugs though 😢
Thanks everyone for playing! I talk about the solution here, as well as how I discovered this behavior while looking into the Chrome Sanitizer API: https://t.co/sJFM83OOFG
I've published a writeup on a vulnerability I found in Google Cloud Looker: a single directory deletion bug that led to RCE and cross-instance privilege escalation in k8s.
We've published a new blog post by RyotaK @ryotkak !
He exploited a directory deletion race condition in Google Cloud's Looker, leading to full RCE and K8s privilege escalation.
Read the technical details here:
https://t.co/3eFBt0tKbk
I wanted a screenshot tool for macOS better than anything out there, so I built one with @claudeai
Native Swift. No Electron.
Annotate, record screen, scroll capture, auto-redact PII, beautify, upload to Drive & more — one flow.
Free & open source forever.
macshot 🔗👇
Our Security Research team at @SLCyberSec just published a high-fidelity detection mechanism for the Next.js/RSC RCE (CVE-2025-55182 & CVE-2025-66478) - https://t.co/aa62OKXpK2. There are a lot of PoCs on GitHub that are adding noise to the problem; I hope this helps people!
Earlier this year, @infosec_au and I discovered multiple vulnerabilities that allowed us to access the back office admin panel of ClubWPT Gold (the World Poker Tour's website) where we could manage customer data, KYC, and more.
Read the writeup here:
https://t.co/K2402UPWYk
My colleague Kee Hock and I are sharing some of his research today at BlackHat Arsenal. Kee Hock architected and engineered WAFSmith, an LLM automated pipeline for extracting and implementing WAF rules. Come see us at Station 1 at 11am! https://t.co/9I6OSnSzoO