it's bit more nuanced.
1. llms can absolutely find nasty bugs in critical software, but it's not like proving a novel theorem, it's rinse and repeat of known vulnerability patterns across huge codebases.
3. we never had the human resources to clear up the debt. in general, a few researchers had the taste, and attention to find novel bugs, think of entirely new vulnerability classes. a few hundred more could focus to sit down, search through huge code space and find bugs in stuff like v8. a few thousand could handle the lower end, the basic bugs, ~pentesters~
5. llms are pretty good at the lower and shallow middle layers, and importantly they are relentless. throw tokens huge codebases, and it will bring up all the shallow bugs, which was previously never got human attention from those few hundred researchers. have better scaffolding and infrastructure for feedback loops, it finds better findings.
5. but currently, no amount of raw tokens is going to one-shot something bugs people like manfred/xion/jann/orange(few on top of my mind). for that class of work, the operator still matters enormously. if you already understand the attack surface, you can use the llm to navigate the search space much faster. the speedup is real, but the tool is still only as good as the operator. not everyone can suddenly pwn anything, the people who already have experience move much faster.
6. this wave likely plateaus once that layer saturates.
7. but the layer is enormous, most enterprise software thinks it's secure behind defense in depth, obfuscation, and sandboxes. those won't hold and we'll see carnage before it levels off. we are going to see huge amount of cves this year.
Gonna say it one more time in case you did not believe me
You don't buy a coaching - you invest ... can be damn sure this amazing hacker got his money worth and then some because i do not charge this much hahaha
MXSS Part 2: Why Client-Side HTML Sanitization is hard
In this video, we dive into Parser Differentials, Namespace Confusion, and the Nesting Depth Limit that led to an XSS on Google and multiple DOMPurify bypasses.
https://t.co/E25nqs4uvD
During my research for the video, I compiled the MXSS Evolution and Timeline, which is now public as blog.
Awesome MXSS: https://t.co/92QVxCW956
https://t.co/fTQNyIXQTF
Hola hackers of #Hyderabad!👋
🌐 Join us for Crypto 101: An introductory session for beginners! Due to popular demand, we're switching up our usual Hacker Mixer for this special event on August 3rd.
Don't miss out! 🚀#Crypto#Blockchain#Learning
What to expect:
✨Meet cool new hacker friends
💡Learn from experts
🔎Converse, collab, & brainstorm new ideas
If you're in Hyderabad and into #cybersecurity, register today: https://t.co/c9v51P3tIY
I did something out of my comfort zone last month. And no, it wasn't another CTF. 😃
I hosted Hyderabad's first Hacker Mixer: an informal gathering for hackers and cybersecurity enthusiasts to mingle, talk, brainstorm, and exchange ideas. 🎉
I wasn't sure what to expect, but I'm beyond happy with the turnout. 50+ people attended the Hacker Mixer. A couple of people came all the way from Vijayawada and Bangalore. Totally insane! 🤯
The official timing for the mixer was 6-8PM, but the conversations flowed until 10PM. My heart is full thinking this is only the beginning.
There's so much more to come. ✨
The most unexpected guest of the evening was 7-year-old Lakshveer. A Python enthusiast and co-founder of Power Parenting, he conducts workshops for other kids, writes blogs, does marketing, and has his own YouTube channel as well.
If the future generation has so much energy and enthusiasm, I know humanity as a whole is going in the right direction. 🌟
Cheers to more such Hacker Mixers, amazing conversations, and meaningful connections in the future. 💖
#event #hackermixer #cybersecurity
Learn how @assetnote discovered unauthenticated XSS and RCE on Citrix products, shedding light on critical security risks.
Dive into their research in the latest issue of InfoSecWriteups Weekly Newsletter! https://t.co/sLd8ohruaD
Discover how identifying unique attack surfaces can unlock critical vulnerabilities easily, as shared by @hacker_ in their latest thread 💡
Find out more in the InfoSecWriteups this weeks Weekly Newsletter! https://t.co/3WdPpnPbSg
📢Attention Bug Bounty Hunters & CTFers based in India📍
🔎Here's a chance for you to play a part in keeping critical infrastructure secure...
...& win bounty upto 10 lakks in return💰
NCIIPC live hacking event happening this month.
Interested participants DM us, & we'll get back to you🚀
🔥 99th edition of IWWeekly is LIVE 🔥
In this week's newsletter learn about:
1. TOP 10 hacking techniques of 2023
2. CSP Bypass
3. Multiple XSS o n Joomla
4. Meteor subdomain takeover
5. Length filter bypass to SQL Injection
Read here: https://t.co/lHGGt8abXC