@tylerni7 Even as an individual researcher, I’m finding so many bugs using AI with just my part-time efforts. I don't know whether to be happy or worried—it’s actually making me skeptical. AI will only accelerate, and automated bug-hunting platforms are going to be insane.
SPR was designed specifically to eliminate these attacks. Almost all other WiFi deployments carry inherent disconnects between L2/L3 that enable MITM attacks and packet injection, whether EAP-TLS or WPA3.
Reminder we are looking for talented security researchers in all areas (iOS, Android, Browser, 0click, AI) 🚀🚀 DM me or shoot us an email at https://t.co/NbnkFxHceg 🦊
@alfiecg_dev I came across an article about your talk - https://t.co/SIReStw1AV I wasn’t able to attend PoC this time, so I couldn’t listen to your talk. Will the slides be released soon? And is the content mostly the same as what you’ve written on your blog?
@5aelo I was hoping to see your presentation in person this time, but unfortunately I won’t be able to attend the PoC. I’ll look forward to your slides!
@seanhn I found chairs with wheels, though they don’t have armrests. There’s Solo Booth at Starbucks Circles Ginza. I haven’t visited it yet, but I’m planning to check it out soon. Seems nice!
https://t.co/eAqklKTXer
Anyone knows if there are any coworking spaces in Tokyo where the HotDesk (daily pass) seats come with chairs that have wheels and armrests? It would be even better if they also provide external monitors. At WeWork, I noticed HotDesk doesn’t have those kinds of chairs. Thank you!
I keep up with security news, and I feel the itch to dive back into full-time research—but for now, I’m just enjoying the present. Haven’t really touched computers much, but lately I’ve been hacking about a few hour a week. Using AI to hunt for crashes is still a lot of fun.
Can’t believe it’s already been 6 months since I retired. Life after retirement hasn’t been about being “productive,” but about finally using my time however I want. Starting next month I’ll be in Japan, then heading over to Europe and Bangkok, I guess.
🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. https://t.co/ule9gaXzc1
These days, when I see the results of bug hunting using AI, I truly feel glad that I retired early.
Theori at aixcc: https://t.co/9wz5JwWJ8Y
Google big sleep: https://t.co/qH47j4bgsx
Xbow: https://t.co/1e2lMJBudF
The Parallels VM escape bug reminds me of a bug I reported to VMware about two years ago. I was waiting until a patch was released before posting, but I ended up forgetting. Just an LPE bug on the host side, feel free to check it out if you're curious. (A colleague of mine forgot his MacBook password, so I discovered the bug in order to read the admin hash and crack it. He made a 'guest' account luckily before.) The diagram might look ugly, tho. PoC is available if you want, but it's a simple logic bug, so easy to exploit.
For a new setup (Mac mini and LG Dual-up display), I spent some hours and it’s pretty nice! Cursor so much helped me out crash prl_vm_app on the host side (Parallels VM escape). Have not finished the exploit yet but it’s likely exploitable. (Sorry, the cables are still messy.)