@67_throwaway Thanks for the information, I greatly appreciate it.
And btw, I would recommend you try to write an actual modern Chrome exploit chain, BRUH.
"All the defenses you must break to exploit Chrome" sounds a bit over if you are a beginner reading this 😅 And no, we don't have to break them all to exploit Chrome. Trusted sources told me that AI was able to do it with some prompting effort, so chill y'all.
As much as I fucking hate those in-the-wild exploit guys, and want to defend vendors, vendors lately have failed to live up to the expectation of good-faith researchers with respect to a consistent quality in response. Which, is gonna fuck themselves up. This is such a hectic era
Why half of security twitter these days sounds like people having inferiority complex getting butt-hurted by AI doing better than them at some tasks, and the other half sounds like a bunch of tech bros proud of AI doing better than them at some tasks.
Such a wild time we're in.
My new hate is this flurry of people now becoming l33t 0day researchers overnight. "I found this 0day"... no... you AND THE AI found the 0day. This industry has always had people taking credit for others work. Be open and honest people, it's fine to admit that AI is playing a part (call out this BS where you see it!).
@__suto For a moment I forgot 😂 yes, let's just have fun, no need to get worked up about it guys. Submit patches, find a more fun target, whatever 😂 vendors and comps play by their rules, you come you play, otherwise go play somewhere else 🤣 I'm just having fun witnessing this tragedy
We’ve been through all kinds of situations: exploits failing, vendors turning off services during demos, patches being released the night before a demo, and more but we happily accepted and continue to play.
And if you don’t participate in the game, who cares about your opinion?
Well since Google sucks fat donkey dick (still annoyed they waited >2 months to reject my RCE payload because i used the --single-thread flag in repro)... This was disclosed yesterday: https://t.co/l1H2gjvAfb
It was my 1st attempt to report the vuln that allows for RCE on every Chromium browser since Dec 2018. This one was rejected because I was still learning how to prove Chrome reachability. Ended up filing a new report a week later after figuring out a trick to bypass Chromium's validation on video files and being able to prove reachability.
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software.
It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans.
https://t.co/NQ7IfEtYk7
Is it just me or https://t.co/W9DTvhz08b is blocking people? Some URLs are accessible but some aren't. gclient sync fails for some sub repos. freetype2 and buildtools
When people hear about these new stories about how autonomous AI can be in vulnerability research, many say: "Oh, X and Y has been doing this for N months/years".
Thing is: show, don't tell, guys. Talk is cheap, show the world the exploit, the prompt, and the patch :)
#BREAKING Iran’s Foreign Ministry:
"The process [war] that has begun will soon engulf Europe. The fire, that the US and the Zionist regime ignited, will engulf the entire world."