https://t.co/BAIKnAPUHU v0.7 will take place on Wednesday, October 7th, and will feature two talks.
⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯
𝐑𝐞𝐜𝐨𝐯𝐞𝐫𝐢𝐧𝐠 𝐒𝐨𝐮𝐫𝐜𝐞 𝐂𝐨𝐝𝐞: 𝐁𝐢𝐭-𝐏𝐞𝐫𝐟𝐞𝐜𝐭 𝐑𝐞𝐜𝐨𝐦𝐩𝐢𝐥𝐚𝐭𝐢𝐨𝐧 𝐔𝐬𝐢𝐧𝐠 𝐂𝐥𝐞𝐯𝐞𝐫 𝐓𝐫𝐢𝐜𝐤𝐬 𝐚𝐧𝐝 𝐀𝐈 (@gynvael)
Getting a decompiled project to compile is one thing. But what if you wanted to recompile a piece of software into a byte-for-byte identical executable? This talk is a case study of achieving a bit-perfect recompilation of an old DOS game, from the initial idea and manual reverse-engineering work to the design of a fairly complex, regression-proof system that ensured the AI didn’t meander while decompiling and lifting the code.
𝐀𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐧𝐠 𝐀𝐩𝐩𝐒𝐞𝐜 𝐰𝐢𝐭𝐡 𝐀𝐠𝐞𝐧𝐭𝐬 (𝐑𝐲𝐚𝐧 𝐒𝐞𝐚𝐫𝐥𝐞)
We’re transforming traditional security reviews with agents. Learn how we’re gathering application context, generating threat models, and identifying and fixing control gaps and vulnerabilities.
⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯⎯
@snyksec, the AI-driven developer security platform, has an office at Zollstrasse 17, next to Zurich’s main railway station. Snyk has kindly offered https://t.co/BAIKnAPUHU a new home, and its office will serve as the meetup’s new venue.
If you haven’t joined us at https://t.co/BAIKnAPUHU before and you’re a Zurich-based professional working in appsec, pentesting, vulnerability research, AI security, or anything in between, come along!
https://t.co/gZ13dnk08o
https://t.co/BAIKnAPUHU v0.6 will take place on Monday, September 21st at Headsquarter The Historic in Zürich. Visiting speaker @CernicaIonut will present “Objects That Never Existed: A Reconstruction Failure Class in LLM Pipelines”, examining how frontier LLMs can reconstruct structured data as containing objects that never existed, why current defences fail to detect the problem, and how it affects production systems. If you're into appsec, penetration testing, vulnerability research, AI security, agentic security, or anything in between, come join us!
https://t.co/D1602yz9mM
We'll try something different for https://t.co/BAIKnAPUHU v0.5. The following two resources will take centre stage:
- "Sifting the Noise: A Comparative Study of LLM Agents in Vulnerability False Positive Filtering" [1]: Filtering false-positive vulnerability alerts through iterative codebase exploration.
- @nvidia's SkillSpector [2]: Evaluating agent skills for malicious behaviour and installation risks.
There won't be a speaker. Instead, we'll have a guided exploration built around a series of questions, giving you a chance to validate your understanding and hear how others interpreted the same resources.
If you can join us on Monday, August 31st, at HeadsQuarter The Historic in Zürich, please take an hour beforehand to familiarise yourself with the paper and repository. As usual, the event is on Luma [3].
If you haven't joined vulnz yet but you're a Zurich-based professional working in appsec, pentesting, vulnerability research, AI security, or anything in between, come join us!
[1] https://t.co/ezjJm8egTm
[2] https://t.co/SS72sIkVLe
[3] https://t.co/pjSxgrlzLc
@endrazine@defcon I felt some DEF CON talks were slop, sterile, or should have been nothing more than abstracts. Yours was a sinful combination of technical depth, analogies, and laughs 😈. A sincere thank you for saving the last day at the con!
Two months ago, @borski and I started an Agentic Red Team at @GoogleDeepMind under @tpiastrelli’s leadership. We’ve spent these first two months learning how a frontier lab works from the inside.
You’ll work closely with internal teams, colleagues from the same guild and Academia, attack agentic systems across reasoning, tool use, memory and trust boundaries, and turn the results into reusable techniques and scenarios.
https://t.co/BAIKnAPUHU v0.4 will take place on Wednesday, July 29th at HeadsQuarter The Historic in Zürich. @xorkiwi will introduce us on poisoning attacks on RAG systems and V will expose recurring vulnerability-inducing architectural anti-patterns and insecure defaults in Ruby on Rails applications. If you're into appsec, pentesting, vulnerability research, AI security, or anything in between, come join us!
https://t.co/MRIqrV8hZS
https://t.co/BAIKnAPUHU is back this June!
We will meet on Monday, June 29th, at HeadsQuarter The Historic in Zurich. Luca will explain why our AI systems need SAST and SCA tools, and @cybaqkebm will go deeper into Android userspace exploitation, complementing his talk from vulnz v0.1.
If you’re into appsec, pentesting, vulnerability research, AI security, or anything in between, come join us.
https://t.co/FBtLq5vEc0