AlphaGo moments for security, where agents find attack paths no human would consider, won't come from coercing agents into retracing conventional patterns
The hardest problems are rarely solved by adding more complexity to the solution -- they are solved by reframing the question until a simpler, clearer answer reveals itself.
A bunch of companies are banning developers from pushing vibe-coded software to production.
Who didn't see this one coming?
Vibe-coding is amazing, but we are now realizing what happens when we let anyone put autogenerated slop in front of users.
We need something better.
.@realGeorgeHotz doesn’t follow the script.
From jailbreaking the iPhone at 17 and reverse-engineering the PS3 to building open-source self-driving technology at @comma_ai, he's consistently pushed the boundaries of what's possible.
Now, as founder of @__tinygrad__, he’s focused on opening up the AI compute stack.
He’s also one of the most candid voices on AI and how to get the most out of AMD solutions.
That’s exactly why he’s joining the Advancing AI Developer Track.
Register: https://t.co/bILVcMveFL
#AdvancingAI #AMDevs
a sloppy unreliable exploit for this nice cBPF uaf that doesn't require bpf (ebpf) privs (cap_bpf/unpriv bpf) tested on centos10.
4.5 -> 7.1
https://t.co/yvHDRoqWPZ
I've a huge man crush on the entire @trailofbits team, I mean there are very few out there right now doing the shizzle that others dream of doing.
Trailmark is impressive where it turns source into a call/class/function graph and then that means our robot overloads can query
This is misleading framing by the BBC.
Completely omitting from the headline that the synagogue hosted an event that was encouraging and facilitating Palestinian land theft.
Instead it’s worded as though a place of worship itself was the target.
For the last 2 weeks, I've been on a graph adventure and mostly looking at older codebases I once abused, this time was httpd 2.0.35, coz we all love the chunk truffle shuffle...
With my new sqlitedb option, we've made strides in feeding this into models
AI companies have open source initiatives. But critical infrastructure that doesn't fit the small-JS-lib-with-lots-of-GitHub-stars mold gets skipped.
CC: @AnthropicAI@OpenAI@GoogleOSS your tools found real bugs in our code. Maybe help us fix the next ones before they happen?
A toothpaste company has quietly killed the entire market research industry and nobody is talking about it.
Colgate published a paper showing you can predict real purchase intent at 90% accuracy by simply asking LLMs to roleplay customers.
And this is beyond insane.
If you ask an AI, "Rate this product from 1 to 5," it gives safe, middle-of-the-road garbage.
So researchers invented a method called Semantic Similarity Rating (SSR).
Instead of asking the AI for a number, they asked it to roleplay.
They gave the LLM a demographic profile. They showed it a product concept. And they asked it to write down its raw, unfiltered thoughts.
Then, they used a semantic model to translate those written thoughts into a numerical score.
The results are staggering.
Tested against 57 real corporate surveys and 9,300 actual human responses, the synthetic AI consumers matched real human buying behavior with 90% reliability.
They perfectly mirrored how different age brackets and income levels react to price changes.
And they provided detailed, qualitative feedback that was deeper and more critical than what actual humans wrote.
This destroys the economics of traditional market research.
You don't need to wait a month to see if a product will sell.
You can simulate 1,000 hyper-targeted customer interviews overnight.
You can A/B test pricing across every demographic instantly.
@dcuthbert The opening comment alone is packed with gold, including:
"Make expensive boxes tell the truth"
Despite all the advances and incidents in our field, we're still needed to operate as the reality check (aka "hammer")
"...If it had a compliance department"
Never too late :-)
Probably the best free Windows usermode exploit development training in the world.
41 tutorials. 17 years. Stack overflows. SEH exploits. Shellcoding. Egg hunting. ROP chains. Heap spraying. Unicode exploits. Bypassing DEP, ASLR, SafeSEH, SEHOP, stack cookies. Integer overflows. Memory corruption root cause analysis. Win32 and WoW64. Metasploit integration. WinDbg automation. https://t.co/V98i0hvXwu v1 through v3.
Updated in 2026 for Windows 10 and 11 x64 with video walkthroughs and AI-assisted crash triage.
Free. No paywall. No login.
https://t.co/jgBNA410yF
Author: @corelanc0d3r
#ExploitDevelopment #ReverseEngineering #InfoSec
The Secure Boot master key used to verify firmware integrity across hundreds of devices was a test key generated by AMI, labeled in the certificate itself as "DO NOT TRUST." Vendors were supposed to replace it with their own keys before shipping. Most did not. The key ended up in a public GitHub repository and was sitting there exposed before anyone noticed. Devices from Acer, Dell, HP, Lenovo, Intel, Gigabyte and Supermicro were all affected.
Developers from Signal (including its protocol's co-creator) along with Microsoft and Harvard unveil Encrypted Spaces, an open-source codebase for a new generation of private collaboration apps. Think Slack, Discord, Google Docs, all end-to-end encrypted. https://t.co/t93oHWn4C3