@dinodaizovi Remember that dynamic asm code rewriting defense spec…. LLM same thing just in software, the security isn’t it’s free from bugs, it’s that now you’re bugs are specialized to you at the code level instead of the ABI or architecture 🙃
@dinodaizovi Definitely finding bugs has never been the problem, every time I see an article about how an LLM did something secretly related, how many times I used to see the same article about some 15 year old hacking NASA, getting a job because of wow so hard!
Today I’m sharing a blog post on the implementation of kernel mode shadow stacks on Windows! This post covers actively debugging the Secure Kernel and also outlines why VTL 1 is relied on to help maintain the integrity of the supervisor shadow stacks! https://t.co/Ti0FxkDS4J
@steren Yeah I hear you, dragged back to the GILimited stack kicking and screaming… I currently believe in pydantic and UV/UVX (uvx pip or just uv) and you get something pretty close to batteries included 0.02$
Just finished my writeup about CVE-2025-23369, an interesting SAML authentication bypass on GitHub Enterprise Server I reported last year. you can read about it here: https://t.co/Ee61EoACtE
New year, I'm officially open for new opportunities. If you need a guy focused on (Windows platforms) advanced vulnerability research and (zero-day) exploit detection, please let me know. :) #OpenToWork
Over the past year, we have made significant progress in leveraging GPT for vulnerability detection,
including integrating it with static engines (https://t.co/Z4wbJTbRfD), combining RAG with formal verification (https://t.co/dvtjjeFuRr),
and employing RAG for GPT vulnerability detection (https://t.co/nzS0Nd1F5w).
The common core of these efforts is to determine how much knowledge we can learn from past audit reports, attack events, expert experience, and all smart contracts, as well as the type and structure of that knowledge. The amount of knowledge directly affects the final outcome, making this a task where greater effort yields greater results.
Of course, there is also an ultimate solution (https://t.co/pw3MYiyW6w).
These tools have earned me a over of $50,000 in bounties over the past year and a half, without to audit anything, only vulnerability confirmation is required, which also causes me to feel that my manual auditing capabilities have deteriorated a lot....
@MarioNawfal@RobTiffany Far as anyone knows, NASA, but NDU/Arnold writes “DC Arnold —economy of roughly 10 percent of U.S. gross national product at a time” so NASA spends on ‘civilian’ projects (2020 memorandum DoD/NASA alignment) = dominate not for some clown to put a car in orbit, give me bullets
@DanielMiessler Love that fabric project you used… After reading up on psychological profiles for conservatives and liberals it’s really disillusioning, a higher % of people see socal change as the same as physical threat, I’m sorry but those big endian’s gotta go !!! Lock’m up!! 🤔😡😳🤯wtf
Our NEW paper on @Google's AI Red Team is live! Boost your organization’s AI security by learning from our group of internal hackers who identify weaknesses & ensure that AI technologies are utilized safely and responsibly.
https://t.co/UAx6sDdbzl
@AuronMacintyre Ffs farmers vote and have electoral college privileges, DuHH.
Education has to be free or we die.
Accepted to a school you go. The economy will grow faster with more people having better education (you can’t want what you don’t know)