Our #BHUSA talk โ Tool Part 1/3: Instead of fighting QL syntax, we let LLMs relax official queries by removing conservative pruning.
https://t.co/OSA0AXGBGM
A few years ago I had a weird thought: does ETH have a theoretical price ceiling?
It came from living through the FOMO cycles โ USDC depeg, BSC mania โ and watching L2s explode. Gas got so expensive I started wondering: is ETH's price actually capped by its own gas fees?
I could only test it properly recently, with Claude. here's what I found
I've uploaded the slides of my recent talk "JS Engine Security in 2025": https://t.co/1znTdICVmY. I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides).
Thanks for the fantastic conference @POC_Crew!
New blog out now! Weโre answering the top questions from the DEFCON audience and sharing the behind-the-scenes story of our victory. https://t.co/2U6Ou9S3JS #AIxCC
"AI Agents for Offsec with Zero False Positives" by @moyix, a journey on how we managed to get 0 FPs with XBOW. You can find the slides for his BH talk here: https://t.co/vFEfm5HkxT
Today, we announced the official release of OSV-SCALIBR, Google's software composition analysis library. If you are working in vuln management / security scanning, SCALIBR is for you! SCALIBR is powering most of Google's vuln scanning. Please RT
https://t.co/Xk95hlSQwd
Our slides about WASM bugs in browsers are now available.
Thanks to everyone who helped with the talk.๐ซก
Hope we can do better next time.
1. BH USA 2024: https://t.co/jy6Qua2Hfo
2. GeekCon Shanghai 2024: https://t.co/DGvkSwiIIK
cc my partners (@p1umer@xmzyshypnc1@q1iqF)
Maybe there's a potential hiccup with AFL's custom mutator post process design. If the post process happens in `write_to_testcase` and saves the sample afterward, it seems to go against the "before executing the target" guideline in the docs.
During #BHUSA Briefing "Achilles' Heel of JS Engines: Exploiting Modern Browsers During WASM Execution" we will discuss some of the interesting vulnerabilities we found on attack surface of WebAssembly and demonstrate how to exploit them >> https://t.co/eJI9e0eTsJ
Thanks to events like Pwn2Own or our V8CTF (~= exploit bounty program), we now have more data about the types of bugs exploited in V8. Based on that, we've gathered some basic statistics: https://t.co/M4ZJZkFrqL
Since returning from BH Asia last year, we have made further progress in the exploiting and eagerly anticipate sharing it with you all #BHUSA#BlackHatEvents
Luck enough that our submission was accepted by Black Hat USA 2024 last week.
We (@p1umer@xmzyshypnc1@q1iqF) will share our bug hunting trip in WASM of Modern Browsers.
[โณ๏ธ] Unlocked BlackHat Asia/USA/Europe and DEFCON during one year finally.
#BHUSA@BlackHatEvents