Last week @Zai_org released GLM 5.3, and we (@semgrep) got early access to evaluate its vulnerability detection capabilities. Here are our results.
I genuinely think open weight models are still very under hyped for cyber security tasks. We're seeing open weight models genuinely challenge the frontier labs. Models for vulnerability detection are getting both cheaper (per vulnerability detected) and more capable (finding more verified issues with less noise).
BUT we also see open weight models take more tokens (and time) to achieve the same results as frontier models. So they have some catching up to do there, but it's worth remembering that a lot of cyber tasks like identifying vulnerabilities from code are simply not as time critical as other use cases.
Luna is still insanely good value for money!
@ghidraninja@defcon The two things I found strange were sudden applause from elsewhere in the room, and not being able to tell if mic position (demo labs had it on the podium) was resulting in excessive plosives.
@4rkodix@malwareunicorn Call For Papers - the people reviewing the main stage, demo lab, and maybe some of the other submissions (workshops/trainings).
@SouthwestAir complaining about limited overhead bin space and not many people checking bags.
Solution? Bring back a free checked bag for each passenger.
Ever wondered how to hack a jetski?
Today at @defcon, 2pm, track 5, I will show how I reversed a jetski diagnostic protocol to go from "no key, no ignition" to blasting it across the water!
@trailofbits@domenkozar Maybe will try submitting, though I’m guessing the projects that get accepted are likely more foundational building blocks that the world runs on…
I have a spare +1 code that can be used to register for #BSidesLV if anyone wants to go but missed out on registering before participant badges sold out - reply or send me a DM.
My 13 y/o cousin called me out when I said pymsi works in any browser. Pyodide doesn’t work on Apple Watch because no WebAssembly support… but a pure JS version could sorta work.
Sadly, watchOS also has no support for a file picker.
@InsiderPhD HackerTracker is showing the AI Slop detection talk on Aug 9 @ 10:30am, which is different than the blog post. Hopefully it’s recorded… or maybe I can catch it and run right to the airport after!
eReader hacking also sounds like a fun one!
2025-08-04
"The Perfect BLEnd: Reverse engineering a bluetooth controlled blender for better smoothies"
By Edward Farrell and Ryan Mast @rmast
Added to the Bluetooth Security Timeline: https://t.co/RRNdoqVT2b
@InsiderPhD Submitting talks is a good tip — it brings a group of people to you that are also interested in whatever you’re talking about. There are also often opportunities to meet other speakers.
The worst that can happen is the talk gets rejected, saving the time it takes to prepare.