Blog post: On the Coming Industrialisation of Exploit Generation with LLMs https://t.co/aK4pysY1wD
TL;DR: I ran an experiment with GPT-5.2 and Opus 4.5 based agents to generate exploits for a zeroday QuickJS bug. They're pretty good at it.
Code: https://t.co/47xHRObhRy
Let me share with you while I'm building. I’ve been improving the secret detection across all loaded JS files and managed to reduce false positives a lot. If all goes well, this will ship in the next rep+ release tomorrow or the day after. Stay tuned!
Devs will always follow the hardcoding anti-pattern 😆
Okta's new bonus up to $500,000 is a call to action for the hunters who live for high-stakes targets and life-changing payouts 🤯💰
And, it's live NOW! Find critical RCE and SQLi on their core IDaaS platform and claim one of the biggest bonuses of the year: https://t.co/TzCmOm12fZ
¿Cómo se conecta el mundo del talento con el mundo hacker? 🚀
Si trabajás liderando equipos de ciberseguridad o Recursos Humanos, te invitamos a Ekoparty Hack the Talent Summit: un encuentro para conectar a quienes diseñan estrategias de talento con quienes lideran equipos de ciberseguridad. ¿El objetivo? Pensar juntos el futuro del talento hacker. 💪
💡 Sabemos que el talento está ahí afuera. El desafío ya no es solo encontrarlo: es entenderlo, atraerlo y construir entornos donde realmente quiera estar. Por eso creamos este espacio: para tender puentes y abrir conversaciones transparentes entre quienes están realmente involucrados en este desafío.
¡No pierdas la oportunidad de sumarte a este espacio de diálogo y networking con referentes de la industria! 🤓
🔗 ¡Conocé más e inscribite! >> https://t.co/lvhkbTSltX
📌 Debido a la capacidad limitada, la inscripción no garantiza participación hasta recibir confirmación.
PHRACK special edition HaRDCov3R (#71.5) to be released at https://t.co/zvu62Bhc1w (@reconmtl).
27th - 29th of June. Meet us at REcon.
Contains one 0day article from the upcoming 72 release, +unpublished 71 article, +classics and the Intro by REcon's own Hugo Fortier ❤️
I wrote-up how I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Link to the blog post below 👇
We just launched Haystack Code Reviewer, a tool that uses AI to chunk and organize the diffs in a pull request as well as guide you through them in a logical sequence!
See a quick demo over at https://t.co/mpxt857cEk. Try it at https://t.co/oYWxy4oM82!
i built myself a personal intelligence agency that delivers daily briefings for ~$1/day
it scrapes hundreds of news sources 24/7, uses gemini 2.0 flash for all the heavy lifting (reading/summarizing/analysis) and gemini 2.5 pro to write the final briefings
The security scene is missing on creating the idea of "vibe code auditing" or "vibe SAST'ing" and flood Internet with hyped videos of how to use AI to find vulnerabilities by guiding on finding sinks, sources and connections :P
El viernes me robaron el celular desbloqueado en Palermo. Gracias a que estaba preparado para este escenario, no pudieron hacer absolutamente nada con el mismo (ni formatearlo). Van un par de recomendaciones simples que les evitarán un dolor de cabeza si algún día les sucede. 👇
TODAY | Find fiction, non-fiction, cookbooks, kids books, DVDs, CDs and more for $1 or less at the Lobby Book Sale. Bring your own bag and cash. All money raised supports library programs and services.
📅 9 am-4 pm
📍 Toronto Reference Library
See you there! 📚
We just launched Haystack Code Reviewer, a tool that lays out code diffs for a GitHub pull request on an interactive canvas!
See a quick demo over at https://t.co/O2wglu6guu. If you would like to give it a spin, head over to https://t.co/DRXJ0yfQm7!