Asjid Kalam

285 posts

Asjid Kalam banner
Asjid Kalam

Asjid Kalam

@odinshell

machine mechanic

Dubai Beigetreten Ağustos 2018
1.4K Folgt519 Follower
Asjid Kalam retweetet
Calif
Calif@calif_io·
As far as we can tell, no. There is only anecdotal evidence, along with claims from AI pentesting vendors. If a strong model can do everything by itself, then what exactly have these vendors been building? It is understandable that people would prefer a story in which the harness, workflow, and surrounding infra matter a great deal. It's also why people keep flexing "0-days" in OpenSSL, FFmpeg, or nginx, despite limited real-world impact. That said, Niels Provos was not trying to sell anything, and he and several people have reported good results with IronCurtain despite using relatively weak models. Most importantly, what Google achieved with Chrome suggests that a good harness may be quite valuable. Google does not appear to have access to anything more capable than Mythos, which means they likely scanned Chrome using Mythos itself or something less powerful. Yet they still uncovered hundreds of bugs. There is, however, another explanation. Google may simply have better Chrome/V8 experts who can extract more value from Mythos. This remains our preferred hypothesis. What provides a real advantage: domain knowledge accumulated over many years, or a harness vibe-coded in an afternoon? We think the answer is fairly obvious.
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦@yo_yo_yo_jbo

@calif_io Are there public measurements of how much improvement good harness offers?

English
5
13
82
14.9K
Asjid Kalam retweetet
kqx
kqx@kqx_io·
Pwning V8CTF with a 0day in Chrome thanks to Phi untagging. Read here: kqx.io/post/cve-2026-…
kqx tweet media
English
3
35
205
15.5K
Asjid Kalam
Asjid Kalam@odinshell·
@0xdef1ant same, its been stuck in the same status for over a month now
English
0
0
4
234
def1ant
def1ant@0xdef1ant·
i think this is promising? but Apple's Security Research UI is so barren that i can't rly tell. any Apple bug hunters care to comment?
def1ant tweet media
English
4
0
24
3.7K
Asjid Kalam
Asjid Kalam@odinshell·
incredible amount of bugs reported from google, i wonder what the security team is cooking
English
0
0
4
291
Asjid Kalam
Asjid Kalam@odinshell·
FSA FTW!
Asjid Kalam tweet media
English
1
1
16
1.3K
Asjid Kalam
Asjid Kalam@odinshell·
@A3_N_ yeah the fork with the ko-fi link 😂😂
English
0
0
0
48
Asjid Kalam
Asjid Kalam@odinshell·
got controlled fake object -> constrained kernel write. insane chain from agents
English
1
0
7
672
Asjid Kalam
Asjid Kalam@odinshell·
netlink OOB 👀👀 on linux 7.0.0-g27d128c1cff6
Asjid Kalam tweet media
English
0
6
50
4.6K
Asjid Kalam
Asjid Kalam@odinshell·
3 reliable non-sandboxed browser process heap UAFs, all with codex modified fuzzers and handholding. more cves incoming. harness > model
English
0
0
5
452
Asjid Kalam retweetet
Christos Tzamos
Christos Tzamos@ChristosTzamos·
1/4 LLMs solve research grade math problems but struggle with basic calculations. We bridge this gap by turning them to computers. We built a computer INSIDE a transformer that can run programs for millions of steps in seconds solving even the hardest Sudokus with 100% accuracy
English
247
804
6.1K
1.8M