Erlend Oftedal

11.2K posts

Erlend Oftedal banner
Erlend Oftedal

Erlend Oftedal

@webtonull

Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js

Oslo, Norway Beigetreten Ocak 2008
2.3K Folgt3.7K Follower
CBS Sports Golazo ⚽️
CBS Sports Golazo ⚽️@CBSSportsGolazo·
"I was wrong, bad. The guys are no joke." @MikeGrella10 issues an apology to Bodø/Glimt after his pre-match prediction 😭
English
7
33
584
48.6K
Erlend Oftedal
Erlend Oftedal@webtonull·
@bcherny Can you define code output? Is it in lines of code? Output tokens? Or new features so it's not tied to the actual size of the code base?
English
0
0
0
28
Boris Cherny
Boris Cherny@bcherny·
New in Claude Code: Code Review. A team of agents runs a deep review on every PR. We built it for ourselves first. Code output per Anthropic engineer is up 200% this year and reviews were the bottleneck Personally, I’ve been using it for a few weeks and have found it catches many real bugs that I would not have noticed otherwise
Claude@claudeai

Introducing Code Review, a new feature for Claude Code. When a PR opens, Claude dispatches a team of agents to hunt for bugs.

English
463
507
7.4K
1.2M
Erlend Oftedal retweetet
BSides Oslo
BSides Oslo@OsloBSides·
New year, new me! There's a 2026 now, BSides Oslo 2026 that is. October 29th at Vulkan Arena. Information on tickets, CFP and all the rest to come.
English
0
3
4
432
Chris Laub
Chris Laub@ChrisLaubAI·
Real example from the paper: Complex word problem about calculating total distance with multiple variables. CoT: Linear walkthrough, compounds errors AoT: Isolates speed calculation, time calculation, distance formula separately When one atom fails, it doesn't break the entire chain.
Chris Laub tweet media
English
2
1
11
2.5K
Chris Laub
Chris Laub@ChrisLaubAI·
Chain of Thought is dead. I just tested Atom of Thought prompting and it's making AI models 30-40% more accurate on complex reasoning tasks. Here's the technique that's about to change how everyone uses ChatGPT and Claude:
Chris Laub tweet media
English
29
63
378
41K
Erlend Oftedal
Erlend Oftedal@webtonull·
What do you call unexpected vibe code written by accidentally clicking the link above a TODO in VSCode? (asking for a friend 😬) Wild code? Shadow vibes? Schrödinger's code because you don't know it's there until you look? Spanish inquisition code because it wasn't expected?
English
0
0
0
247
Erlend Oftedal retweetet
Erlend Oftedal
Erlend Oftedal@webtonull·
A DBA walks into a NOSQL bar, but turns and leaves because he couldn't find a table
English
15
776
90
0
Erlend Oftedal
Erlend Oftedal@webtonull·
@taviso Best of luck with the new gig. Hope we continue to see the same awesome research 👍
English
0
0
0
718
Tavis Ormandy
Tavis Ormandy@taviso·
A personal update... after nearly 20 years at Google, today is my last day! I'm going to be working on independent research for the foreseeable future, then who knows! I've worked with so many talented people, made so many friends and seen incredible research over the years 🫡
English
115
87
2.2K
198.8K
FotMob
FotMob@FotMob·
🇳🇴🔟 Still drinking it in… Erling Haaland beat the current FotMob algorithm to record our fifth perfect 10.0 rating in the men’s game (competitive fixtures only). And it takes Norway a step closer to a World Cup return.
FotMob tweet media
English
12
81
1.4K
54.7K
xssdoctor
xssdoctor@xssdoctor·
In my scenario, I had xss but i needed to import a js file to escalate. The csp was tight, but i was able to upload pdfs to the same domain. I uploaded a pdf with my malicious js in it, and I was off to the races. Enjoy!
English
4
1
79
7.5K
xssdoctor
xssdoctor@xssdoctor·
I just found the coolest csp bypass ever! did you know that a valid pdf can ALSO be valid javascript? (details below)
English
11
122
779
59.7K
JS0N Haddix
JS0N Haddix@Jhaddix·
I'm at the cutting edge of AI-assisted pentesting. Would anyone be interested in a webinar on where we sit and some of the false promises I've heard on the RSA floor?
English
92
25
428
26.7K
Erlend Oftedal retweetet
Ryan Chenkie
Ryan Chenkie@ryanchenkie·
⚠️ Developers, please be careful when installing Homebrew. Google is serving sponsored links to a Homebrew site clone that has a cURL command to malware. The URL for this site is one letter different than the official site.
Ryan Chenkie tweet mediaRyan Chenkie tweet media
English
245
2.5K
11K
1.4M
Erlend Oftedal
Erlend Oftedal@webtonull·
@SpotifyCares It's no longer possible to remove/mute songs on Discover Weekly. Please bring this back. I appreciate the suggestions, but some of them are not so good (wrong language, wrong style, unwanted lyrics)
English
1
0
0
23