Asjid Kalam
285 posts

Asjid Kalam retuiteado

As far as we can tell, no. There is only anecdotal evidence, along with claims from AI pentesting vendors.
If a strong model can do everything by itself, then what exactly have these vendors been building? It is understandable that people would prefer a story in which the harness, workflow, and surrounding infra matter a great deal. It's also why people keep flexing "0-days" in OpenSSL, FFmpeg, or nginx, despite limited real-world impact.
That said, Niels Provos was not trying to sell anything, and he and several people have reported good results with IronCurtain despite using relatively weak models.
Most importantly, what Google achieved with Chrome suggests that a good harness may be quite valuable. Google does not appear to have access to anything more capable than Mythos, which means they likely scanned Chrome using Mythos itself or something less powerful. Yet they still uncovered hundreds of bugs.
There is, however, another explanation. Google may simply have better Chrome/V8 experts who can extract more value from Mythos. This remains our preferred hypothesis.
What provides a real advantage: domain knowledge accumulated over many years, or a harness vibe-coded in an afternoon? We think the answer is fairly obvious.
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦@yo_yo_yo_jbo
@calif_io Are there public measurements of how much improvement good harness offers?
English
Asjid Kalam retuiteado

Pwning V8CTF with a 0day in Chrome thanks to Phi untagging.
Read here: kqx.io/post/cve-2026-…

English

@0xdef1ant same, its been stuck in the same status for over a month now
English
Asjid Kalam retuiteado

@dyn___ @orange_8361 @thezdi I like to think v8.dev/blog/sandbox and other efforts have something to do with it, but hard to tell :) docs.google.com/document/d/1nj… has also been trending downwards lately but it’s a very sparse signal
English


first linux kernel exploit. this one is fully found, chained and exploited by ai agents.
not KerneICTF LTS/COS-worthy (yet), since the relevant attack surface is disabled there now.

Asjid Kalam@odinshell
netlink OOB 👀👀 on linux 7.0.0-g27d128c1cff6
English

First cve in chromium, MiraclePtr is a real pain.
chromereleases.googleblog.com/2026/04/stable…

English
Asjid Kalam retuiteado
Asjid Kalam retuiteado
Asjid Kalam retuiteado
Asjid Kalam retuiteado












