b33f | 🇺🇦✊

10.5K posts

b33f | 🇺🇦✊ banner
b33f | 🇺🇦✊

b33f | 🇺🇦✊

@FuzzySec

意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs

Jumanji Katılım Nisan 2012
1.3K Takip Edilen33.2K Takipçiler
b33f | 🇺🇦✊ retweetledi
Off-By-One Conference
Off-By-One Conference@offbyoneconf·
Dr. Edward (@edwardzpeng) has locked in his keynote details for @offbyoneconf! He shares hands-on lessons from AI-augmented offensive security projects and discuss how traditional researchers must adapt to this fast-shifting landscape. More info: offbyone.sg/talk/edwardzpe…
Off-By-One Conference@offbyoneconf

AI & security research moves incredibly fast. That’s why our next keynote speaker, Dr. Edward Zhiniang Peng (@edwardzpeng), is locking his abstract and title later. This ensures the freshest developments! More info: offbyone.sg/talk/edwardzpe… #OB12026 #CyberSecurity #AISecurity

English
0
6
17
4.3K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
@dyn___ I will say, most of the power is in the harness (I assume that is true for any real target also), giving the model the tools it needs to explore, iterate and test efficiently. Especially the memory oracle. But I need some more banked resets before I can continue work on it 😅
English
1
0
1
47
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
Round 2, fight! GPT5.6 chains together an impressive set of techniques to gain ACE and uses that to render a Mortal Kombat logo in-game. End-to-end the model took 30-40 minutes to produce and validate the full chain. I assume we achieve SOTA here in Pokemon Red exploitation 👻
b33f | 🇺🇦✊ tweet media
b33f | 🇺🇦✊@FuzzySec

Do you even pokemon bro? I'm doing some harness/benchmark development, here GPT5.6 finds a short path to trigger a deterministic invalid-species fallback in pokemon red using a WRAM type confusion -> integer underflow -> pokedex oob r/w 🕶️

English
3
5
68
9.4K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
@dyn___ I have three categories in the harness: - Playing the game (testing long-horizon) - Repro known glitches - Bug hunt Overall I think these are pretty good for general evaluation but the harness still needs work to be fully ready.
English
1
0
1
122
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
The model also demonstrated other objectives, like it is able to crash the emulator (MBC3 banking) using only valid game state and inputs, theoretically it could then escape but this would require a lot more work. Eventually it may be good to do some write-ups on pokemon primitives and exploit chains. I imagine the speedrunning and TAS community must be going through a golden age.
English
1
0
2
590
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
It may also be interesting to understand how the model spent that time as a breakdown. Note that my benchmark has independent components which place restrictions on the model and are validated at runtime by a memory oracle.
b33f | 🇺🇦✊ tweet media
English
1
0
3
717
b33f | 🇺🇦✊ retweetledi
hashkitten
hashkitten@hash_kitten·
Seems that wp2shell PoCs are now floating around the internet, so we've published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself - slcyber.io/research-cente…
English
15
183
642
56.9K
b33f | 🇺🇦✊ retweetledi
Rodrigo Branco
Rodrigo Branco@bsdaemon·
Our team (Platform Security Engineering) at @AnthropicAI is hiring for a few different positions/responsibilities: Offensive (job-boards.greenhouse.io/anthropic/jobs…), Architecture (job-boards.greenhouse.io/anthropic/jobs…), OS Kernel (job-boards.greenhouse.io/anthropic/jobs…) and BMC (job-boards.greenhouse.io/anthropic/jobs…). Come join @matrosov , myself and other awesome folks. Reach out if you have questions.
English
3
31
166
18K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
@sundhaug92 Yes an no, it applied a limited pallet to the four grayscale shades, pokered-gbc recompiles the game as a native GBC ROM and assigns real CGB palettes to everything.
English
0
0
0
32
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
Do you even pokemon bro? I'm doing some harness/benchmark development, here GPT5.6 finds a short path to trigger a deterministic invalid-species fallback in pokemon red using a WRAM type confusion -> integer underflow -> pokedex oob r/w 🕶️
b33f | 🇺🇦✊ tweet media
English
4
7
96
20.1K
Tibo
Tibo@thsottiaux·
What are you building this weekend?
English
2.6K
63
3.3K
533.5K
b33f | 🇺🇦✊ retweetledi
AI Security Institute
AI Security Institute@AISecurityInst·
Our first public analysis of the open/closed weight gap in frontier cyber capabilities finds it is 4–7 months with GLM-5.2 and DeepSeek V4-Pro, narrowing from 6–10 months through most of 2025. Advanced capabilities are reaching less safeguarded open models faster than before. 🧵
AI Security Institute tweet media
English
11
56
238
66.4K
b33f | 🇺🇦✊ retweetledi
Calif
Calif@calif_io·
In case you missed it, the recording is up: youtube.com/watch?v=maWnIK… @5aelo Thank you so much! We'll name one of our chains after you.
YouTube video
YouTube
English
0
31
108
18.7K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
This thread is one of the largest signs that we in fact do need to push forward with a collective middle powers strategy and that it is already causing concern. Also, UA arms sales in the Middle East during IR conflict show there is obvious pressure on US defense industry.
Under Secretary of War Elbridge Colby@USWPColby

There is a great deal of hubbub about a collective “middle powers”strategy these days. At DoW, we are not concerned that this is a serious possibility. Rather, we are more concerned that a few allies and partners will *think it is* and waste valuable time, money, and political capital on a distraction. 1/

English
0
0
3
1.6K
b33f | 🇺🇦✊ retweetledi
stratan
stratan@5tratan·
What The Claude, episode 3. We're taking a break from content-process RCEs for Bug 2022034. A raw NaN. Typed JS actor IPC. A parent-process fake object. An XUL leak. Code execution outside the sandbox. NaN around and find out. github.com/str8outtaheap/…
English
1
14
62
12.4K