Ofri Ziv

226 posts

Ofri Ziv

Ofri Ziv

@OfriZiv

Katılım Temmuz 2016
156 Takip Edilen283 Takipçiler
Ofri Ziv retweetledi
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑
Who needs a real, genuine, in depth pen test, with results next week? If anyone was hurt by Delve’s operations, we are here to help. Ping me.. We will help.
English
0
8
19
1.2K
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
Just in ⚡️: Most AI security claims are based on demos or bug bounties. We tested ours differently: CTF competitions designed for human hackers. Result: Top 1% 🔝 → better than 125,000+ participants 🤯 Still behind the very best humans. But now: elite offensive capability can run on demand, at scale. Get the findings: blog.tenzai.com/tenzais-ai-hac… Read @Forbes' take: forbes.com/sites/thomasbr…
Tenzai tweet media
English
0
7
17
1K
Ofri Ziv retweetledi
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑
We evaluated @Tenzai_Labs AI hacker across six major CTF competitions designed for humans. Result: Top 1% performance, outperforming 125,000+ human hackers across different domains - web hacking, ai hacking, low level system hacking. We wanted to see what @Tenzai_Labs's hacking agent is really capable of in the most complicated and competitive environments, where to excel, one needs to solve increasingly difficult challenges. The results we achieved surprised even me. This is incredible evidence of what AI agents with the right harness can do and I expect it to only get better from now. blog.tenzai.com/tenzais-ai-hac…
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑 tweet media
English
4
19
87
21.1K
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
Claude adds code security. They say, “Security solved.” Meanwhile in prod: ‼️ Enterprise services trust consumer services ‼️ Over-permissive IAM ‼️ Someone forgot to enable the captcha You can read code You can’t read reality Get it: blog.tenzai.com/test-in-prod-o…
Tenzai tweet media
English
0
2
9
1.3K
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
What a week for AI! But also: what a week for cracked human hackers! ⚡️ Our community met up - in person (!) - to hear from the rarest of talent, share notes, and try to guess who's who on the CTF leaderboards 🕵️‍♂️ Another @Tenzai_Labs meetup, wrapped. @oridavid123 @OfriZiv @ace__pace
Tenzai tweet mediaTenzai tweet media
English
0
2
5
227
Ofri Ziv retweetledi
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑
✳️New @Tenzai_Labs Research✳️ As coding agents and vibe coding go mainstream, one question keeps coming up: how secure is the code these agents actually generate? And more importantly, which agent is the most secure? To find out, @oridavid123 put @Cursor_ai, @OpenAI's Codex, @AnthropicAI's Claude Code, Cognition's @DevinAI and @Replit head-to-head in a test. Each was tasked with building the same applications using a set of identical prompts. We then unleashed Tenzai’s hacking agent on the vibe-coded apps to uncover vulnerabilities and compare which of the agents performed best. The verdict? There are no winners. 👇blog.tenzai.com/bad-vibes-comp…
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑 tweet media
English
2
5
19
981
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
Hey you! If *our manifesto* gets your heart racing and your mind lit up - if you want to build systems that reason, break, and adapt in real time - we want to work with you. We’re hiring engineers + researchers + hackers in 📍 Tel Aviv who care about rigor, ownership, and doing hard things well, with a willingness to question existing assumptions: #joinus" target="_blank" rel="nofollow noopener">tenzai.com/#joinus We're out of stealth and building #AI #hackers in the open, systems that actively explore, reason about, and break real, evolving software. This is deep, hands-on work on complex systems, where #security, AI, and modern software meet.
English
2
5
12
963
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
The @NYSE floor just got 🔥! A thrill to see @Tenzai_Labs ✳️ lighting up the trading floor, and much gratitude to the team over at the @NYSE for this fun shoutout - a record-breaking seed round is really just the beginning! Let's go AI hackers!
Tenzai tweet mediaTenzai tweet mediaTenzai tweet media
English
0
5
19
7.9K
Ofri Ziv retweetledi
Tenzai
Tenzai@Tenzai_Labs·
First event right out of the gate: meetup with hundreds of hackers from the !BS community, for researchers by researchers. No buzzwords, no sales pitches, zero bullshit. Only fitting we send @ace__pace to the front line to share skepticism (+ enthusiasm!) around agentic hacking🤡
Tenzai tweet media
English
0
6
13
746
Ofri Ziv retweetledi
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑
I got into hacking when I was in high school. It was mostly curiosity - understanding how systems are designed, how they’re implemented, what their limitations are, and how to break them. Then, I started working as a pentester. It was both a challenge and a joy (plus I was getting paid for it!). That same curiosity still drives the best pentesters and hackers in the world. They’re incredibly rare - part scientist, part artist - and their craft keeps the digital world honest, finding what’s broken before attackers do. But mastery doesn’t scale. Software today changes by the hour. AI now writes and ships code faster than any human team can test it. That’s why we built @Tenzai_Labs , an AI based hacker for the right side. Our platform uses autonomous, agentic AI to continuously hack, test, exploit, and help fix vulnerabilities across enterprise software, at the speed of AI. Together with my long-time friends and colleagues, plus a bunch of new brilliant minds, we're tackling this head on. There's no bigger privilege than working alongside people with such talent, grit, and determination. Going after such a world-changing problem was an opportunity I just could not resist. So, here I am, back in the startup grind again 🙂 Read our manifesto here - #manifesto" target="_blank" rel="nofollow noopener">tenzai.com/#manifesto
English
11
20
63
56.8K
Ofri Ziv retweetledi
Ace Pace
Ace Pace@ace__pace·
Enterprise applications are complex, obscure, and mostly crap. Legacy code, modern wrappers around legacy… There’s sometimes a mainframe hiding somewhere. Today’s pen tests just scratch the surface
English
2
1
7
1K
Ofri Ziv retweetledi
Chris Wysopal
Chris Wysopal@WeldPond·
Over the last 2 yrs LLMs have vastly improved their ability to write syntactically correct code, but they haven’t improved in ability to write code without vulnerabilities which is steady at 45% coding tasks with vulns.
Chris Wysopal tweet media
English
15
39
124
19.6K
Ofri Ziv retweetledi
Akamai Security Intelligence Group
Akamai Security Intelligence Group@akamai_research·
Since 2023, 12 security vulnerabilities were discovered in Kubernetes. 4 of those were identified by our very own @TomerPeled92. Ready for another one? This one is in Log Query and can achieve RCE with SYSTEM privileges on all endpoints in the cluster. akamai.com/blog/security-…
Akamai Security Intelligence Group tweet media
English
4
9
19
2.3K
Ofri Ziv retweetledi
Akamai Security Intelligence Group
Akamai Security Intelligence Group@akamai_research·
Turns out, sometimes it isn't DNS... it's DHCP 👀 See @oridavid123's research on how DHCP can be used to spoof DNS records- potentially leading to Active Directory compromise. Worst part? No credentials needed, just network access. Full write-up: akamai.com/blog/security-…
Akamai Security Intelligence Group tweet media
English
3
101
282
39.8K
Ofri Ziv retweetledi
Ophir Harpaz 🎗️
Ophir Harpaz 🎗️@OphirHarpaz·
Our team looked at all CVEs and pointed out some of the critical/interesting ones. We'll update this post as we go on with our research and patch-diffing, so stay tuned.
Akamai Security Intelligence Group@akamai_research

What you need to know about Patch Tuesday, all in one place. Akamai researchers have analyzed this month's patch and pulled together all the insights: what to focus on and why. akamai.com/blog/security/…

English
0
5
12
0
Ofri Ziv retweetledi
Hexacon
Hexacon@hexacon_fr·
🗿 Exploring ancient ruins to find modern bugs: Discovering a 0-day in MS-RPC service, by Ophir Harpaz (@OphirHarpaz) and Stiv Kupchik (@kupsul)
Hexacon tweet media
English
0
9
33
0