Shift
17.6K posts


@Shiftreduce @mboehme_ Hmm, the one I was working on was an alive2/LLVM based pipeline and it was pretty nice
English

i have a research set i build mostly from vibes right here
1. induct-research - reads, summarizes on a 15 point template
2. bilbilo and cite forward and back ref
3. 4 different indices updated
At any time i can ask for something and have it quickly checked against the growing corpus and the internet. If anything new is found in the process I hoover it up.
This process is very good at making slop into real work.
English

We live in interesting times.
Last month Linux patched a core uaf in the epoll subsystem, we rarely see these kind of bugs.
As i like these kind of bugs, i wrote a few words about it here: guysrd.github.io
English

One thing I’ve always found interesting about vulnerability research, is how it seems to almost always be very age-bounded.
You will meet the occasional 15 year old all-star. But usually it takes several years of serious experience to reach Jedi levels.
But you almost never meet a 50 year old who still churning out bugs day to day. People “age out” for a lot of difference reasons.
English

Running FastAPI or another python ASGI framework? Then patch Starlette now, chances are high it's in your supply chain! A host header parsing issue can lead to vulnerabilities leading from auth bypass up until RCE! Examples for affected packages are liteLLM, vllm, etc... Here is the X41 Advisory:
x41-dsec.de/lab/advisories…
English

im celebrating the release of the new openbsd
but the usb rndis driver, extremely fragile!
if someone walks up to your OpenBSD 7.9 thinkpad in starbucks tomorrow and tries to plug in a suspicious usb device into your daily driver whilst yelling "please run `ifconfig urndis0 up` as soon as possible! this is a matter of life and death!" don't fall for it, you've been warned.

OpenBSD@openbsd
OpenBSD 7.9 is out now! See what's new here: openbsd.org/79.html
English
Shift retweetledi

since I saw this post, I’ve been planning to tweet this
Shift@Shiftreduce
pwn2collision? my bet everyone is sitting on the similar bugs unless they have a local model.
English

It’s time to reveal our secret AI model which we’ve been using for years even back when the ChatGPT wasn’t a thing.
Let me introduce you the top-secret model trained in Taiwan, It’s security-focused, fully automated, requires no prompting, and is ready to use out of the box.
That is: OrangetsAI !
TrendAI Zero Day Initiative@thezdi
That's a wrap on Pwn2Own Berlin 2026! 🏆 $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own #P2OBerlin
English



