Toan Pham

121 posts

Toan Pham

Toan Pham

@__suto

Cybersecurity Engineer | Qrious Secure (@qriousec) & VnSecurity (@vnsec) | First guy pwned v8ctf with 0day | Enterprise Security by Day, Bug finding by Random.

Katılım Ağustos 2009
815 Takip Edilen2.5K Takipçiler
loknop
loknop@loknop·
@__suto that hash might be OpenAI and they want to announce it in a blogpost themselves?
English
0
0
0
330
Toan Pham
Toan Pham@__suto·
@yz9yt yes i said 9 by c6eed09, 26 is total
English
0
0
1
27
Toan Pham
Toan Pham@__suto·
@Fried_rice yes he seems went there first 🤣 saw your duplicate! anw, great job!
English
0
0
8
1.7K
Chaofan Shou
Chaofan Shou@Fried_rice·
@__suto I’m not c6eed09fc8b174b0f3eebedcceb1e792 🤣
Eesti
1
0
10
2.4K
Toan Pham
Toan Pham@__suto·
@S1r1u5_ i know some folks, basically you can show to people you want when needed
English
0
0
2
45
Toan Pham
Toan Pham@__suto·
@S1r1u5_ if stealth they might just demo rce 0day instead?
English
1
0
1
75
Toan Pham
Toan Pham@__suto·
Yes, the goal is common, but the outcome is slightly different, in my opinion. And I would bet/hope on your point about context engineering and expertise still matter; otherwise, all the power would be in the hands of the foundation companies and i personally dont like that outcome!
English
0
0
3
147
Tim Becker
Tim Becker@tjbecker·
@__suto In my view, we all have a common goal: leverage LLMs to find high impact bugs. The model capabilities definitely matter, but context engineering and analysis techniques are huge levers!
English
1
0
3
229
Toan Pham
Toan Pham@__suto·
So it turned out that was Anthropic—no wonder it uncovered so many vulnerabilities across multiple components! The bar has been raised higher than ever. Let’s see if BigSleep or Codex can surpass this :) anthropic.com/news/mozilla-f…
Toan Pham@__suto

Someone new ( has never submitted before ) has made a strike with 22 bugs across firefox components ( about 6 in js ) in total more than 50! Look like they invented something cool. at the sametime 0 js bug in v8: chromereleases.googleblog.com/2026/02/stable…

English
2
8
67
12.8K
Toan Pham
Toan Pham@__suto·
I bet Xint would get a lot more attention if there were a 0-click kernel RCE pixel drop. For the “Surpass” thing, I’m more curious about teams with unlimited access to foundation unfiltered raw models performing vulnerability hunting than about others like Xint Code or Xbow—or solo players like me.
English
1
0
5
440
Toan Pham
Toan Pham@__suto·
The important thing is that these AI systems ( I hope ) are good enough to prevent massive, silly bugs in IoT and infrastructure that nobody has the time or excitement to look at, except when they are shown at events like Pwn2Own, where one router, printer, or camera can have tons of duplicate 0day has been there for years.
English
0
0
12
1.7K