Behlül ⛧

217 posts

Behlül ⛧ banner
Behlül ⛧

Behlül ⛧

@b3hlulll

web app security, alive for good vibes~

Remote Katılım Nisan 2012
410 Takip Edilen844 Takipçiler
Behlül ⛧ retweetledi
Joe Desimone
Joe Desimone@dez_·
Cobbled together a supply chain monitoring system last week: Cursor+Composer-2-fast harness on live package diffs (pypi+npm). Simple! Received a slack alert within minutes of Axios compromise. Reported to the devs after triple checking, because at first I could not believe it!
Joe Desimone tweet mediaJoe Desimone tweet media
English
12
52
376
34K
Behlül ⛧ retweetledi
Cloudflare
Cloudflare@Cloudflare·
We’re introducing Dynamic Workers, which allow you to execute AI-generated code in secure, lightweight isolates. This approach is 100 times faster than traditional containers. cfl.re/4c2NvPl
English
130
361
3K
1.4M
Behlül ⛧ retweetledi
Claude
Claude@claudeai·
Introducing Code Review, a new feature for Claude Code. When a PR opens, Claude dispatches a team of agents to hunt for bugs.
English
2.1K
5.1K
62.6K
23.5M
Behlül ⛧ retweetledi
Joe Desimone
Joe Desimone@dez_·
Patch Diff to SYSTEM - using LLMs to exploit a LPE vuln on Windows. More importantly, some thoughts on model capabilities the implications on our security industry elastic.co/security-labs/…
Joe Desimone tweet media
English
3
75
263
22.1K
Behlül ⛧ retweetledi
Haifei Li
Haifei Li@HaifeiLi·
Re: AI finding bugs.. Folks used to use CPUs to run fuzzers to find bugs, now they use GPUs to run models to find bugs. It’s essentially another way of fuzzing. A verifying process is built upon the nondeterministic output by fuzzer or AI. But there’re some differences: An individual researcher can do fuzzing at home and find serious bugs - I’ve been doing it for long time, the ROI is very good if you “fuzzing it right”. Now serious AI bug finding seems can only be performed by resource-rich companies.. What’s the ROI of AI bug findings? Can it be improved in future eg. the ROI can be very good if you “prompting it right”, or when “the model is good enough and using it is cheap enough”?
English
8
7
139
20.9K
Behlül ⛧ retweetledi
staysaasy
staysaasy@staysaasy·
My new favorite insult is calling someone’s job a Claude skill.
English
221
1K
14.4K
647.1K
Behlül ⛧ retweetledi
alli
alli@sonofalli·
anthropic vs openai is like kendrick vs drake but for nerds
English
190
846
8.9K
278.1K
Behlül ⛧ retweetledi
Security Bug Aggregator
Security Bug Aggregator@BugsAggregator·
[453094710][reward: $250000] Out-of-bound read in the jmp table of ActiveMediaSessionController leads to sandbox escape. crbug.com/453094710
English
9
89
653
283.9K
Behlül ⛧ retweetledi
Adem Kanat
Adem Kanat@ADEMKANATT·
Her hafta hem içerik kalitesini hem de çekim ve prodüksiyon süreçlerini adım adım daha iyi hale getiriyoruz. Bu hafta 3. bölümünü paylaşıyor olacağız. Takip ederek bölümleri kaçırmamanızı tavsiye ederim. 🎧 Spotify: open.spotify.com/episode/5KSOio… 📺 YouTube: youtube.com/watch?v=ePghH7…
YouTube video
YouTube
Kayhan Kayıhan@kayhankayihan

🎥 Yeni Video Serisi Başladı! | 2026’da Siber Güvenlik Bizi Neler Bekliyor? @cyberfellow_org @ADEMKANATT ile birlikte keyifli ve bol içgörülü bir video serisine başladık. 2026 yılında siber güvenlik dünyasında bizi nelerin beklediğini konuştuk. youtu.be/ePghH79hGw4?si…

Türkçe
0
3
6
1.7K
Behlül ⛧ retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Hacktron Research is leading in @vercel react2shell WAF challenge with $150,000 in bounties. This is the shit that keeps me up. building @HacktronAI to bring the best of hackers and AI together, and to be in the loop when hacks like this happen or find before they happen. your goodhart's-law-optimized “completely autonomous AI pentester” isn’t doing this shit. it's too busy selling snake oil.
s1r1us (mohan) tweet media
English
8
12
195
22.6K
Behlül ⛧ retweetledi
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
94
102
1.8K
54.2K