Sabitlenmiş Tweet
Ivan at Wallarm / API security solution
10.5K posts

Ivan at Wallarm / API security solution
@d0znpp
SSRF bible author; Bug Hunter (Google/Facebook/Twitter/Yandex/Tesla); Masters in Physics, MSU / quantum magnetism; CEO at @Wallarm
Austin, TX Katılım Nisan 2010
1.4K Takip Edilen6.7K Takipçiler
Ivan at Wallarm / API security solution retweetledi
Ivan at Wallarm / API security solution retweetledi

Thank you Jensen and NVIDIA! She’s a real beauty! I was told I’d be getting a secret gift, with a hint that it requires 20 amps. (So I knew it had to be good). She’ll make for a beautiful, spacious home for my Dobby the House Elf claw, among lots of other tinkering, thank you!!
NVIDIA AI Developer@NVIDIAAIDev
🙌 Andrej Karpathy’s lab has received the first DGX Station GB300 -- a Dell Pro Max with GB300. 💚 We can't wait to see what you’ll create @karpathy! 🔗 #dgx-station" target="_blank" rel="nofollow noopener">blogs.nvidia.com/blog/gtc-2026-…
@DellTech English
Ivan at Wallarm / API security solution retweetledi

🦞 Make claw agents safer with our new NVIDIA OpenShell – an open source runtime to build with autonomous evolving agents.
🐚 OpenShell sits between your agent and your infrastructure to govern how the agent executes, what the agent can see and do, and where inference goes.
🔐 Gives you fine-grained control over your privacy and security while letting you benefit from the agents’ productivity.
Run one command—and make zero code changes. Then any claw or coding agent like OpenClaw, Anthropic’s Claude Code, or OpenAI’s Codex can run unmodified inside OpenShell.
Every SaaS company just became an agent company. The missing piece was never the agents — it was the infrastructure that makes them safe enough to deploy. That's OpenShell.
Technical blog to learn more ➡️ nvda.ws/4brnAPW

English
Ivan at Wallarm / API security solution retweetledi

Just found a simple Cloudflare WAF bypass 👀
<img src=x onerror=alert()> → blocked by Cloudflare
<Img Src=OnXSS OnError=alert(document.domain)> → bypasses the WAF and triggers the alert.
#BugBounty #BugBountyTips #WAFBypass

English
Ivan at Wallarm / API security solution retweetledi
Ivan at Wallarm / API security solution retweetledi

NVIDIA to get into agentic bots battle
nemoclaw.bot
English

Andrej Karpathy just published a GitHub repo that hints at self-evolving software.
It’s called autoresearch.
And the idea feels like evolution applied to research.
Instead of humans manually running experiments, an AI runs a continuous loop:
mutation → AI edits the code
selection → run experiment
fitness → measure performance
survival → keep improvements
repeat
Each experiment becomes a generation.
Bad mutations disappear.
Good ones survive.
The system slowly evolves better models.
The crazy part — the repo is almost empty:
prepare.py
train.py
program.md
You don’t write the research code anymore.
You write the goal.
Inside program.md you describe what the system should optimize:
reduce validation loss
try architecture tweaks
test new hyperparameters
keep improvements
Then the agent runs experiments automatically.
While you sleep.
Nature needed millions of years to evolve complex systems.
AI can run thousands of generations overnight.
One researcher.
Thousands of experiments.
Continuous evolution.
Code:
github.com/karpathy/autor…
English
Ivan at Wallarm / API security solution retweetledi

If you’re into AI and agents and such, I released something I think is currently sorely missing - institutional memory that your agents can access you might find this useful github.com/l33tdawg/sage/
English
Ivan at Wallarm / API security solution retweetledi

Today we are introducing a Python SDK for Mac's on-device LLM! github.com/apple/python-a… apple.github.io/python-apple-f…
English
Ivan at Wallarm / API security solution retweetledi

Over the CNY holidays, I decided to build something that imho is 'peak agentic AI' 🤣 - the world's first self-evolving CTF platform! AI agents design, validate, calibrate, and evolve security challenges autonomously.
levelupctf.com
Here's the full story 🧵
English
Ivan at Wallarm / API security solution retweetledi

PAN-OS flaw CVE-2026-0229 allows unauthenticated attackers to trigger reboot loops & maintenance mode via malicious packets. Patch immediately.
#PaloAltoNetworks #PANOS #CyberSecurity #CVE20260229 #NetworkSecurity #InfoSec #Firewall
securityonline.info/crash-loop-pal…
English
Ivan at Wallarm / API security solution retweetledi

Vulnerability Summary:
Endpoint: GET /rest/v1/contacts
Severity: CRITICAL (9.8 CVSS)
Weakness: CWE-284 - Improper Access Control
Impact: ANY authenticated user can view ALL contact form submissions #BugBounty #PII

English
Ivan at Wallarm / API security solution retweetledi
Ivan at Wallarm / API security solution retweetledi

👼GatewayToHeaven (CVE-2025-13292).
I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users).
Below is the full breakdown of the exploit chain⛓️


English
Ivan at Wallarm / API security solution retweetledi
Ivan at Wallarm / API security solution retweetledi










