depthfirst

54 posts

depthfirst banner
depthfirst

depthfirst

@depthfirstlabs

Autonomous Security From Design To Production

San Francisco Katılım Nisan 2025
25 Takip Edilen406 Takipçiler
Hamid Kashfi
Hamid Kashfi@hkashfi·
Still "Lab", but working fully remotely without any hardcoded offsets, bypassing ASLR on standard Ubuntu + Nginx deployment via an LFI primitive. There's still lots of room for improvement but I'm already out of tea and who cares? Just patch.
English
3
9
80
7.6K
depthfirst retweetledi
depthfirst retweetledi
Dino A. Dai Zovi
Dino A. Dai Zovi@dinodaizovi·
Because regex-triggered vulnerabilities depend on the specific regex input, they are especially difficult for static analyzers (and humans) to find. This is impressive.
Zhenpeng (Leo) Lin@Markak_

NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at depthfirst.com/nginx-rift

English
0
7
26
5.8K
depthfirst retweetledi
Zhenpeng (Leo) Lin
Zhenpeng (Leo) Lin@Markak_·
Using the same system, we found NGINX RCE, Linux LPE, Chrome RCE, FFmpeg RCE and a lot of other critical Vulnerabilities, feel free to try it out! We are trying our best to help secure OSS!
QM@qasimmith

Today we're launching the Open Defense Initiative: up to $5 million in @depthfirstlabs credits for critical open source projects to find and fix real, exploitable vulnerabilities. The timing matters: frontier models can autonomously discover and exploit vulnerabilities in widely-reviewed codebases. Open source models will catch up soon, and when they do, bad actors will have unfiltered access to these capabilities. We have a narrow window to harden critical software before that happens. This is the time to act, but until today frontier-level security, like what Mythos offers, has been reserved for a handful of large companies who are required to pay a lot for access. depthfirst is not only comparable in performance but also goes significantly beyond surface level findings, highlighting real, exploitable vulnerabilities due to its understanding of the system’s context and ability to verify like an attacker would. depthfirst found vulnerabilities in FFmpeg that Mythos missed, at a tenth of Anthropic's self reported spend. We want every defender to have these capabilities, starting with the open source projects the world runs on. If you maintain a critical open source project, apply for Open Defense credits through the form in the comments.

English
0
11
72
11.8K
depthfirst
depthfirst@depthfirstlabs·
depthfirst autonomously discovered, verified, and generated a patch for NGINX rift, an 18 year old heap overflow (CVSS 9.2). It leads to an RCE and is affecting most of the global web traffic. Follow the link in the comments to learn more.
Zhenpeng (Leo) Lin@Markak_

NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at depthfirst.com/nginx-rift

English
2
2
7
2.6K
depthfirst
depthfirst@depthfirstlabs·
@nginx powers a large portion of global web traffic, and is used by major companies to run and secure their web services. This code had been there for 18 years and run countless times before we found the vulnerability.
Andrea Michi@andreamichi

@depthfirstlabs found a critical vulnerability in @nginx leading to RCE (CVE-2026-42945, CVSS 9.2). We recommend patching to 1.30.1 or 1.31.0 as as possible. Securing the world software is depthfirst mission and NGINX is one of the most widely deployed web server in the world

English
0
0
3
214
depthfirst
depthfirst@depthfirstlabs·
@andreamichi Working on security has never been more important than now 🫡
English
0
0
1
81
depthfirst retweetledi
Andrea Michi
Andrea Michi@andreamichi·
This week @depthfirstlabs introduced dfs-mini1, a security model trained via Reinforcement Learning to detect vulnerabilities in smart contracts. The model achieves pareto optimality on OpenAI’s EVMBench Detect and SOTA at pass@8 beating frontier models at a fraction of the cost
Andrea Michi tweet media
English
7
13
40
7.6K
depthfirst retweetledi
Forerunner
Forerunner@ForerunnerVC·
We're backing @depthfirstlabs in their $80M series B, announced today. depthfirst is building the essential layer for trust and safety in this technology shift, founded by a crew of former Faire, DeepMind, and Databricks leaders: depthfirst.com/post/series-b-…
English
1
2
9
1.2K
depthfirst
depthfirst@depthfirstlabs·
@kirstenagreen Thank you Kirsten, we are so grateful for your and Forerunner's trust!
English
1
0
3
48
depthfirst retweetledi
Kirsten Green
Kirsten Green@kirstenagreen·
We're proud investors in @depthfirstlabs's series B! From working with depthfirst's cofounder when he cofounded Faire, to getting to know the rest of the depthfirst team, I’ve built tremendous respect for how they're approaching the market.
Andrea Michi@andreamichi

depthfirst has raised an $80M Series B at a $580M valuation. Attackers are using AI to break into systems faster than ever before. depthfirst is on a mission to stop this. RT + Comment “depthfirst” and I’ll send you a FREE vibe coding security agent.

English
3
2
29
5.5K
depthfirst
depthfirst@depthfirstlabs·
@arshammem Thank you Arsham, we're so excited to have you on board!
English
0
0
1
21
depthfirst retweetledi
QM
QM@qasimmith·
This is an insane vulnerability found entirely by @depthfirstlabs low level agent. I'm so glad that exceptional security researchers like @Markak_ are working on improving these agents to help defenders.
Zhenpeng (Leo) Lin@Markak_

Our agent autonomously found this kernel 0day and its exploit works on the #KCTF target. We are building to find vulnerabilities systematically, not just shadow bugs. See the quoted post below—comment "depthfirst" and we'll send you a free agent to try out.

English
0
1
7
525