Corben Leo

4.3K posts

Corben Leo banner
Corben Leo

Corben Leo

@hacker_

I hack stuff legally; co-founder @boringmattress

Brookings, South Dakota Katılım Şubat 2016
681 Takip Edilen71.9K Takipçiler
Sabitlenmiş Tweet
Corben Leo
Corben Leo@hacker_·
In 2010, WikiLeaks released a classified document. A list of infrastructure critical to U.S national security. The government listed a Trans-Atlantic cable. 3 years ago, 19-year-old me gained ADMIN access to that cable (and another; shared codebase). 🧵Here's how I found it
Corben Leo tweet media
English
90
950
4.9K
0
Sudo su
Sudo su@sudoingX·
how much VRAM do you have right now
English
158
5
87
11.1K
Corben Leo
Corben Leo@hacker_·
vibe hacking is so in
English
1
0
4
512
Corben Leo
Corben Leo@hacker_·
on a generational run this week & it doesn't even feel like i'm trying hard
Corben Leo tweet media
English
5
0
63
2.6K
Jon Barber 🤖
Jon Barber 🤖@BonJarber·
100M tokens with less than 9% accuracy degradation 👀👀
艾略特@elliotchen100

论文来了。名字叫 MSA,Memory Sparse Attention。 一句话说清楚它是什么: 让大模型原生拥有超长记忆。不是外挂检索,不是暴力扩窗口,而是把「记忆」直接长进了注意力机制里,端到端训练。 过去的方案为什么不行? RAG 的本质是「开卷考试」。模型自己不记东西,全靠现场翻笔记。翻得准不准要看检索质量,翻得快不快要看数据量。一旦信息分散在几十份文档里、需要跨文档推理,就抓瞎了。 线性注意力和 KV 缓存的本质是「压缩记忆」。记是记了,但越压越糊,长了就丢。 MSA 的思路完全不同: → 不压缩,不外挂,而是让模型学会「挑重点看」 核心是一种可扩展的稀疏注意力架构,复杂度是线性的。记忆量翻 10 倍,计算成本不会指数爆炸。 → 模型知道「这段记忆来自哪、什么时候的」 用了一种叫 document-wise RoPE 的位置编码,让模型天然理解文档边界和时间顺序。 → 碎片化的信息也能串起来推理 Memory Interleaving 机制,让模型能在散落各处的记忆片段之间做多跳推理。不是只找到一条相关记录,而是把线索串成链。 结果呢? · 从 16K 扩到 1 亿 token,精度衰减不到 9% · 4B 参数的 MSA 模型,在长上下文 benchmark 上打赢 235B 级别的顶级 RAG 系统 · 2 张 A800 就能跑 1 亿 token 推理。这不是实验室专属,这是创业公司买得起的成本。 说白了,以前的大模型是一个极度聪明但只有金鱼记忆的天才。MSA 想做的事情是,让它真正「记住」。 我们放 github 上了,算法的同学不容易,可以点颗星星支持一下。🌟👀🙏 github.com/EverMind-AI/MSA

English
3
0
4
798
Lydia Hallie ✨
Lydia Hallie ✨@lydiahallie·
if your skill depends on dynamic content, you can embed !`command` in your SKILL.md to inject shell output directly into the prompt Claude Code runs it when the skill is invoked and swaps the placeholder inline, the model only sees the result!
Lydia Hallie ✨ tweet media
English
126
240
2.9K
808.8K
Ed Zitron
Ed Zitron@edzitron·
I think we are really underestimating the genuine danger that is being created by using AI code in such an unrestricted and unmanageable way. I've heard recently that one hyperscaler is allowing non-coders to ship actual code (with engineers "overseeing"), seems very dangerous
Jessica Lessin@Jessicalessin

"A rogue AI agent recently triggered a major security alert at Meta Platforms, by taking action without approval that led to the exposure of sensitive company and user data to Meta employees who didn’t have authorization to access the data." @jyoti_mann1 theinformation.com/articles/insid…

English
18
130
1.1K
56.1K
Corben Leo
Corben Leo@hacker_·
@NebulaWiz @Fr3ki_ @chompie1337 I didn't word it great but Claude found an auth bypass by itself, which was a crit. by itself with what it gave access to. The RCE was a cherry on top (but it needed guidance)
English
1
0
0
94
Corben Leo
Corben Leo@hacker_·
CLAUDEEEE. My outlook on the future has dramatically shifted overnight. Wow.
Corben Leo tweet media
English
40
60
1.5K
212.2K
Corben Leo
Corben Leo@hacker_·
$THLLY's acquisition of Imperva couldn't have been timed any better
English
0
0
3
2.1K
Corben Leo
Corben Leo@hacker_·
@rez0__ Nah, pretty sure short(er)-lived agents is the correct architecture
English
1
0
1
1.3K
theseriousadult
theseriousadult@gallabytes·
this is the worst the technology will ever be at finding vulns. going to take a near-total overhaul of the software stack. defense beats offense in cyber but only if defense takes the magnitude of the task seriously enough for long enough.
Anthropic@AnthropicAI

We partnered with Mozilla to test Claude's ability to find security vulnerabilities in Firefox. Opus 4.6 found 22 vulnerabilities in just two weeks. Of these, 14 were high-severity, representing a fifth of all high-severity bugs Mozilla remediated in 2025.

English
5
10
102
8.2K
Corben Leo
Corben Leo@hacker_·
haha i was right
Corben Leo tweet media
English
1
2
17
5.3K
Corben Leo
Corben Leo@hacker_·
Just saw OpenAI symphony & I'm surprised this isn't already most ppl's workflow? Why wouldn't you follow SLDC...? I've been using a customized version of github.com/obra/superpowe… & Plane.so locally...Agents have access to it via MCP plugin. I write a spec, have agents break them down into work items. For dev they take a work item, plan, write code, review code against standards, tests, etc...better than "make no mistakes"
English
0
1
24
3.2K
Grigori Karapetyan
Grigori Karapetyan@GregKara6·
claude helped me crack a vehicle ECU not cracked by anyone else in the world for the last decade. i hooked it up to a glitch device with python scripting capability and left it alone, it literally glitched the chip, got passed the security chip, NOPed out the instruction to skip it on subsequent boots. Insane.
English
5
1
29
3.2K
Corben Leo
Corben Leo@hacker_·
important production web-app for a top-100 company in the SP-500. I gave it vague instructions with scope, and skills containing some methodology, went to bed. Woke up and it had run for 1h30mins ish. Woke up to this morning & it had found a funky behavior on an endpoint it found. I told it to continue, it found the major bug, I then steered it to find RCE (had to push pretty hard). idc if people don’t believe it honestly but I will point to just “trust me bro”👇I have no reason to fabricate this or lie
Corben Leo@hacker_

@lowellmanners I'm top 100 all-time on HackerOne. This was not a hallucination, I have been extremely reserved about AI & it's capabilities....

English
3
1
14
7K
0xVoodoo
0xVoodoo@Fr3ki_·
@hacker_ @chompie1337 Was this web, binary, IoT, embedded, something else? Was it a CTF or a production webapp? I'm seeing a lot of glaze for Claudes hacking skills with literally 0 evidence to convince me it's real. PoC or GTFO
English
1
0
1
7.1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Just remember... When your AI agent accidentally deletes a production database on your target while your letting it do the hacking for you, your the one that will face charges, not the bot.
English
13
27
267
15.6K
DeptOfWarCrimes🇺🇸🙈🙉🙊
@rez0__ @hacker_ Kinda curious how he taught it his Methodolgy. Wont take it literally since i dont think he was actually training the model.. Is he using prompt injection ? Or some type of vector retrieval system ? Is it loading his entire methodology at the beginning ? Or in sequence
English
1
0
0
187