Sabitlenmiş Tweet
Yiannis (John) Kozyrakis | @[email protected]
2.4K posts

Yiannis (John) Kozyrakis | @[email protected]
@ikoz
security engineer | https://t.co/4md7HaGx5W
London, UK Katılım Ağustos 2008
1K Takip Edilen1.3K Takipçiler
Yiannis (John) Kozyrakis | @[email protected] retweetledi

Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
sockpuppet.org/blog/2026/03/3…
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

I’m super excited about this blogpost. The approach is so counterintuitive, and yet the results are so much better than anything else that we’ve tried for memory safety. We finally understand why.
security.googleblog.com/2024/09/elimin…
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi
Yiannis (John) Kozyrakis | @[email protected] retweetledi

We are excited to announce that Google, Microsoft, and Meta are formally partnering as the founding steering committee to improve app security through a newly restructured App Defense Alliance, under the Joint Development Foundation.
Learn more: hubs.la/Q02873mh0

English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

* People ask LLMs to write code
* LLMs recommend imports that don't actually exist
* Attackers work out what these imports' names are, and create & upload them with malicious payloads
* People using LLM-written code then auto-add malware themselves
vulcan.io/blog/ai-halluc…
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

not every day 4 world-class security teams (all from Google, though that's not all of them...TAG, Mandiant, CrOS Security, and more) co-author a doc... #powerofopen
storage.googleapis.com/gweb-uniblog-p…
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

Here are the slides for my keynote, 'Mobile Exploitation, the past, present, and the future' at #Zer0Con2023. Zer0con was a blast as always, thank you @POC_Crew!! 🚀💫
github.com/externalist/pr…
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

The Android team has open sourced our internal Rust Training! It's a four day course covering the full spectrum of Rust, from basic syntax to advanced topics like generics and error handling. It also includes Android-specific content on the last day.
google.github.io/comprehensive-…
English

New APVI entry: platform certificates used to sign malware
Found by yours truly :)
bugs.chromium.org/p/apvi/issues/…
English

Yiannis (John) Kozyrakis | @[email protected] retweetledi
Yiannis (John) Kozyrakis | @[email protected] retweetledi

The folks in Chrome who work on securing the web platform API have compiled a great guidelines doc based on their experience. chromium.googlesource.com/chromium/src/+…
Thanks @mikewest et al!
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi
Yiannis (John) Kozyrakis | @[email protected] retweetledi

@Hexploitable @dcuthbert My 7: Olive oil, onions, garlic, peppers, tomatoes, carrots, more olive oil
English

@dcuthbert Not drastically different: Onion, garlic, tomato, paprika, soy sauce, miso, salt
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu fredericb.info/2022/06/breaki… < what an awesome write up
English
Yiannis (John) Kozyrakis | @[email protected] retweetledi

We have finally published Tproxy (objectifsecurite.gitlab.io/tproxy/) our generic TCP interception proxy (think Burp for TCP): TLS handling, wireshark dissection, intercept and modify by hand or with scripts in GUI or CLI.
There is a complete doc with demos (objectifsecurite.gitlab.io/tproxy/Demos/)
English











