Thomas Garnier

4.6K posts

Thomas Garnier banner
Thomas Garnier

Thomas Garnier

@mxatone

Horizontal Security Lead at Databricks. Worked at Google and Microsoft. Co-creator of Sysinternals Sysmon and Linux KRSI.

Kirkland, WA Katılım Kasım 2010
376 Takip Edilen2.6K Takipçiler
Thomas Garnier retweetledi
Databricks
Databricks@databricks·
Serverless compute is now GA! ✅ Focus on writing code while we handle the rest. Enjoy fully managed compute infrastructure with fast workload startup, high reliability, and simple operation. Learn more about our latest updates: bit.ly/3zPsCXp
Databricks tweet media
English
1
9
53
6K
Thomas Garnier
Thomas Garnier@mxatone·
@pacbypass @sweis You can also argue that nation states steal bugs regularly (cf The Shadow Brokers) and fixing them if you think they can easily be stolen is a good idea.
English
1
0
0
83
Thomas Garnier
Thomas Garnier@mxatone·
@pacbypass @sweis That's fair. I think it depends on the methodology they used and how much it relies on things that are locked to TAG (vs Google, other vendors or everyone).
English
1
0
0
158
Thomas Garnier retweetledi
Ryan T. Brown 🎮🩷
Ryan T. Brown 🎮🩷@Toadsanime·
There may never have been a day as big as today for indie games. On the back of mass layoffs of major AAA studios, today more high-profile and under-the-radar gems are releasing on May 9th than any other day in recent memory. They need your support. Here's a thread of 'em! 🧵
Ryan T. Brown 🎮🩷 tweet mediaRyan T. Brown 🎮🩷 tweet mediaRyan T. Brown 🎮🩷 tweet mediaRyan T. Brown 🎮🩷 tweet media
English
110
5.5K
31.4K
3.1M
Maya Kaczorowski
Maya Kaczorowski@MayaKaczorowski·
ok I guess I did in fact bingo
Maya Kaczorowski tweet media
English
2
0
12
687
Thomas Garnier retweetledi
Yanir Tsarimi
Yanir Tsarimi@Yanir_·
I hacked Microsoft's AI bot for healthcare on a Friday night Within hours I could access data of multiple healthcare organizations, but it didn't stop there Microsoft fixed the issue, and then I did it again, and again, and again.. Here's the story of Lethal Injection: 💉
Yanir Tsarimi tweet media
English
26
244
1.4K
255.7K
Thomas Garnier retweetledi
Ali Ghodsi
Ali Ghodsi@alighodsi·
Today we released an open source model, DBRX, that beats all previous open source models on the standard benchmarks. The model itself is a Mixture of Experts (MoE), that's roughly twice the brains (132B) but half the cost (36B) of Llama2-70B. Making it both smart and cheap. Since only 36B expert parameters are used live, it's close to twice the speed (tokens/seconds) of Llama2-70B. We're excited to build custom versions of this for organizations that have proprietary data! Check it out! databricks.com/blog/announcin…
English
134
209
1.1K
216.3K
Thomas Garnier
Thomas Garnier@mxatone·
@sweis Reminded me of the duqu / Stuxnet bug. I didn't know before that TTF uses a VM to draw the glyphs. Create great R/W primitives.
English
0
0
0
414
Steve Weis
Steve Weis@sweis·
This iMessage exploit is crazy. TrueType vulnerability that has existed since the 90s, 2 kernel exploits, a browser exploit, and an undocumented hardware feature that was not used in shipped software: securelist.com/operation-tria…
Steve Weis tweet media
English
61
1.3K
5.9K
2.6M
Thomas Garnier retweetledi
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
The fact that they developed a complete zero-click to kernel chain, JUST to then force the device to open a web page to trigger the "real" chain, is the most bureaucratic exploit I can imagine 🙈 koeln.ftp.media.ccc.de/congress/2023/…
LiveOverflow 🔴 tweet media
English
20
298
1.7K
164.8K
Thomas Garnier retweetledi
Matei Zaharia
Matei Zaharia@matei_zaharia·
As good a time to say this as any: if you’re on the AI research job market, Databricks is hiring, with the mission to democratize AI. We power amazing customer use cases and we publish. Check databricks.com/company/careers or reach out.
English
5
29
200
43.6K
Thomas Garnier retweetledi
Ali Ghodsi
Ali Ghodsi@alighodsi·
The founders of Databricks put together this strategy blog on where we think data platforms are headed in the future. We're moving Databricks quickly in this direction. This is very exciting and is the outcome of the MosaicML acquisition we did earlier this year! databricks.com/blog/what-is-a…
English
13
132
765
209.5K
Thomas Garnier
Thomas Garnier@mxatone·
@MrDBCross It depends on people but I assume some people are amazing at finding issues and find it hard to develop skillsets on the engineering side. Similar to some engineers not really into security.
English
0
0
1
52
Thomas Garnier retweetledi
Bill Marczak
Bill Marczak@billmarczak·
The way Kaspersky wrote this, it's an interesting case study of defenders working out how to capture a zero-click exploit. I especially like that Kaspersky said what they tried that *didn’t work*, in addition to what did ultimately work. Let’s dive in with a thread!
English
3
28
122
40.9K
Thomas Garnier retweetledi
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Web Security vs. Binary Exploitation
English
98
1.9K
10.2K
833.5K