Paul Seekamp

5.5K posts

Paul Seekamp banner
Paul Seekamp

Paul Seekamp

@nullenc0de

I spend a significant amount of time reading security stuff. Co-Founder/Partner @CoastlineCyber https://t.co/ZQT5L8q2RO

ɴ̵̢̧̮̮̹̖̳͍̳̣̻̰̯̜̰̰̭̑̌̊̿̀̾͑̆̀̈́ Katılım Ocak 2012
627 Takip Edilen17.3K Takipçiler
Sabitlenmiş Tweet
Paul Seekamp
Paul Seekamp@nullenc0de·
Big news! I started @CoastlineCyber, a boutique cyber security consulting firm dedicated to strengthening your organization's security posture. 💪
Paul Seekamp tweet media
English
1
5
30
15.5K
Paul Seekamp
Paul Seekamp@nullenc0de·
@HackingDave She doesn't know she's in a room with the guy that created the social engineering toolkit.
English
1
0
35
1.3K
Dave Kennedy
Dave Kennedy@HackingDave·
Taylor Swift said hello !
Dave Kennedy tweet media
English
26
10
299
23.3K
Paul Seekamp
Paul Seekamp@nullenc0de·
Anthropic, how many likes do I need to bring back the day-one public release of Claude 4.6? @AnthropicAI
English
1
0
5
679
Simone Margaritelli
Simone Margaritelli@evilsocket·
Opus 4.7 at max effort now bypasses/ignores plan mode and just changes things around without user interaction. Great.
Simone Margaritelli tweet media
English
4
0
34
5.4K
Paul Seekamp
Paul Seekamp@nullenc0de·
@evilsocket I think i will. I just like claude channels so much. Dont want to give it up. But I might have to.
English
1
0
1
93
Simone Margaritelli
Simone Margaritelli@evilsocket·
@nullenc0de considered switching to openai? their 20x plan seems pretty nice and 5.5 seems much smarter
English
1
0
0
81
Simone Margaritelli
Simone Margaritelli@evilsocket·
dude i'm fixing really stupid mistakes that opus 4.7 started making at max effort, with sonnet 4.5 ... wtaf is anthropic doing to this model
English
8
0
27
4.7K
Paul Seekamp
Paul Seekamp@nullenc0de·
@evilsocket Oh I totally agree. I have been using Sonnet now. I can't use Opus anymore. It's like I traveled back in time to a dumber, less usable model.
English
1
0
1
68
Paul Seekamp
Paul Seekamp@nullenc0de·
Lol, spent 4 weeks deciding to migrate my Critical to a medium risk because the PII wasnt "sensitive enough". But they patched the vuln in less than 1 hour... Money must be tight. The $50k bounty was too much to pay. I understand 👍 Shareholders don't want to see that stuff.
English
1
0
7
902
Paul Seekamp
Paul Seekamp@nullenc0de·
@thedawgyg They patched like 30 critical findings last week and judging by the amount of reports I have sitting in triage for a month they probably have so many.
English
0
0
4
653
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Even Google is reducing bounty amounts.... "We will be reducing some of our reward amounts and bonuses across Android and Chrome. While these adjustments may reduce the payout for a single bug report, we continue to prioritize our VRPs and the total aggregate rewards paid out in 2026 is expected to increase." Yet when I was trying to tell people this would happen a few months ago, people said i was an idiot... lol... If even Google is reducing bounties do you really think these significantly smaller companies arent going to do the same thing?
Google VRP (Google Bug Hunters)@GoogleVRP

📣📢 Calling all Android and Chrome bug hunters 🧑‍💻🔎! We're updating our Android & Chrome VRP programs to ensure we can continue to reward the most challenging and impactful vulnerabilities researchers find in our products. For details, 👇 bughunters.google.com/blog/evolving-…

English
17
6
205
21.5K
Seth Jenkins
Seth Jenkins@__sethJenkins·
@nullenc0de Can you DM me both Buganizer numbers? And maybe a description? I'll take a look.
English
1
0
7
886
Paul Seekamp
Paul Seekamp@nullenc0de·
I'm gonna rant for a second: I found a Zero-Click RCE in the latest Samsung phones in February. Samsung says it's "Out of Scope" because "AOSP Source." So I go to Google, they say it’s High, not Critical, because "AOSP Baseline." My RCE still sitting in the wild, no patch😬
English
33
40
958
48.7K
Nossy
Nossy@ibay770·
@nullenc0de Can it be used to root the phone?
English
1
0
0
1.6K
Paul Seekamp
Paul Seekamp@nullenc0de·
@te3co I have a second one but its the same fix. So im waiting until I see how they fix it and then if they dont fix it the way i think they will. I'll just drop it here 🤣
English
0
0
3
2.7K
Paul Seekamp
Paul Seekamp@nullenc0de·
@Dave_Maynor And certainly going to be interesting soon. It's already getting interesting.
English
0
0
0
593
David Maynor
David Maynor@Dave_Maynor·
@nullenc0de Yeah. Because one thing audits like these show me is that while traditionally understood bug classes are easy, I keep finding new bug classes.
English
1
0
0
669
Paul Seekamp
Paul Seekamp@nullenc0de·
@roddux LOL well I was already in the queue to get patched. I just have no idea when...
English
0
0
2
1.5K
Jeremie Strand
Jeremie Strand@jeremie_strand·
@nullenc0de This is the broken incentive structure of shared codebases. Samsung points to AOSP, Google downgrades severity, and a zero-click RCE just sits there. No wonder researchers burn out on coordinated disclosure.
English
1
0
24
3.2K
Paul Seekamp
Paul Seekamp@nullenc0de·
@imftxyz Lol well. They are already in the queue to get patched it just might take 6 months...
English
0
0
7
3.4K
Paul Seekamp
Paul Seekamp@nullenc0de·
@D0rkerDevil You sitting on them? Seems like it's better to at least right now.
English
1
0
3
2.3K
Paul Seekamp
Paul Seekamp@nullenc0de·
@Dave_Maynor I get it. The triagers are overwhelmed. But, also they are gonna have to figure it out.
English
1
0
0
706