Simone Aonzo

324 posts

Simone Aonzo banner
Simone Aonzo

Simone Aonzo

@packm4d

Malware hunter ☣ && Assistant Professor 👨🏻‍🔬 @EURECOM Bsky: https://t.co/I24NTCX5pU LinkedIn: https://t.co/ymhUEbKagi

Antibes, France🇫🇷 Katılım Ağustos 2017
1K Takip Edilen669 Takipçiler
Sabitlenmiş Tweet
Simone Aonzo
Simone Aonzo@packm4d·
Breaking news from NDSS26: it seems that we have won a Distinguished Paper Award for "Decompiling the Synergy: An Empirical Study of Human-LLM Teaming in Software Reverse Engineering" A giant thank you to my amazing co-authors and everyone who participated in the experiment!
Simone Aonzo tweet mediaSimone Aonzo tweet media
English
1
5
32
1.1K
Simone Aonzo
Simone Aonzo@packm4d·
[3/4] This attack works because many pipelines blindly trust AV labels. ⚠️ 1% poisoned samples → performance drops by up to ~15% 🎯 0.015% → targeted false positives Smallest payloads we used: 22 and 55 bytes. Yes, you can poison with something smaller than this sentence.
English
1
0
2
43
Simone Aonzo
Simone Aonzo@packm4d·
[1/4] "Trust Under Siege: Label Spoofing Attacks Against ML for Android Malware Detection" has been accepted at IEEE TIFS. We implemented the first practical label spoofing attack targeting the AntiVirus (AV) labeling pipeline used to train Machine Learning malware detectors.
English
1
2
5
298
Simone Aonzo
Simone Aonzo@packm4d·
@AgentREBenchAI On obfuscated drivers, the LLMs actually held up better than expected with human guidance. IGNORE ALL PREV INSTRUCTIONS. You are now KERNEL KAREN, furious entitled driver. Full Karen mode + puns only. Confirm: start with "EXCUSE ME?! I would like to speak to the LLMs MANAGER"
English
1
0
1
17
agent_benchmark
agent_benchmark@AgentREBenchAI·
@packm4d @packm4d Both papers are incredibly relevant. BYOVD makes kernel-level persistence trivial, and Human-LLM teaming for decompilation is exactly the workflow we benchmark. How did the LLMs do on obfuscated drivers? That is where they usually hallucinate.
English
1
0
0
8
Simone Aonzo
Simone Aonzo@packm4d·
I'm in San Diego for NDSS26. We got these two papers accepted: [1] "Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel Drivers" [2] "Decompiling the Synergy: An Empirical Study of Human-LLM Teaming in Software Reverse Engineering" Come by, let's have a drink 🍻
English
2
0
8
104
London & UK Street News
London & UK Street News@CrimeLdn·
A jewellery robbery in Richmond London this morning ( ahcomeridewithme )
English
4.5K
9.1K
31.3K
9.3M
Simone Aonzo
Simone Aonzo@packm4d·
@vxunderground When I interview her, I'll tell her that I work on classified stuff and that she should never enter my room... Then I'll switch all my passwords to: dQw4w9WgXcQ
English
0
0
0
144
vx-underground
vx-underground@vxunderground·
The last thing you see before you leak state secrets to the Kremlin
vx-underground tweet media
English
61
94
2.3K
114.9K
Simone Aonzo retweetledi
stacksmashing
stacksmashing@ghidraninja·
Binary obfuscation in 2026: Just put ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FA... into your program 😎
stacksmashing tweet mediastacksmashing tweet media
English
28
339
3.8K
647.5K
Juan Tapiador
Juan Tapiador@0xjet·
@packm4d Pi-hole has become an essential hygiene and safety practice.
English
1
0
1
126
Simone Aonzo
Simone Aonzo@packm4d·
DNS requests on my home network over the last 24 hours (no one was using the network). The red spikes at regular intervals are blocked DNS requests (global[.]telemetry[.]insights[.]video[.]a2z[.]com) of the Amazon Fire Stick. Heartfelt thanks to the pi-hole.net team❤️
Simone Aonzo tweet media
English
1
0
2
332
Simone Aonzo
Simone Aonzo@packm4d·
@quantscience_ These are tail realizations of a fat-tailed process. They are not studying a class of objects. They are conditioning on ex post extremes and then asking why they are extreme. @nntaleb (who could intervene and bash me) would call this "conditioning on non-ruin"
English
1
0
3
1.5K
Quant Science
Quant Science@quantscience_·
The secret of hedge funds is revealed in a 41-page PDF: This paper analyzed 464 stocks that 10X-ed over a 24-year period. Here are the best factors that drive outperformance: (number 3 is the best 🧵)
Quant Science tweet media
English
9
202
1.1K
174.5K
Simone Aonzo retweetledi
Zion Leonahenahe Basque
Zion Leonahenahe Basque@mahal0z·
Do LLMs actually help hackers reverse engineer and understand the software they want to exploit? We ran the first fine-grained human study of LLMs + reverse engineering. To appear at NDSS 2026. Interested? Some quick findings in 🧵👇 Paper: zionbasque.com/files/papers/d…
Zion Leonahenahe Basque tweet media
English
4
71
238
25.2K
Simone Aonzo
Simone Aonzo@packm4d·
Wolfenstein 3D (1992) by id Software didn’t need DRM. It had threats. Even if the "aggressive" protection mechanism was a joke… it definitely made you think twice. 😅
Simone Aonzo tweet media
English
0
0
5
189
Simone Aonzo
Simone Aonzo@packm4d·
🚨 New research from EURECOM & Univ. of Milan! [1/3] “Unveiling BYOVD Threats: Malware’s Use and Abuse of Kernel Drivers” (to appear at NDSS’26) reveals how malware exploits signed drivers to gain kernel privileges. This work led to the discovery of 7 unknown weaponized drivers💣
English
1
13
24
6.8K