Perri Adams

2.1K posts

Perri Adams banner
Perri Adams

Perri Adams

@perribus

@Dartmouth ISTS Fellow & @SAISHopkins Adjunct Prof., inter alia. Former @DARPA, @DEFCON CTF, etc. @DistrictCon, @hexacon_fr, @LABScon_io CFP Review Boards

From one Washington to another Katılım Mayıs 2011
989 Takip Edilen6.6K Takipçiler
Sabitlenmiş Tweet
Perri Adams
Perri Adams@perribus·
Back in 2023, the assessment of the pre-authentication vulnerability in SSH was that it wasn't exploitable on Linux. For my OffensiveCon 2025 keynote, I wrote enough of an exploit to show, with the right heap groom and stabilization, it's likely exploitable. Then I tried to have AI do it. Up to @taviso whether that merits switching to Windows 98 :) youtube.com/watch?v=Y1naY3…
YouTube video
YouTube
Tavis Ormandy@taviso

If someone get a working OpenSSH exploit from this bug, I'm switching my main desktop to Windows 98 😂 (this bug was discovered by a Windows 98 user who noticed sshd was crashing when trying to login to a Linux server!)

English
9
35
245
51.1K
Perri Adams retweetledi
Claude
Claude@claudeai·
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
English
1.9K
5.8K
50K
26M
Perri Adams retweetledi
Sean Heelan
Sean Heelan@seanhn·
What mathematicians call "literature review" should be familiar to you as "vulnerability research". Or, put another way: erdosproblems.com is currently the best benchmark for LLM capabilities in finding 0days.
Sean Heelan tweet media
Dmitry Rybin@DmitryRybin1

Recently I gave a talk on LLMs for Math Research (mostly to an audience of pure and applied mathematicians) I tried to compile the latest progress in one presentation pdf and video recording: drive.google.com/drive/folders/…

English
6
19
172
29.8K
Perri Adams retweetledi
Zardus@DEFCON.social
[email protected]@Zardus·
Hello security researchers! Like it or not, agentic AI is here. It’s time to explore its impact on novel, academic research in cybersecurity. To this end, we’re launching the Conference for Synthetic Security Research (synsec.org). Researchers, start your agents!
English
15
69
407
36.2K
Perri Adams
Perri Adams@perribus·
Have a Furby 0-day? A Juicero exploit? A bewitched 🪄PoC for some cursed, End-of-Life 👻 product that your friends keep begging you to stop reverse engineering & touch grass? We see you: your real friends are at @DistrictCon Junkyard. 9 days to submit your most unhinged bugs!
Perri Adams tweet media
English
2
13
56
11.9K
Perri Adams retweetledi
Dino A. Dai Zovi
Dino A. Dai Zovi@dinodaizovi·
This is not that much different than server-driven UI for mobile apps, where server-side logic controls layout, actions, and flow in mobile app UI. It was created to allow changes faster than a client code release could support. Software is software and good patterns re-appear.
dreadnode@dreadnode

Can we eliminate the C2 server entirely and create truly autonomous malware? On the Dreadnode blog, Principal Security Researcher @0xdab0 details how we developed an entirely local, C2-less malware that can autonomously discover and exploit one type of privilege escalation vulnerability. A future where fully autonomous red team assessments are powered by nothing more than a pre-installed local model and a Lua interpreter may be closer than you’d imagine. Read about it here: dreadnode.io/blog/lolmil-li…

English
0
1
4
1.9K
Perri Adams retweetledi
chompie
chompie@chompie1337·
bring your eol exploits to @districtcon junkyard! now’s the time to flex yr cute demo
chompie tweet media
English
1
18
101
14.7K
Perri Adams retweetledi
kuzushi
kuzushi@kuzushi·
This might actually be one of the best panel talks I've ever attended. @OffensiveAIcon
English
0
4
13
2.7K
Perri Adams
Perri Adams@perribus·
Had a great time doing a keynote panel with Rob Joyce and Dave Aitel at @OffensiveAIcon… and love the creative engagement from the audience Photo credit to @caseyjohnellis
Perri Adams tweet mediaPerri Adams tweet media
English
3
4
27
3.2K
Perri Adams retweetledi
Offensive AI Con
Offensive AI Con@OffensiveAIcon·
OAIC Day 1: Complete ✅ The conversation and idea sharing from yesterday's sessions have been bar-none. Plus, a full moon for last night's rooftop party! On deck this morning: --> Breakfast from 7-8:45 AM --> Kickoff at 9 AM with our keynote panel, featuring @RGB_Lights, @perribus, and @daveaitel. #OAIC2025 #OffensiveAICon
Offensive AI Con tweet mediaOffensive AI Con tweet mediaOffensive AI Con tweet mediaOffensive AI Con tweet media
English
0
6
25
2.4K
Perri Adams retweetledi
Xinyu Xing
Xinyu Xing@xingxinyu·
🚀 From DARPA #AIxCC to SWE-bench! Team 42-b3yond-6ug’s small coder model is now: 🏆 #1 on SWE-bench (lite) 💡 #6 on SWE-bench (verified) All while using far less compute than the giants ahead. Big thanks to #AIxCC for fueling this journey!
Xinyu Xing tweet mediaXinyu Xing tweet media
English
2
4
30
3.4K
Perri Adams retweetledi
Rob T. Lee
Rob T. Lee@robtlee·
Excited to be here at #OffensiveAICon for the next two days. 200 people focusing on offensive capabilities surrounding AI in the cybersecurity world. This team is top-notch and couldn't have brought together a more spectacular bunch of people to speak and to be able to participate in the event. I’m hoping to learn a lot. Interact with all the wonderful offensive AI minds. @RGB_Lights @daveaitel @mbazaliy @joshua_saxe @perribus @cyberphor and many more Shoutout to @dreadnode and RemoteThreat for putting the event together. @OffensiveAIcon @SANSInstitute @SANSOffensive
Rob T. Lee tweet media
English
1
2
5
1.2K
Perri Adams retweetledi
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
Katie Paxton-Fear tweet mediaKatie Paxton-Fear tweet media
English
12
66
474
50.4K