symeon

1.1K posts

symeon banner
symeon

symeon

@symeonp

vuln research

London, UK Katılım Ağustos 2009
343 Takip Edilen1.2K Takipçiler
sakura
sakura@eternalsakura13·
@symeonp @hlvl4d I scanned Skia with CodeQL today, and there were way too many false positives—300 cases.🥹
English
1
0
0
113
sakura
sakura@eternalsakura13·
@symeonp Nice, how did you find it? Was it through fuzzing or code review?👍
English
1
0
6
2.5K
symeon
symeon@symeonp·
@_EthicalChaos_ Very very true Ceri! Been using it for both vuln hunting and soft dev and it's really impressive. Of course needs some guidance as you say....
English
0
0
1
68
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿
CCob🏴󠁧󠁢󠁷󠁬󠁳󠁿@_EthicalChaos_·
The last few weeks I have been consuming LLM tokens like pacman chomping on pac dots going for the world record. I am blown away by its capability. My background before the world of cyberz was software development. Using LLMs to code so far tells me that you still need to understand good vs bad code and have a decent grasp of SOLID principles if you want production quality code, unlike my GitHub. That way, you can prompt the LLM to do it again but better. Essentially becoming a lead developer guiding a junior with their PRs. Without this, you'll certainly get what has been coined as AI slop. But it does make me wonder how learning to become a software developer will change. I assume it will switch to learning to read, understand, debug and spot design flaws over syntax, data structures and mundane writing tasks that now take seconds to write. Certainly an exciting time.
English
5
3
36
4.4K
symeon retweetledi
Synacktiv
Synacktiv@Synacktiv·
At #Pwn2Own Berlin 2025, a full exploit chain against VMware Workstation was demonstrated via a heap overflow in the PVSCSI controller. Despite Windows 11 LFH mitigations, advanced heap shaping and side-channel techniques enabled a reliable exploit. 🔍 Full technical write-up 👇 synacktiv.com/en/publication…
English
4
151
534
49.2K
symeon retweetledi
BINARLY🔬
BINARLY🔬@binarly_io·
✨AI-generated code is accelerating development, but it's also introducing unmaintainable, vulnerable dependencies. Today, we introduce VulHunt: A new framework for semantic binary vulnerability detection. binarly.io/blog/vulhunt-i…
English
2
24
87
379.4K
symeon retweetledi
Tim Becker
Tim Becker@tjbecker·
@danrobinson #L60" target="_blank" rel="nofollow noopener">github.com/theori-io/aixc… An early version of this was proven in AIxCC and is open source. In evaluations, we gave it thousands of candidate bug reports (with just a handful of true positives), and it filtered out nearly every false positive while preserving every true positive.
English
1
1
7
511
symeon retweetledi
clearbluejar
clearbluejar@clearbluejar·
pyghidra-mcp v0.1.13 new release - 👀🔥 New Features: - Import Directory - Mermaidjs CallGraphs Ghidra Headless Vibe reversing++
clearbluejar tweet mediaclearbluejar tweet media
English
2
6
17
855
NSG650
NSG650@nsg650·
@symeonp Nope I can't find it either. How did you come across it though?
English
1
0
0
96
symeon
symeon@symeonp·
Hey @nsg650 any chances that you can share the PCADRVX64.sys driver? :) i can't find a single copy of it, thanks!
English
1
0
0
403
symeon retweetledi
quarkslab
quarkslab@quarkslab·
BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪 However, with the right primitives, you can do much more. Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver. 👇 blog.quarkslab.com/exploiting-len…
quarkslab tweet media
English
2
56
164
12.3K
symeon retweetledi
tylerni7
tylerni7@tylerni7·
Will post more later but: please check out @theori_io's landing page for AIxCC! We've got source code, agent traces, and blog posts to understand the system we built! theori-io.github.io/aixcc-public/
English
2
34
114
12K
symeon
symeon@symeonp·
@garethheyes right I see!! I opened it and then clicked 'update the restart' and somehow reverted it back to the stable one! whoops, sorry, thanks!!
English
1
0
0
81
symeon
symeon@symeonp·
@garethheyes thanks cheers, that's the one I believe I tried?
English
2
0
0
71
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
Manual testing doesn't have to be repetitive. Meet Repeater Strike - an AI-powered Burp Suite extension that turns your Repeater traffic into a scan check.
GIF
English
2
10
67
7.6K