Mathy Vanhoef

3.6K posts

Mathy Vanhoef banner
Mathy Vanhoef

Mathy Vanhoef

@vanhoefm

Prof. @KU_Leuven | Ex-Postdoc NYU | Network Security & Crypto | FragAttacks & KRACK | https://t.co/cFWyCYRZyH

Orion Arm Katılım Şubat 2011
1.6K Takip Edilen14.4K Takipçiler
Sabitlenmiş Tweet
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
I found some design and implementation flaws in Wi-Fi again. All Wi-Fi devices are affected. It was a long ~9 months embargo, over this time a lot of info has been collected and that info now available at fragattacks.com
English
32
1.1K
2.6K
0
Mathy Vanhoef retweetledi
Gerard Govers
Gerard Govers@gerardgovers·
Als een significant gedeelte van de bevolking géén kinderen heeft zullen zij die nog wel kinderen hebben (en investeren om die op te voeden) het niet OK blijven vinden dat de pensioenen van mensen mét en zonder kinderen gelijk blijven.
Nikolaus Haufler@nikolaushaufler

𝟲𝟬𝟬.𝟬𝟬𝟬€ kostet es, zwei Kinder großzuziehen (Direktkosten + Verdienstausfall). Fast genau so viel bezieht ein kinderloser Mensch im Alter an Rente, Gesundheit und Pflege aus dem Umlagesystem. Ein einseitiges Geschäft: Eltern investieren, Kinderlose profitieren. 🧵

Nederlands
12
7
32
3.9K
Mathy Vanhoef retweetledi
Matthew Green
Matthew Green@matthew_d_green·
There’s been some reporting that Meta contributed an unfathomable sum to promote age verification laws globally. This is broadly true, but actual situation is a bit more complex. Figured it was worth an update.
English
30
152
1K
176.7K
Mathy Vanhoef retweetledi
Tao Yan
Tao Yan@ga1ois·
[2]After our failed competition, we headed to Apple Store and bought the mbp m5 and spent less than half an hour to set it up and found a fixed offset is changed 1 bit on it, so we just change 1 bit on our exp and it worked with a 100% success rate. Yes just 1 bit change, 1 to 2.
Tao Yan tweet media
TrendAI Zero Day Initiative@thezdi

Unfortunately, Tao Yan & Edouard Bochin of Palo Alto Networks could not get their exploit of Apple Safari – Renderer Only working within the time allotted. #Pwn2Own #P2OBerlin

English
14
38
571
102.9K
Mathy Vanhoef retweetledi
Moritz Schloegel
Moritz Schloegel@m_u00d8·
NDSS 2027 is looking for volunteers to join the Artifact Evaluation Committee. If you care about reproducibility & open science, we would be glad to have you on board. All sorts of backgrounds welcome & no prior experience required. Self-nominate here: forms.gle/3UydnaYP6vUChF…
English
0
2
4
473
Mathy Vanhoef retweetledi
ggwhyp
ggwhyp@ggwhyp·
I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
English
31
92
720
110.5K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
@SwiftOnSecurity This platform has kept going downhill. The "For You" page is mainly interaction slop where tweets stop in the middle of the sentence, right before the "juicy info", to get you to click on it. The "Following" page is less interesting because many people left or are less active
English
0
0
4
550
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
Been doing this account for 12 years with 100% original stuff, huge debuff of my posts the last 2 months or so. I'm not gonna really pursue it rn, but yeah something weird is going on and kinda nerfed my drive so you're not seeing a lot I normally would. ☹️🤷‍♀️
English
35
15
900
39.4K
Mathy Vanhoef retweetledi
Pwnie Awards
Pwnie Awards@PwnieAwards·
🚨Nominations for the 2026 Pwnie Awards are now open! Best bug? Worst Bug? Incredible research? Cataclysmic fuckups that knocked over half the internet? You know who deserves a Pwnie this year! Let us know! 🏇🏇🏇🏇🏇 tally.so/r/441Aro
English
2
10
25
4.9K
Mathy Vanhoef retweetledi
Brian Pak
Brian Pak@brian_pak·
Hey everyone. We’ve seen the discussions around Copy Fail (CVE-2026-31431) and the disclosure process. We appreciate the passion from distro maintainers, defenders, and the broader Linux community. This is a serious issue, and we want to share some context on our side in good faith. 🧵
English
16
85
542
106.5K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
Just presented AirSnitch at Black Hat Asia 2026! The presentation covered how we could often bypass Wi-Fi client isolation in home and professional access points. This was an awesome collaboration with UC Riverside! The slides and our NDSS'26 paper are linked below ⬇️
Mathy Vanhoef tweet mediaMathy Vanhoef tweet mediaMathy Vanhoef tweet mediaMathy Vanhoef tweet media
English
2
11
37
2.8K
Mathy Vanhoef retweetledi
Trail of Bits
Trail of Bits@trailofbits·
Google used a ZK proof to disclose a quantum breakthrough that cuts the cost of breaking cryptocurrency by 20x without handing attackers the circuit. We found anyone could forge a “proof” of an even stronger attack. 🧵
English
14
93
722
80.7K
Mathy Vanhoef retweetledi
K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵
hackers as the first group to embrace KYC for access to new models is cutting me deep. we used to be rebels
English
21
38
376
25.6K
Mathy Vanhoef retweetledi
Rob Fuller
Rob Fuller@mubix·
In collaboration with a couple of other leaders in the industry we are releasing SecurityTitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.
English
18
69
327
32.2K
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
@HaifeiLi @udunadan Or combine with manual code exploration, where AI greatly speeds up understanding of the code and verifying hypothesis. At least I think this can speed up the type of vuln research where you're trying new style of attacks (I still need to experiment more with AI though..)
English
0
0
1
30
Mathy Vanhoef
Mathy Vanhoef@vanhoefm·
@HaifeiLi @udunadan Might become the same as fuzzers: if you use an out-of-the-box config, i.e., common prompts, you won't find new things (once the new low-hanging fruit is found). To find new stuff, you'll need new strategies like combining with other tools (fuzzers, DAST) in a new way.
English
2
0
1
100
Haifei Li
Haifei Li@HaifeiLi·
Well, I recommend that folks who claim they used AI to find bugs describe their steps in detail - such as which AI models they used, what prompts they employed, which source files they asked the AI to analyze and how, etc. This is like the vulnerability PoC in the AI era. Only with sufficient details can others independently reproduce the findings and properly assess whether it’s real innovation, hype, or somewhere in between.
English
1
9
79
12.3K