vladko312

53 posts

vladko312 banner
vladko312

vladko312

@vladko312

Katılım Nisan 2017
37 Takip Edilen8 Takipçiler
vladko312
vladko312@vladko312·
@NotDeGhost The problem is that CTFs (especially simpler ones) often create tasks considered classic, like WAF + SQLi. Those are not "solved", but "learned"/"trained". CTFs should make more tasks that require thinking or finding uncommon knowledge. But it requires authors to do the same.
English
0
0
1
42
Robert Chen
Robert Chen@NotDeGhost·
We think Jeopardy CTFs are dead, and are looking for new ideas: a new style of challenges that allows for a leaderboard indifferent to the presence of AI. As outlined in the blog, we think the AD and KOTH formats are a step in the right direction, although imperfect.
English
5
1
50
4.4K
Robert Chen
Robert Chen@NotDeGhost·
We're launching a $100,000 fund to save CTFs.
Robert Chen tweet media
English
17
108
646
63K
vladko312
vladko312@vladko312·
@ZackKorman Those are not predictions, those are hidden pitches for investors. CEOs pretend like the AI will "take jobs" or "hack everything" because that is what investors want/expect from AI. What they need to believe in. At the same time, CEOs look good to the public, as if they care.
English
0
0
0
15
Zack Korman
Zack Korman@ZackKorman·
The same people who warned of mass unemployment caused by AI are now warning of mass cybersecurity chaos caused by AI. I think they’re just bad at prediction.
English
35
20
291
20K
vladko312
vladko312@vladko312·
@wbond Hello, @wbond ! I recently discovered a vulnerability in one of your GitHub repositories. Private vulnerability reporting is not enabled for this repository and I got no reply for my e-mail. What would be the preffered channel to report the vulnerability? Thank you in advance!
English
0
0
0
5
Will Bond
Will Bond@wbond·
While AI is moving us forward in leaps and bounds, I’m watching a bazel build for a Python repo download over 1GB of 3 JDKs and Rust toolchain, over the course of 8 minutes.
English
1
0
1
171
vladko312
vladko312@vladko312·
@watchtowrcyber It would be interesting to see your attempt to reproduce RCE using CVE-2026-46633. It has CVSSv4 of 9.3 and could act as RCE payload for most Twig versions, sandboxed or not, including previously unexploitable ones. Still, there are no known RCE payloads, unlike CVE-2026-46640.
English
0
0
0
164
watchTowr
watchTowr@watchtowrcyber·
speak soon xo
English
2
2
27
3.8K
vladko312
vladko312@vladko312·
@AnthropicAI Mythos recently found multiple sandbox bypasses in Twig. For CVE-2026-46640, I made a PoC module for SSTImap, but it was not as trivial as the description might imply. As for CVE-2026-46633, I'm stuck after getting code injection. Can @AnthropicAI help prove it to be exploitable?
English
0
0
0
90
Anthropic
Anthropic@AnthropicAI·
Patching these vulnerabilities will make us safer. But the software industry will need to adapt to the volume of vulnerabilities that models like Claude Mythos Preview will be able to find. We discuss this in our initial update on Project Glasswing: anthropic.com/research/glass…
English
113
150
1.7K
503.3K
Anthropic
Anthropic@AnthropicAI·
Last month we launched Project Glasswing, our collaborative AI cybersecurity initiative. Since then, we and our partners have found more than ten thousand high- or critical-severity vulnerabilities in essential software.
English
516
645
8.5K
2.8M
vladko312
vladko312@vladko312·
@zseano The screenshot is not even about AI. It is about preventing agents from doing stuff without human control. AI might help find bugs, but AI agents have a risk of exploiting them and causing harm to the system. This rule seems reasonable, you can still use AI, but not agents.
English
1
0
5
495
zseano
zseano@zseano·
Would not be surprised if AI testing becomes a new Hackerone platform standard that companies opt in or out of 🧐 Get caught using AI? Bye bye bounty. Interesting times ahead for the industry
zseano tweet media
English
17
12
217
15.9K
vladko312
vladko312@vladko312·
@Krevetk0Valeriy @DeniedZoomer Maybe then publicly mention the existance if vulnerability (without details), mention failed contacts and tag the company in the post? This might attract some attention from that company. And ask to escalate up, not to IT, as IT might underestimate importance of non-tech impact.
English
0
0
0
27
Valeriy
Valeriy@Krevetk0Valeriy·
@DeniedZoomer Full disclosure threatening is not my style 💁🏻‍♂️ I would prefer less Twitter drama to have 😁
English
2
0
0
173
Valeriy
Valeriy@Krevetk0Valeriy·
Twitter Security community knows about responsible disclosure a lot. Can anyone advise me on what I should do next with the company? CERT didn’t help? It’s a large company and a major data breach. I haven’t felt the need to look into GDPR, but it seems like the time has come?
Valeriy tweet media
English
5
2
49
7.3K
vladko312
vladko312@vladko312·
@herrmann1001 Why is RFID security so separated from the rest of InfoSec? It feels like a lot of systems just trust the card hardware to protect the data. No extra encryption or signing. And there is very little research about using cards to provide untrusted input beyond changing values.
English
0
0
1
73
Iceman
Iceman@herrmann1001·
Mind blown 🤯 Some smartphones sold in mainland China (like certain OPPO models) can read MIFARE Classic cards, crack the keys in seconds, store them, and then fully emulate the card directly on the phone. No extra hardware. Just the phone. Access control, transit cards, hotel keys… game over. Huge thanks to Ian for showing me this in person. Really eye-opening how far NFC capabilities have gone in some regions. Who else has seen this in the wild? #NFC #MIFARE #TechSecurity​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​ #oppo
English
102
608
3.9K
456.7K
Zack Korman
Zack Korman@ZackKorman·
Security people: This behavior is completely unacceptable. I don't care that you sent a few emails and got ignored. You don't get to drop this info publicly and put these users at greater risk. He's been called out by multiple people (@rez0__) and is doubling down. Not cool.
Zack Korman tweet media
English
48
13
245
79.7K
vladko312
vladko312@vladko312·
@ZackKorman @rez0__ People want to improve security bu reporting vulnerabilities. Sometimes they don't know how to do it correctly. Just calling them blackhats would just leave them guessing why other disclosures are welcome, but they are criticised for what they think is the same thing.
English
0
0
0
20
vladko312
vladko312@vladko312·
@ZackKorman @rez0__ The reason why @rez0__ approach was bad: Calling someone blackhat will not help them and others to fix their mistakes. People see disclosures and want to do something cool like that. It is better to explain how it should be done, rather than just calling them bad 🧵
English
2
0
0
38
vladko312
vladko312@vladko312·
@weezerOSINT customers without an immediate exploit for others to use. Your approach provides others with instructions on how to exploit the vulnerability immediately, which is not perfect. If the vulnerability affects that many people, it would be preferable to warn them without public PoC
English
0
0
2
44
vladko312
vladko312@vladko312·
@weezerOSINT The better approach would be to try contacting multiple times over some time, and if no contact was made - release a proof of vulnerability with a date for full disclosure in a month if no response would be given. That would give the company reasons to respond and inform the ...
English
1
0
1
618
impulsive
impulsive@weezerOSINT·
if you've ever used Reframe to get sober, your private journals, your craving logs, what triggered you, how bad it got, your name, your email, all of it is sitting in a database that anyone can read without logging in i unzipped the app and found a database key in a config file. thats it. thats all it took 357,939 users exposed. disclosed april 7, no response
impulsive tweet mediaimpulsive tweet media
English
32
41
467
191.6K
vladko312
vladko312@vladko312·
@waitbutwhy "everyone survives" makes it seem like someone was in danger to begin with. Without such wording, blue is just a pointless gamble, as it only really saves others who pressed blue. With that wording, others might not have understood the gamble, so it becomes moral to save them.
English
0
0
0
6
vladko312
vladko312@vladko312·
@waitbutwhy Even this raw question still feels biased for blue (my choice). Starting with surviving frames blue as a good choice, tricking people. Now it becomes moral to press blue to save THEM. With a different wording, the correct button could be red, as blue has no benefits for anyone.
English
1
0
0
19
Tim Urban
Tim Urban@waitbutwhy·
Everyone in the world has to take a private vote by pressing a red or blue button. If more than 50% of people press the blue button, everyone survives. If less than 50% of people press the blue button, only people who pressed the red button survive. Which button would you press?
English
5.7K
1.4K
14.4K
27.1M