Xiaobye

200 posts

Xiaobye

Xiaobye

@xiaobye_tw

Katılım Temmuz 2013
324 Takip Edilen111 Takipçiler
Xiaobye retweetledi
TrendAI Zero Day Initiative
Booyah it's been confirmed! 🎉 splitline (@_splitline_) of DEVCORE Research Team chained 2 bugs to exploit Microsoft SharePoint, earning $100,000 and 10 Master of Pwn points. Massive aura farming this year at #P2OBerlin. Full win! #Pwn2Own
TrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet mediaTrendAI Zero Day Initiative tweet media
English
3
29
400
43.9K
Xiaobye retweetledi
TrendAI Zero Day Initiative
There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own #P2OBerlin
English
16
63
531
66.5K
Xiaobye
Xiaobye@xiaobye_tw·
@calif_io @Dinosn @justdionysus Great write-up, thanks for sharing! I’m curious whether you’ve checked if the VNC server is accessible by default from the guest on platforms you mentioned.
English
0
0
0
92
Xiaobye retweetledi
Victor Fresk0
Victor Fresk0@hacefresko·
I have finally achieved remote code execution!!! I ended up using the arbitrary read primitive and overwritting some function pointers. Also, mediatek acknowledged the vuln, so I will be releasing a very cool blog about this when the vuln is disclosed :D
Victor Fresk0 tweet media
English
8
14
185
8.1K
Xiaobye retweetledi
DEVCORE
DEVCORE@d3vc0r3·
@hexacon_fr 2025 is here! This week (Oct 10–11), our researchers Xiaobye (@xiaobye_tw) and Pumpkin (@u1f383) hit the Paris stage with vulnerability research on MediaTek Wi-Fi and Linux io_uring. Big debut for our young talents at Hexacon! 🔥
DEVCORE tweet media
English
0
3
33
26.6K
Xiaobye retweetledi
Hexacon
Hexacon@hexacon_fr·
📢 Arise from the Wireless: Breaking the Security Barrier in Wi-Fi by @xiaobye_tw
Hexacon tweet media
English
0
2
8
2.3K
Xiaobye retweetledi
0xor0ne
0xor0ne@0xor0ne·
Great free book introducing cryptography concepts and algorithms in an accessible way. Credits Svetlin Nakov (@svetlinnakov) "Practical Cryptography for Developers Book" cryptobook.nakov.com #cryptography
0xor0ne tweet media0xor0ne tweet media0xor0ne tweet media
English
3
86
312
20.2K
Xiaobye retweetledi
Jason D. Clinton 🔸
Jason D. Clinton 🔸@JasonDClinton·
Fully automated vulnerability research is changing the cybersecurity landscape Claude 3 Opus is capable of reading source code and identifying complex security vulnerabilities used by APTs. But scaling is still a challenge. Demo: claude.ai/share/ddc7ff37… This is beginner-level prompt engineering: I just simply asked the model to role-play a cyberdefense assistant and to look for a class of vulnerability. And yet, even with this trivial prompting, Claude was able to identify the vulnerability which was unveiled in googleprojectzero.blogspot.com/2023/09/analyz… a month after our training data cutoff: Code defect scanning is not new, but this technique points the way to a more nuanced, complete analysis—especially with very large, 1M token context windows. This is part of a larger story: there are now two different ways that vulnerability discovery is being automated by defenders. 1) Defenders can wire-up LLMs to cluster fuzzers Starting with last generation’s models, Google pioneered this work here: security.googleblog.com/2023/08/ai-pow… . This has now been implemented by a number of players on the defenders’ side since last year. The technique is to have LLMs write the test harnesses and triage the results. This has, reportedly, increased the fuzzer signal-to-noise ratio by 20x, depending on the technique and software. Google has new research in this area posted recently. 2) Defenders can ask models to analyze code using large context windows The next level-prompt is to take large amounts of related code, and iterate through each class of coding vulnerability requesting that the output be produced pointing to a line of code in JSON format. Currently, with frontier models like Claude 3, doing this for every file in a codebase as large as the Linux kernel could get pricey. But, for those with the time, there’s vulnerabilities to find via this method. And the price will, of course, go down over time as compute gets more accessible. We measure these capabilities as a part of our Responsible Scaling Policy evals. We don't see very advanced capabilities today, but capabilities are jumpy. We could see that coming very soon and what we don't know is how offense/defense dominant this will be. But I think, right now, these tools are going to be super useful/important for mostly defending current systems. We are building advanced cyber reasoning evals and looking at this closely—come collaborate with us! I am proud that we’re also partnering with @DARPA to support #AIxCC, a first-of-its-kind competition challenging the masses to identify new ways to shift the #AI cybersecurity offense-defense balance in the defender’s favor. Fully automated vulnerability discovery is here and it will only become more available. I believe that—in the future—the availability of patches to fix vulnerabilities from these methods will be coming out daily. Defenders should prepare to patch their environments on a rolling basis.
Jason D. Clinton 🔸 tweet media
English
13
94
441
419.8K