Yoav Alon

630 posts

Yoav Alon

Yoav Alon

@yoavalon

CTO @orcasec | I tweet about fuzzing, bugs, and all that security jazz

Katılım Nisan 2014
381 Takip Edilen1.8K Takipçiler
Yoav Alon retweetledi
𝙿𝚊𝚟𝚎𝚕 𝙶𝚞𝚛𝚟𝚒𝚌𝚑
Being an Israeli CEO since 2019 is basically very much like: while True: slack_team(f"Don't come to the office today due to: {random.choice(['pandemic', 'war', 'sirens', 'protests', 'shenanigans'])}")
English
7
20
516
32.9K
Yoav Alon retweetledi
Yaron Dinkin
Yaron Dinkin@ydinkin·
Joining the agentic vuln research hype, @EyalKraft and I did something. Unfortunately, it worked better than we hoped. We spent a few weeks building an agentic loop that reverse-engineers and exploits kernel drivers. We already found 100+ exploitable drivers. (link below)
Yaron Dinkin tweet media
English
9
49
281
38.8K
Yoav Alon retweetledi
Dmitry Vyukov
Dmitry Vyukov@dvyukov·
syzkaller/syzbot now has AI agentic framework for kernel bug fix generation, bug assessment, security triage, POC generation, etc: groups.google.com/g/syzkaller/c/… Includes set of tools to build kernels, navigate/edit source, test reproducers, etc. Contributions/research are welcome.
English
1
39
127
10.9K
Roee Shenberg
Roee Shenberg@roeeshenberg·
Wanted to replicate modded-nanogpt to try out a small idea to accelerate convergence. "Let's try runpod, it'll be simple." Big mistake. Gimme back VMs, this isn't functional...
English
1
0
1
215
Yoav Alon retweetledi
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
Recorded some updated thoughts on agentic coding tools if someone is curious.
English
15
88
761
44.4K
Yoav Alon retweetledi
Rob Zolkos
Rob Zolkos@robzolkos·
@badlogicgames "includeCoAuthoredBy": false In ~/.claude/settings.json
English
1
3
34
2.4K
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
So far my experience with Gemini Code is … not amazing. It's really bad at actually doing edits. It's sometimes marinating for 5 minutes for a basic edit.
Armin Ronacher ⇌ tweet media
English
18
5
129
12.7K
Jarred Sumner
Jarred Sumner@jarredsumner·
In the next version of Bun `bun init` detects if you're using Cursor and adds a Cursor rule to guide the agent to use Bun's CLI & APIs
Jarred Sumner tweet media
English
45
49
1.2K
72.6K
Yoav Alon retweetledi
Yoav Alon retweetledi
Ivan Fratric 💙💛
Ivan Fratric 💙💛@ifsecure·
Domato Lives! Today, we merged a WebGPU fuzzer written by @btiszka who used it to find several serious bugs in Chrome. Check it out at github.com/googleprojectz…. Potentially also interesting for other browser vendors working on their own WebGPU implementation ;)
English
0
29
98
11.3K
Yoav Alon retweetledi
Snyk
Snyk@snyksec·
Snyk 🤝 @orcasec Together, we're revolutionizing DevSecOps. 💪 Learn how our strategic partnership provides unparalleled visibility into risks throughout the entire app lifecycle - from dev to runtime. #AppSec #CloudSec snyk.co/uhrWl
English
0
2
4
814
Yoav Alon retweetledi
Ido Frizler
Ido Frizler@idofrizler·
עכשיו במהדורת RGB מיוחדת עם 16,777,216 עמודים: פיל עם קרחת, את השיער לא חופף. חלמתי על פיל בצבע #A8E04F
Ido Frizler tweet media
עברית
19
12
441
20.2K
Yoav Alon retweetledi
Tal Be'ery
Tal Be'ery@TalBeerySec·
1/ A world first reverse engineering analysis of AWS Session Tokens. Prior to our research these tokens were a complete black box. Today, we are making it more of a glass box, by sharing code and tools to analyze and modify AWS Session Tokens. @TalBeerySec/revealing-the-inner-structure-of-aws-session-tokens-a6c76469cba7" target="_blank" rel="nofollow noopener">medium.com/@TalBeerySec/r…
English
4
154
442
57.8K
Yoav Alon retweetledi
shubs
shubs@infosec_au·
Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
shubs tweet media
English
15
219
789
73.1K