Sam Curry

3K posts

Sam Curry

Sam Curry

@samwcyo

Присоединился Ocak 2017
1.1K Подписки100.4K Подписчики
notkirb_
notkirb_@notkirb_·
@samwcyo Maybe if you use your brain instead, you would have better luck
English
5
9
3.5K
127.1K
Sam Curry
Sam Curry@samwcyo·
Asked Claude to root my Xiaomi 17 Pro Max. Did not go well.
Sam Curry tweet media
English
365
374
13.7K
1.9M
Sam Curry ретвитнул
Andy Greenberg (@agreenberg at the other places)
A second iOS exploit has been spotted in use by Russian spies to infect websites and hack visitors' iPhones. This one works on iOS 18, and appeared in a very reusable form, so will likely proliferate. If you haven't updated your iPhone, now's the time. wired.com/story/hundreds…
English
3
95
244
69.5K
Sam Curry ретвитнул
Rust
Rust@playrust·
The Rust X Hackerone Program! 🐛🕵️‍♂️💰 Earn cash rewards by reporting bugs, security vulnerabilities, and exploits! Discover more here: #HackeroneBountyProgram" target="_blank" rel="nofollow noopener">rust.facepunch.com/news/soft-refr…
English
13
17
264
37.5K
Sam Curry ретвитнул
spaceraccoon | Eugene Lim
spaceraccoon | Eugene Lim@spaceraccoon·
I found a remote code execution on the latest TP-Link Tapo webcam models! The path to code execution wasn't direct and involved an interesting chain (3 CVEs). Check out my blogpost for more details! spaceraccoon.dev/getting-shell-…
English
9
91
510
28.2K
Sam Curry ретвитнул
Andy Greenberg (@agreenberg at the other places)
A full iOS exploit toolkit, "Coruna," has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been created for the US government. wired.com/story/coruna-i…
English
8
312
720
99.3K
Sam Curry ретвитнул
Sock
Sock@sockdrawermoney·
It is weird to grind away at something for over a year and finally start talking about it openly. I'm encouraged by the probing questions and thought so far on mlld.ai -- thank you all who've taken the time! For anyone who'd prefer a video intro, turn on notifs!
English
2
1
25
3.9K
Sam Curry ретвитнул
John Scott-Railton
John Scott-Railton@jsrailton·
BREAKING: US just sanctioned a network of exploit brokers trafficking in stolen US hacking tools First-ever use of #PIPA (Protecting American Intellectual Property Act) by @USTreasury. Here's the wild backstory of how @opzero_en got US-taxpayer funded exploits. 1/
John Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
13
205
618
65.7K
Sam Curry ретвитнул
cts🌸
cts🌸@gf_256·
V12 is now live for open beta. It can: - Find valuable bugs - Generate working, runnable PoC - Generate patch and test the PoC against it In our testing during audits at Zellic, Zenith, and Code4rena we've been consistently impressed. Best of all: it's free. (Don't abuse it!)
cts🌸 tweet media
pashov@pashov

@claudeai Impressive. Very nice. Now do this, but for smart contracts

English
20
75
490
114.1K
Sam Curry ретвитнул
Caleb Gross
Caleb Gross@noperator·
Terence Tao perfectly captures why AI is gaining traction in security research: > To date, the problems that AI has solved are the ones that are attention-bottlenecked: the ones for which Erdős posed once or twice in a paper, but there's been almost no follow-up literature; no one has really looked at them. But AI can scale, and so we are making progress on a lot of problems for which we didn't really have enough human attention. youtube.com/watch?v=zJvuaR… #fn:1" target="_blank" rel="nofollow noopener">noperator.dev/posts/on-the-m…
YouTube video
YouTube
Caleb Gross tweet mediaCaleb Gross tweet media
Caleb Gross@noperator

1/ Agentic LLMs can automate vuln detection. Very exciting, but doesn't address the hardest part (imo) of vuln research: prioritization. Can we reliably explore the search space and separate signal from noise? I wrote a paper (and OSS tool) to solve this. arxiv.org/pdf/2512.06155

English
4
46
354
56.9K
Sam Curry ретвитнул
kqx
kqx@kqx_io·
How a single typo led to RCE in Firefox Can you spot the bug? Read now at: kqx.io/post/firefox0d…
kqx tweet media
English
6
93
638
147K
Sam Curry ретвитнул
sshell
sshell@sshell_·
@thedawgyg i don't know it it's up to date, but i always really liked the idea of informed bug hunting using the "chromium money tree" from @rebane2001 basically tells you how much has been paid out in bounties at for chrome at the file level lyra.horse/misc/chromium_…
sshell tweet media
English
1
9
59
5.7K
Sam Curry ретвитнул
Hacktron AI
Hacktron AI@HacktronAI·
We found a RCE in Google's AI code editor Antigravity - $10000 Bounty Link to the blog in comments:
Hacktron AI tweet media
English
17
97
568
66.4K
Jenish Sojitra
Jenish Sojitra@_jensec·
Has anyone figured out how to deal with security implications of hosting @openclaw ?
English
8
0
33
10.9K
Sam Curry
Sam Curry@samwcyo·
@maxbittker Yes 😄 -- my runes were smuggled in from tutorial island using a bot which @sshell_ and I made. There were probably 20,000 different characters that spawned in, teleported to lumbridge, then dropped all their stackables
Sam Curry tweet mediaSam Curry tweet media
English
4
2
35
4.1K
max
max@maxbittker·
was this you @samwcyo ? noticed you're #1 on the magic highscores :)
max tweet media
English
1
0
10
3.3K
max
max@maxbittker·
Opus4.6 stayed busy last night while I was asleep. ...where did the runes come from at 0:03...?
English
34
2
279
130.6K
Sam Curry ретвитнул
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top-1…
English
2
78
233
41.7K