mayank

139 posts

mayank banner
mayank

mayank

@exec_mayank

software | security | appsec | linux ¦ views my own current: security@amazon

nyc | the internet شامل ہوئے Nisan 2017
761 فالونگ121 فالوورز
mayank
mayank@exec_mayank·
@giovignone what was the issue? the only one i found by octane security was this medium issue -- [TBD][486506202] Medium CVE-2026-5888: Uninitialized Use in WebCodecs. Reported by Identified by the Octane Security Team: Giovanni Vignone, Paolo Gentry, Robert van Eijk on 2026-02-22
English
1
0
1
92
Gio
Gio@giovignone·
A couple months back, the team and I were debating what was our most commonly used piece of software. We landed on Chromium. So we wanted to see if we could find live vulnerabilities in it with our AI. Today, I'm excited to share that not only did our AI find a live vulnerability in Chromium – which powers Google Chrome, Brave, Microsoft Edge, and other browsers – but we also found live bugs in Safari and Firefox. You can also find Octane Security in Chrome's latest stable release: chromereleases.googleblog.com/2026/04/stable… Check out the video for the details...
Octane Security@octane_security

Just three engines handle 99.7% of browser traffic. Octane found vulnerabilities in all of them. This is the same security analysis we've used to secure smart contracts. Now we're targeting the mission-critical applications the rest of the world runs on.

English
7
13
66
11.5K
mayank
mayank@exec_mayank·
ultimately, i see security professionals only getting supercharged instead of replaced as an effect of ai. like with many disciplines, human in the loop is the best strategy moving forward.
English
0
0
2
15
mayank
mayank@exec_mayank·
if a competent security professional has looked at your application, you can be reasonably sure all the important threats have been made visible. but if you simply replace the human with ai, you'll always be concerned whether it missed anything.
English
2
0
2
26
mayank
mayank@exec_mayank·
it's true that often times, the ai will find the same bugs as a security engineer. so you may be tempted to simply replace your security org with llms. however, the problem with this is, ai doesn't provide *security assurance*
English
1
0
2
41
mayank
mayank@exec_mayank·
@gadievron thank you for letting me know, i'll cancel my registration and wait for the talks to be released
English
0
0
1
6
Gadi Evron
Gadi Evron@gadievron·
Unprompted update: We’re at 700 attendees live and 300 online. And the people coming range from CISOs to researchers to top level officials. This has exploded beyond anything we could have imagined.
English
6
7
47
11.3K
mayank
mayank@exec_mayank·
@gadievron thank you! is there a benefit to registering for the online version if i won't be able to watch the live events anyways?
English
1
0
1
13
mayank
mayank@exec_mayank·
published my threat modeling notes that i created while preparing for various security engineering interviews, including the one at amazon:
mayank tweet media
English
1
0
0
89
mayank
mayank@exec_mayank·
@george__mack it isn't that simple — everyone knows about computer viruses, but that term does nothing. software is complex, and so is dealing with it. being security conscious with every piece of software is too much work, and humans are lazy.
English
0
0
1
86
George Mack
George Mack@george__mack·
How to fix a $220 billion industry -- with $0 and a reframe.
George Mack tweet media
English
14
12
215
36.3K
mayank
mayank@exec_mayank·
@elidourado 2.4% for march. there's 20 more days remaining in april, i'm sure there will be more things that will offset the inflation increasing tariff concerns you're worried about and it will still go down (or atleast not go up)
mayank tweet media
English
0
0
0
20
Eli Dourado
Eli Dourado@elidourado·
I have mostly come to terms with a deep recession. It’s sad that there will be so much suffering, but my family will be fine. My concern at this point is that there are worse things than a recession, and we may get them. We are playing with fire.
English
9
5
154
7.4K
mayank
mayank@exec_mayank·
@elidourado we'll have the exact number for march tomorrow, but this data says otherwise
mayank tweet media
English
1
0
0
129
chiefpie
chiefpie@cplearns2h4ck·
Claude 3.7 + IDA MCP automatically reverse engineers Windows driver ctf I wrote without symbols(p1, p2). Proceeds to create structures and recreates source code(p3) with extreme accuracy compared to original source(p4). ~3mins fully automated
chiefpie tweet mediachiefpie tweet mediachiefpie tweet mediachiefpie tweet media
English
29
205
1.2K
117K
mayank
mayank@exec_mayank·
@ImposeCost why are we talking about non-repudiation vs accuracy
English
1
0
0
78
mayank
mayank@exec_mayank·
nyu website (nyu<dot>edu) hacked as a protest against illegal racial affirmative action. still hasn't been fixed after 2 hours; hack claimed by @bestniggy
mayank tweet media
English
9
9
95
25.2K
mayank
mayank@exec_mayank·
@0xMatt If you're available for more young people to mentor who are just getting in the cybersecurity industry, I'd love to get advice from you!
English
0
0
0
20
mayank
mayank@exec_mayank·
@qtnx_ rose-pine-moon is great for working at nights
English
0
0
0
69
mayank ری ٹویٹ کیا
Garry Tan
Garry Tan@garrytan·
We pay people well, we want them to win But we are a sports team not a family
English
52
199
1.9K
225.8K