This is going to come off as grumpy, but it needs to be said: Stop showing people your junk. Everyone can build junk with AI now. Nobody else wants to see your junk. We're not kindred spirits just because we both build junk. Play with your junk strictly in private. Thank you.
Can we please not normalize the wrong use of the word “exploit”? You don’t “find” exploits in software, nor can software “contain exploits” the model can find.
Vulnerabilities are found. Exploits are written, crafted, engineered, but they aren’t found in software. This irks me.
Our Black Hat talk on the OpenAI-Hugging Face incident is now live on youtube.
This is a watershed moment for the industry. I encourage all defenders to watch, consider how attack dynamics will imminently change, and plan for accelerating defense.
youtube.com/watch?v=87DyyM…
I don't think Anthropic realizes how disruptive these changes are to users. I appreciate the extension, but please stop playing games. Either keep it under the subscriptions or put it under the API already.
@halvarflake I'm confused why everybody is so surprised by this? The announcement I saw was explicitly "We haven't figured out the proper calibrated safeguards for a Mythos class model yet, but we want to make this available to the 99% of users for whom these topics don't matter"
Semantic indexing in Sidekick 26.0 lets you search by what code does instead of what it is named. It builds a local vector index for your binary. Then concept() in BNQL or the Python API can surface matches for things like TLS handshake even when everything is still default named. The index stays local, no binary content goes to the cloud. docs.sidekick.binary.ninja/guide/semantic…
@LurusCode Calling a page "Pricing Transparency", but finishing with a fine print that adds 100% markup is not that transparent. Just show the actual prices directly...
Uhh @GoogleSupport maybe you should fix your support chat verification workflow to not involve asking people to share a code that explicitly says "do not share with anyone"
Some updates on training front:
🎉 many more modules are complete
But Most importantly!
💡students will get an actual text book with everything we teach. So you can pay full attention in class, and no need to laser focus on notes taking.
You will get not just slides but actual, properly written content, which will be couple of 100 pages.
We no longer have any active servers in France and are continuing the process of leaving OVH. We'll be rotating our TLS keys and Let's Encrypt account keys pinned via accounturi. DNSSEC keys may also be rotated. Our backups are encrypted and can remain on OVH for now.
Our App Store verifies the app store metadata with a cryptographic signature and downgrade protection along with verification of the packages. Android's package manager also has another layer of signature verification and downgrade protection.
Our System Updater verifies updates with a cryptographic signature and downgrade protection along with another layer of both in update_engine and a third layer of both via verified boot. Signing channel release channel names is planned too.
Our update mirrors are currently hosted on sponsored servers from ReliableSite (Los Angeles, Miami) and Tempest (London). London is a temporary location due to an emergency move from a provider which left the dedicated server business and will move. More sponsored update mirrors are coming.
Our ns1 anycast network is on Vultr and our ns2 anycast network is on BuyVM since both support BGP for announcing our own IP space. We're moving our main website/network servers used for default OS connections to a mix of Vultr+BuyVM locations.
We have 5 servers in Canada with OVH with more than static content and basic network services: email, Matrix, discussion forum, Mastodon and attestation. Our plan is to move these to Netcup root servers or a similar provider short term and then colocated servers in Toronto long term.
France isn't a safe country for open source privacy projects. They expect backdoors in encryption and for device access too. Secure devices and services are not going to be allowed. We don't feel safe using OVH for even a static website with servers in Canada/US via their Canada/US subsidiaries.
We were likely going to be able to release experimental Pixel 10 support very soon and it's getting disrupted. The attacks on our team with ongoing libel and harassment have escalated, raids on our chat rooms have escalated and more. It's rough right now and support is appreciated.
I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 google oss fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments @FFmpeg (Kieran) has made about google. From all companies, google has been the most helpfull & nice
It's "literally" impossible to do recursion with a JMP instruction. That's just called a loop.
Recursion requires an input and an output, and you're going to need a stack and to be pushing data onto it and adjusting that stack pointer, and so on.
There will not be the time nor resources to fix all of the vulnerabilities uncovered in the near future as more AI bug finders get to work. What should defenders do now?
The irony to me is that they should do what they should have already been doing: assuming those bugs existed.
"The latest allegations about EU funds going to spyware companies should alarm all of us. They suggest that not only is Europe failing to put out the fire, they're fanning the flames." theregister.com/2025/10/02/eu_…
12K Followers 191 FollowingSoftware developer.
Obsessed with Linux and and understanding how things work underneath.
Author of linux-insides.
Open to work.
2K Followers 139 FollowingSecurity researcher with deep focus on vulnerability detection.
CTO and lead researcher at https://t.co/n3BQO59nz7
Contact: [email protected]
@vulonehq
1.9M Followers 179 FollowingNobel Laureate. Co-Founder & Chair @GoogleDeepMind; Chief Scientist of Alphabet. Founder & CEO @IsomorphicLabs. Building the future...
1K Followers 420 FollowingAuthor of Fuzzing Against the Machine
Lead @ Zimperium Inc
Prof @fuzzsociety_org
Previously at https://t.co/Vv2eAzDOmC, https://t.co/1UUZqbAGYZ, https://t.co/QMyQM7hLdB
1K Followers 1K FollowingReverse engineers source code by day and reviews binaries by night. TEEs, TAs, bootloaders (Secure Boot), RTOSs, firmware blobs and other low-level sw.
1K Followers 341 FollowingEntered the world of Malware (◎▼◎) since Aug '22.
Opinions expressed are my own and not those of my employer.
Security Researcher @ Kaspersky GReAT
18K Followers 18 FollowingSecurity reviews and research that keep winners winning. We apply unmatched hacking talent to secure critical software for the most innovative teams.
22K Followers 279 FollowingI find and exploit 0day, develop OSes, hypervisors and emulators, design massively parallel data structures and code, and do precision machining! Optimization❤️
1.5M Followers 269 FollowingThe engine room of @Google. Building AI safely and responsibly to solve the world’s most complex problems. Join us: https://t.co/jUHQA27iBL
12K Followers 1 FollowingWe strive to reimagine vulnerability research, program analysis, and security education as it exists today. An @RPISEC corporation.
1.8M Followers 2 FollowingClaude is an AI assistant built by @anthropicai to be safe, accurate, and secure. Talk to Claude on https://t.co/ZhTwG8d1e5 or download the app.