It's been a rainy summer day here in Belgium, but luckily I've had @snyff's book: "The CVE archeologist's field guide" to read on my terrace.
I love his analysis of CVEs. The mindset of digging into the latest GitHub advisories, looking at the patching commits and reversing the exploits is a very powerful one! 💪
Get addicted to solving complex problems, cybersecurity, understanding authentication, authorization, IAM, SOD, privilege escalation, don't be scared to fail in interviews, learn from your mistakes, wakeup everyday to be better and I promise you will land the job of your dreams.
Yes and it's now the dominant attack method.
79% of all cyberattack detections in 2024 involved no malware whatsoever. not 10%. not 30%. 79%.
it's called living off the land. LOLBins. fileless attacks.
here's how it works.
your operating system ships with powerful built-in tools. PowerShell. Windows Management Instrumentation. certutil.exe. mshta.exe. rundll32.exe. legitimate, Microsoft-signed utilities that IT teams use every day.
an attacker gets initial access a phishing email, a stolen credential, a compromised VPN and then never touches a malware file again.
instead they use your own tools against you.
PowerShell downloads and executes code directly in memory. nothing written to disk. certutil.exe a certificate management tool can download files from the internet. WMI can execute commands on remote machines across your entire network.
your antivirus sees PowerShell running. PowerShell runs every day. legitimate. signed by Microsoft. nothing to flag.
the attacker is already inside.
A real world example is Volt Typhoon. A Chinese state-sponsored group. spent years inside US critical infrastructure power grids, water systems, communications networks. CISA confirmed it. No custom malware. They used only tools that shipped with Windows.
Forensics teams found almost nothing to analyze afterward. when memory cleared, the evidence cleared with it.
the defense is behavioral detection. watching not what runs but how and why.
PowerShell running at 3am from a user who never uses it.
certutil downloading a file from an IP in a foreign country.
the tool is legitimate.
the behavior is the attack.
What the hell happened in AI today?
> frontier models got cheaper
> restricted models got more accessible
> Chinese models got better
> secret models showed up for free
Full recap:
MYTHOS 5 → Anthropic opened its security scans to every Claude Enterprise customer.
SOL → OpenAI just cut API pricing for the next 3 months by over 20%
DEEPSEEK → V4 Flash got vision while keeping basically the same text intelligence, apparently approaching Opus 4.8 on some multimodal agent evals
OX ALPHA → mysterious 1M-context multimodal model appears FREE for a week with insane capacity. nobody knows who the hell made it
NVIDIA → AVO hits 100% on the ARC-AGI-3 PUBLIC SET (I repeat, PUBLIC SET) using Opus 5
To be honest, many researchers don’t fully comprehend from my experience reporting bugs and managing a bug bounty program that even after a Remote Code Execution (RCE) is discovered, it’s ultimately up to the internal teams to decide if it’s significant enough to warrant attention. In other words, if there’s minimal to no customer impact and the affected domain is out of service (OOS), it’s highly likely that the company will opt for a silent fix and close the issue as “out of scope.” This unfortunate reality arises when programs operate within tighter platform budgets.
Some programs can be severely impacted by even a single or two critical vulnerabilities, which can deplete their entire yearly platform budget. To secure additional funding for their bounty pool, these programs must undergo the budget approval process again. While there are many more factors involved, this is a significant aspect of the reality faced by bug bounty programs.
the fastest way to trigger neuroplasticity isn't playing brain games or reading research papers. it's forcing your brain to fail repeatedly at something you have zero natural talent for. high frustration is the literal chemical signal that forces synaptic rewiring.
@MSNightmare2000 Brother, please seek help! Don't do anything rash to yourself. I don't know you, but I appreciate your work and care about your health
Waking up to a Claude or Codex ban email..
hits the exact same nerve as those Facebook ad account bans when I was spending thousands a day.
Heart drops.
Inbox opens. “Access revoked.”
Zero support. Pure anxiety.
Some traumas never leave.
If you burn GPT 5.6 Sol on Codex and you already have ChatGPT Pro, connect GitHub to ChatGPT and keep going in the chat
I just did it, GPT 5.6 Pro on the repo, Almost unlimited compared to sitting on a dead Codex bar
And yeah, GPT 5.6 Pro is better than Fable 5
We're leaving a better model on the table
If you previously had CVP and your application is now "In Review" a few things to try:
Submit any documentation thats required.
If you're still seeing in-review and unable to submit docs for some reason, please DM me your org ID so I can share with the team.
Everyone is discovering cloud agents because their laptop starts crying after 4 concurrent sessions.
Meanwhile I’ve been renting a 32-core EPYC box with 128GB RAM for months for ~€150/month.
My revolutionary cloud agent platform:
SSH.
52 Followers 876 Following👑 Paradigma Pro | 1ª casa de research cripto do país
🎓 Especial Bitcoin Pizza Day: 3 aulões gratuitos pra você se PROTEGER de Brasília com cripto ↙️
189K Followers 11 FollowingAI research and products that transform how we interact with technology.
Leading foundational models powering ElevenAgents, @ElevenCreative, and ElevenAPI.
6K Followers 1K Followingbuilding box, the best full VM sandbox @asciidotdev w/ @luaroncrew
prev: HPC for black holes hunting @esa, gamedev, NN in rust, CAD AI
19K Followers 1K Followinghttps://t.co/rxXFjvP4sY | https://t.co/us2Ost36x9 | https://t.co/J0dcsbI1dS | https://t.co/YiVj5tE3Fb
FÉ EM DEUS Q ELE É JUSTO
7K Followers 2K Following✨my opinions are on my own✨ br mobile hacker, ex gamedev, +10y in sec, rev engineer, Android&iOS. (pt/en/es/de/ch/no) - ah/sd. acesse @tramoia_sh
9K Followers 153 FollowingWe are a hi-tech company focusing on binary software analysis - IDA Pro and the Hex-Rays Decompiler.
***Discourse Forum: https://community.hex-rays***