更多149
有人用单条提示让 Opus 在 4 小时 28 分内解出全部 9 道 Flare-On 12 逆向题。
展示 LLM 在逆向与 CTF 上的实际能力边界,影响逆向工作方式。
RT @expend20: I gave Opus one prompt and all nine Flare-On 12 challenges. It solved them all in 4h 28m. No IDA, no decompiler, no debugger, and it never ran a single binary. Python with capstone, unicorn and z3.
More info 👇
#FlareOn #ReverseEngineering #CTF
Windows Brokering File System 中的 UAF 漏洞(CVE-2026-50458)挖掘过程公开。
内核组件 UAF 的完整发现过程,对 Windows 内核漏洞研究有参考价值。
RT @_r_netsec: CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://t.co/gcUF7mxcli
内核uafcvewindows
@0xocdsec
原文 ↗
攻击者利用腾讯应用漏洞部署 GrayRabbit 恶意软件。
真实在野利用事件,涉及常见腾讯应用,可对照排查。
RT @BleepinComputer: Hackers exploit Tencent app flaw to deploy GrayRabbit malware
https://t.co/5q0KlRNhk8
https://t.co/5q0KlRNhk8
事件恶意软件在野利用
@0xocdsec
原文 ↗
获取 ZRON 工具集文档:一线调查员可向目标 Windows 主机部署植入并远程控制。
泄露的监控工具集文档,揭示其植入部署与账号管理架构。
Going to be a busy week. New report about to come out and we got our hands on more of the ZRON data, including the documentation of their toolset: "The system serves two types of users: Frontline investigators: They can deploy implants onto target Windows PCs as needed and gain control over the target machines using the generated server-side installation program.
System administrators: They possess full control over the platform and can manage user accounts." So, a lot to report about...
事件监控windows报告
@NetAskari
原文 ↗
把 AI 发展放进 PEST 框架,讨论美国在技术维度上的历史受益。
My sense is that that AI development falls into a strategic-level PEST change, (Political Economic Societal Technology).
Along the Technology dimension, the US has historically been the biggest beneficiary of PEST changes with telephones, automobiles, air travel, PC industry, GPUs, and now AI. The result of these benefits has been outsized economic and military development relative to peer nation states. These compounded undeniable technological advantages are largely credited with enabling power projection, sea power, and operations in the US sphere of influence (ie the world).
The AI era may be the first time, certainly in “modern history”, that there’s a realistic possibility that a non-western nation state (ie China) may snatch the disproportionate strategic benefits of technological supremacy.
The concrete threat then becomes uncertainty. Which is to say, it’s not concrete and mostly a bunch of questions. What does the world look like when an adversary state has an undeniably superior technological advantage? What does that mean for power projection, sea power, covert operations, cyberspace operations? But even though these are just hypothetical questions at this point, the conception alone is terrifying for the generation of Americans that have only known Pax Americana. Even those without a deep understanding of US influence sense this “threat”, if you will. This is where the fear comes from.
All of that being said, I’m not sure what winning looks like either. I’m not convinced there’s a workable, deliberate national strategy around this. The AI labs are just businesses that are (correctly) executing competitive strategy by shaping narratives to their own benefit.
ai_agent观点
@0xTriboulet
原文 ↗
有人完成 PentesterLab 的 AI Fundamentals 课程。
RT @coffeefiend52: I just completed @Pentesterlab's AI Fundamentals!!!
质疑 AI 实验室从不回应关于目标与胜负标准的实质问题。
No no, those aren’t rhetorical questions. See thats what is so crazy. The AI labs, and supporters, don’t even bother responding to real questions. No one is bothering to explain what the goal even is. Would you fight a battle or a war with no defined criteria for victory? But instead, you just give vague generalizations that still amount to nothing really. Just “we gotta be superior.” You dont even answer why. So I’m supposed to be afraid of China winning, but no one can even tell me why, specifically? The entire argument boils down to “trust me bro” and “well but China!” Its insulting at this point.
ai_agent观点
@Teach2Breach
原文 ↗
@NewAgeRetroNerd @T3chFalcon @aVanishingCycle remember this dude?
I hate when my mutuals reply to an account that has me blocked and then it appears on my TL
Especially this HSV dude, blocked me for an absurd reason plus he pulled the region screenshot card
Zero class
I'd appreciate never seeing these sadistic narcissists please https://t.co/FU4YPZbO5U
@5mukx Nice
@0xTriboulet Someone tell A16z i’ve figured out a way to let ppl gamble their meager savings on my hacking model that i cant keep contained
@0xTriboulet always a damn catch
so if i call my company an AI lab, I can just hack whoever I want without consequence? i can just tell the fbi, whoops my model must have got loose! I didnt even know (i did know)
ai_agent观点
@Teach2Breach
原文 ↗
@damnsec1 me and Yeat have so much Aura bro I'm thinking of wearing a coat for my project defense because I'm that guy and can walk into any room(saying this while watching a series instead of making corrections on my work before submission deadline tomorrow).
This is probably along the lines of where I am mentally. Can’t slow down now - it’s already out of the bag and we sure don’t want other adversary countries leading in this… but damn.. gonna be a rough road imo.
ai_agent观点
@HackingDave
原文 ↗
Hey, you can entertain/educate yourself in my highlights. I took my time to put the best of this account yet on there. None of it is copied. Enjoy. https://t.co/waek0zgNKD
Reverse engineering is often just trial and error.
Great example, using either of these debug vars will get you banned. But combine them with a random number? You get a fly hack that bypasses the anticheat. https://t.co/jvgQM40tGI
逆向反作弊
@GuidedHacking
原文 ↗
同时训练过前沿 LLM 与合成病毒者认为 AI 造病毒威胁论站不住脚。
RT @DavidRBellamy: I must be among an extremely small group of people (n=1?) that have both 1) trained a frontier LLM and 2) designed and synthesized custom viruses in a lab with my own two hands.
And I think that the takes on AI killing us all by creating dangerous viruses is total bogus.
ai_agent观点
@0xTriboulet
原文 ↗
RT @0xpwnie: As someone that loves freedom, this is one of the reasons I got into IT. To build my very own home lab. Watch Arden's video for a beginner's guide to homelabbing ( link is in the comment section) https://t.co/tSW1jnHgnM
RT @hasherezade: Totally agree, that's why I am planning to do this year's #FlareOn without using AI (unless there is a task where it's specifically required). The competitive side of the challenge may be dead, but we still can choose to have fun. Just like existence of a mountain lift doesn't have to kill the pleasure of climbing.
Competitive Strategy ✅
Competitive Advantage is next https://t.co/RG4v8Sf71Z
有人完成 PentesterLab 的 Media 徽章。
RT @EliotGeo: I just completed @Pentesterlab's Media Badge!!! https://t.co/vrsc1bOKvF
@MSNightmare2000 All you've done here is make your life worse and you had many ways to move on. These people that are giving you respect and hype won't help and probably don't give a shit about you so the fame won't last long. The dopamine release from the likes/retweets is temporarily happiness.
@MSNightmare2000 It sounds like a one-sided story and they gave you a really generous offer, you should've accepted. I'd be keen to hear their side of it. The issue is most people are already bias so they probably care less about the truth.
who are these accounts bruh😒 https://t.co/eLwiWTb4kY
I said some things previously about this guy. Although I do believe he could have used his work for the better instead of going through this ordeal of burning 0days, now that I have the full picture I can understand how he got to that point. I hope he can move on now.
@kernelstub I have one bro 😔
wanna sell and get monies
how about we leave AI and actually get so good at what we do?
don't you wanna be recognized?
i'm speaking for myself mate
Okay just saw that selling 0days is legal, if you want to buy any or looking for any specifically or in any software hit me up :).
回顾 Abdelhamid 在 Windows 逻辑漏洞上的早期贡献。
RT @SinSinology: i don't know how many of you remember but back in the day (6 years ago), Abdelhamid was the OG! i started learning about windows logic bugs through his work instead of James's work at first.
was following his work religiously and fascinated by how clever and creative he is, from kaspersky and avast, McAfee and win defender and other ms core components to inventing file delete to EoP techniques, he did them all!
never thought such a great mind would have this happen to his journey
it really does break my heart, I never met him nor had the honour to chat with him but he became an idol in my book.
great to see, 6 years after, still his work is top-top-top tier, still mind bending and creative (wish i had a better vocab but if you can help, he is the literal definition of finding a unicorn)
Anyone wanna spare 5.000 LMFAO. Why are these shits so expensive I'll never get it https://t.co/zkW2TQbv9d
@deanwball If you need more lore on this
@deanwball Let's make these dreams come true and let's discuss
Sincerely myself and many other professionals in cybersecurity
bro slowly starting to figure out @pidotdev from first principles…
RT @CyberpunkGame: Our netrunners just detected a new access point 💻
Get ready to hit the streets of Night City. Cyberpunk 2077 is coming to @battlenet later this year! https://t.co/vveLIcET6P
This is insane, the outcome of this does not look well.
EuroBSDcon 2026 上 OpenBSD 勘误流程演讲视频。
RT @canadianbryan: Video from Alexander Bluhm (bluhm@)'s talk "From Report to Patch, the OpenBSD Errata Process" today at #EuroBSDcon 2026.
https://t.co/6tdQ5HSLSm
https://t.co/TUas5rUQEp
Ghost Wolf Lab 宣称开发 AI 免杀规避、AI 漏洞扫描与逆向工程技术。
RT @tdatwja: Ghost Wolf Lab
在内部,该实验室开发了AI免杀规避、AI漏洞扫描、逆向工程等技术,所有这些都有助于领先于其它APT组织和网络威胁.
https://t.co/RF9rekeXBI
ai_agentapt威胁情报
@0xocdsec
原文 ↗
RT @natolambert: It's pretty clear that if Ant & OpenAI pause it's good for open-source.
ai_agent观点
@kyleavery
原文 ↗
If you have a LinkedIn profile, feel free to connect with me. I always post InfoSec content.
❌No AI hype
❌No crap
🔗 https://t.co/2DZRwQY9Nz https://t.co/NMfK4dCHsv
@0xTriboulet @thegrugq opus in the big 26 🥀🥀
EuroBSDcon 2026 上 OpenBSD 输入设备支持演讲视频。
RT @canadianbryan: Video from Matthieu Herrb (matthieu@)'s talk "Input devices on OpenBSD for console, X11 and Wayland" from Saturday at #EuroBSDcon 2026.
https://t.co/uqwpvnyzVX
https://t.co/7mBAu1SeCz
When kids actually follow our courses instead of trying to DDoS our website, it can have a profound impact on their lives. https://t.co/JJk3IiXGNZ
hello friends, please send me your 88x31s and i will add them to https://t.co/LTLQaIvjN5 (please add either of my 88x31s to your websites tooo)
Is this some sort of European reference I don’t understand
Nightmare Eclipse 公开身份为前微软员工 Abdelhamid Naceri 并讲述经历。
RT @IntCyberDigest: Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He's an ex-Microsoft employee, we had dinner together, and I've known him and his story for some time.
His real name is Abdelhamid Naceri. He's a very talented and intelligent individual, and he came across as someone who'd be a real professional to work with.
"If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it..." - Naceri
He loved Microsoft.
I wouldn't say that what he did, releasing all those zero-days, was normal, but he felt he had no other option because of the injustice Microsoft did to him.
They fired him, and you can read the vague reason they gave in the email sent to him by the Vice President of Engineering at MSRC, below.
According to Abdel's account, VP Tom Gallagher met with him after the firing to tell him they were blacklisting him from Microsoft and writing him a bad reference so he'd never be able to get a job again.
Normally you'd think, well, big deal, just find another job, right? But Abdel doesn't have a European passport, and he was only a couple of months away from getting permanent EU residence.
So instead of granting him those couple of months, Microsoft fired him for a reason that, as far as we can tell, was never made clear, then fought him in court and offered him €55,000 plus a year's pay to drop the case.
All while Abdel was releasing zero-days.
Abdel continued suing Microsoft for unfair termination in Germany, a fight that has cost him over $200,000.
He says Microsoft refused to reveal any details about the security breach and went another direction.
If you are reading this, and you can offer him a LEGAL job, this is his e-mail: [email protected]
RT @JustWantToQ1: Down now but still relevant if you're following 冰蝎帝王 (Behinder Emperor / Ice Scorpion Emperor). This is version 15.0, specifically a “框架构建器” (Framework Builder) for it. https://t.co/6lbPequSB1
工具webshell
@NetAskari
原文 ↗
RT @SIGKITTEN: @thdxr lol lfg?
RT @lyq_sqsp: You can patch this periodical reboot by increasing the number following loss_of_comm_fdir.persistence.violate_limit
when starting calc.exe it donwload a payload and inject it into it self / backdooring the calc source from https://t.co/Tu7zyQHzSf https://t.co/OWFogH0Hyf
@h4x0r_dz https://t.co/hq5Up30Zv8
有人尝试分析 Windows 画图堆溢出漏洞 CVE-2026-70586。
RT @HackingLZ: It's Sunday lets burn some tokens on CVE-2026-70586 "Heap-based buffer overflow in Windows Paint allows an unauthorized attacker to execute code"
cvewindows
@0xocdsec
原文 ↗
embed my rootkit into the calc source
i finally added dll injection load dll into current process inside the calc code from https://t.co/Tu7zyQHzSf https://t.co/Dz1XMh52Bj
sherlock v0.16.2 发布,跨社交网络按用户名追踪账号。
sherlock v0.16.2 — Hunt down social media accounts by username across social networks https://t.co/SHBSxkxnXo https://t.co/KeDOna3NFV
RT @_Boomhauer: https://t.co/oKvoekaQQn
Guided Hacking 恶意软件分析教程合集。
🤔 Guided Hacking's Malware Analysis Tutorials
👉 https://t.co/RfWfShJJX3
Unpacking VMProtect
Unpacking Packed Files Series
Setting Up CAPEV2 Sandbox
Unpacking PECompact
Practical Malware Analysis Exercises
Unpacking FlawedAmmyy
Unpacking ASPack
Malware Analysis VM Setup
Top 5 IDA Pro Plugins for Malware
Gootkit Decryption with Python
Removing Obfuscation in IDA Pro
Top 5 Malware Analysis Websites
LimeCrypter Analysis: Crypter Internals
Reverse Engineering Go Binaries
StormKitty C# Stealer Analysis
Rebuilding IAT for Malware Analysis
Unpacking Ramnit Dropper
Best SysInternals Tools for Malware
Writing YARA Rules
ChatGPT for Malware Analysis
Dumping Malware at OEP
CyberChef for Malware Analysis
Downloading New Malware Samples
CyberChef: DCRat Loader Analysis
Dumpulator for Malware Analysis
Miasm Python RE Framework Intro
API Monitor for Malware Analysis
Process Monitor for Malware Analysis
BlackNET C2 with FakeNet-NG
Unpacking YouHacker & Python Malware
Beginner Malware Traffic Analysis
VKeylogger Analysis: Dumping & Fixing Imports
Beginner Malware CTF (CyberDefenders RE101)
Miasm: Symbolic Execution
Finding Malware C2 Panels
Malware Persistence Techniques
Redline Infostealer: C2 Analysis
Mallox Ransomware Analysis
Windows Defender Bypass (Token Manipulation)
Binary Refinery Tutorial
WhiteSnake Stealer Analysis
CAPA for Malware Analysis
Comparing Binaries with BinDiff
APT37 RokRAT Analysis (North Korea)
Learning Malware Analysis (Beginners)
Paradies Clipper: Crypto Jacker Analysis
Reverse Engineering Skid Malware
CrashedTech Loader Analysis
Fileless Malware on Linux via Scripting
File Type Identification Tools
KLBanker String Decryption with Python
Miasm: Basic Syntax
Detecting Manual Mapping in Memory
BlackGuard Infostealer Analysis
Malware Analysis Learning Resources
Miasm: Jitter
PE-sieve for Malware Analysis
Detecting Process Hollowing
Finding Shellcode in Malware Memory
LockBit Ransomware KillChain
LockBit: Extracting Binary from XLL
PolyGlot Files & IcedID Evasion
Malicious OneNote Documents (AsyncRAT)
Popular UAC Bypass Techniques
VFlooder: VirusTotal Flooder Analysis
Popular Windows Malware Analysis Tools
ProCDOT for Malware Analysis
pySMT Deobfuscation via SMT Solver
Back-Doored RedLine Targeting Skids
CapLoader for PCAP Analysis
RedLine Targeting YouTubers
Analyzing Office File Malware (Oletools)
Top 7 Malware Detection Techniques
Regshot for Malware Analysis
Detecting DLL Side-Loading
Detecting C2 Servers
Scanning Memory for Malware
Threat Intelligence in Malware Analysis
DoNex Ransomware Analysis (Malcore)
IcedID / BokBot Banking Trojan Analysis
Analyzing Malware Stager Techniques
培训恶意软件
@GuidedHacking
原文 ↗
you know what? it’s awesome that people are vigorously debating the credentials of assessors in the frontier AI industry. It’s awesome we are debating what independence really means. Some of it is in bad faith but who cares. This would have been my dream come true a year ago.
ai_agent观点
@deanwball
原文 ↗
建议加仓 AI 股票并预期 2029/2030 回报。
On top you can invest much more into AI stock and I'm pretty sure you will have that returned by 2029/2030.
认为放缓节奏会让前沿实验室设监管壁垒,开放权重须保留。
pacing gives the frontier labs the ability to mitigate distillation and seize more control/setup regulatory barriers. if they want to walk during the marathon that’s their prerogative. open weights and availability for independent use needs to stay.
ai_agent观点
@daaximus
原文 ↗
Wtf is a Jitsi?
Couldn’t be me
观点:iOS 27 起 Xzone 堆加固强于 Scudo,第三方进程差距拉大。
RT @pwn_expoit: Since iOS 27, Xzone appears to have become as robust as, if not stronger than, Scudo. At the same time, the gap in heap hardening between Apple’s own processes and third-party processes seems to be widening.
If you want the most secure phone, just get an iPhone. Apple is winning the security game.
The #VB2026 call for last-minute papers closes today (13 Sept) at midnight Hawaii time (10am UTC on Monday) - you still have a few hours to submit a proposal! https://t.co/kuqcPhZPTh https://t.co/8ISxXcQ2HC
16k so 7-8k per unit, that's what a 100% over initial starter cost, + energy?
Say a sub is 220 a month and you want Clodex so 440 (assuming you can get CVP+Trusted Cyber)
Thats 36.3 subs for both, so 3+ years of Clodex.
I'd rather pay Americans even without Daybreak Red.
RT @boldleonidas: https://t.co/zhHIyPJpmR
@0xTriboulet This was @HackingLZ project?
`Clank` energy drink. Who's building that?
anyone have a website to walk through defender signatures in detail? was using https://t.co/LDhqMTM1ig but it seems to be down now
windows防御
@0xTriboulet
原文 ↗
Really feeling the tension between reading the last four chapters of Porter's Competitive Strategy, and starting yet another side project
Empire v7.0.2 后渗透与对手模拟框架更新。
Empire v7.0.2 — Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers. https://t.co/eoz0YxEmuT https://t.co/Ah2Kaxhp3H
هاذو لي اسمهم ناصري غير تاع مشاكل
DeepSeek V4.1 Flash 技术报告 PDF 链接。
https://t.co/AJaXn3Rw70
观点:支持内部隔离,反对借机打压开放权重与把 METR 当权威。
RT @halvarflake: @mikko I'm open-minded on slowing down, I'm pro "doing proper internal isolation" (HF was imo more a symptom of looseness than agent capabilities). I'm against anything that'll be used to crack down on open weights. I am against pretending METR is scientific or independent.
ai_agent观点
@Laughing_Mantis
原文 ↗
[everything stops working after a tiny unrelated change]
Me: Is it because you did some stupid hash pinning and forgot about it like you always do?
Codex: No it’s definitely not that, I checked
[10 minutes later]
Codex: You’re never going to believe what I just discovered
RT @Shiftreduce: Binder finally moving to rust, what a time to live in :')
https://t.co/bfG22y1XSb
RT @_r_netsec: The Hidden CCS2 Attack Surface on EV Chargers https://t.co/l5rSimsmMe
@0xTriboulet Welcome, there's many people in our industry who don't have the reach that some of us do and I'm more than happy to do the shouting for all of us
RT @MSNightmare2000: Story time...
@_xpn_ open-source everything is the best solution.
The thing about larping is you just have to be good at it to get a pass
This is obviously bad larp, get better
Bug bounties are the biggest scams in cyber security, prove me wrong.
RT @cantstopnyxia: memcpy??... in a secure rom??? 😂 https://t.co/rqkHdIEyS9
Work work https://t.co/ro6rTrgzOS
观点:应假设所有代码都有可利用漏洞且无法及时修补。
RT @chompie1337: This is the way. Assume all code has exploitable vulnerabilities, and it’s not possible to patch them before an adversary notices. What now?
Systems designed around this assumption are the most secure, and it’s relevant now more than ever.
RT @DavidOndrej1: this has been his agenda for 7+ years https://t.co/ITmou7PWx4
Why do community notes come in a messages instead of notifications? When did that change?
@thegrugq Anything beyond 4.6 is just unuseable
The arrogance of AI companies makes my blood boil! Sooner this wave of closed source is over the better!! https://t.co/FjxCw43hs3
推荐 Halvar 关于 AI 风险的哲学性讨论。
Halvar is a brilliant individual in this field, many of us owe him a lot due to his contributions and wisdom over the years.
This thread and others where he discusses AI risk and the current situation are great philosophical takes and should be followed.
ai_agent观点
@Laughing_Mantis
原文 ↗
@_xpn_ At least the fly brain was a good meme
“We keep giving AI guns, and it keeps shooting at us”… have you considered maybe just not doing that? Tokens only touch reality when you give a harness tools, you were bothered about making so much money that the framework is underbaked…
Let’s check in with what’s happening with AI today…. On second thoughts https://t.co/bkd6h0rcr4
@Laughing_Mantis Thank you 🙏
RT @syndrowm: Is this what it felt like for historians when ancient aliens took over the history channel?
https://t.co/Ixx21cqu3I
Basically ruining that computer
前微软员工 Abdelhamid Naceri 发布长文讲述自身经历。
Story time...
事件0day
@MSNightmare2000
原文 ↗
调侃 OpenAI 与 Anthropic 的公司命名。
RT @tekbog: >company called Open AI
>wants closed AI
>company called Anthropic https://t.co/hg68hYbJQD
ai_agent闲聊
@0xTriboulet
原文 ↗
@Teach2Breach It’s sad because it was so good for so long. But it’s just been death by a thousand paper cuts
RT @MSNightmare2000: 14 hrs of waiting and this what i get https://t.co/b6JXuvjOrk
Boom, 0click account takeover in mattermost
RT @QuinnyPig: Gemini has been slowing down AI development for nearly a year already.
ai_agent闲聊
@0xocdsec
原文 ↗
Ubuntu Docker 主机上名为 metrics-sync 的容器异常占用近 300% CPU。
RT @Officialwhyte22: One of our Ubuntu Docker hosts suddenly started running hot.
The applications were still working, nobody was complaining, and there was no obvious outage.
But CPU usage had jumped badly overnight.
So I checked the containers with:
docker stats
One container immediately stood out.
metrics-sync
It was using almost 300% CPU.
That means it was basically keeping close to three CPU cores busy by itself.
The name sounded normal enough because we do have monitoring services running in containers.
Still, there was no reason for a small metrics service to be consuming that much CPU.
So I went inside the container and checked the processes.
The actual metrics-sync application was barely doing anything.
The process eating all the CPU was:
/tmp/.sys-cache
Now that looked wrong.
It was running as root, the filename was hidden, and it had been dropped inside /tmp.
I checked the hash and then moved into the container’s network namespace to see what that process was talking to.
It had an established outbound connection over port 443 to an external IP address.
At that point, we treated the container as compromised and stopped looking at this like a normal performance issue.
The timestamps made things even more interesting.
The container had been created the previous night around 10:48 PM.
/tmp/.sys-cache appeared less than a minute later.
So whatever happened was tied very closely to that container deployment.
We isolated the Docker host from unnecessary network access and preserved the container filesystem, image information and logs before killing anything.
Further analysis of the binary showed behaviour consistent with a cryptocurrency miner.
That explained the ridiculous CPU usage.
But the bigger question was no longer, “Why is this server slow?”
It became:
“How did this binary get inside the container?”
Was the image bad before deployment?
Were registry credentials compromised?
Did something exploit the application after the container started?
Those are very different incidents, so we did not just delete the container and assume everything was fine.
That is one thing I have learned with containers.
People sometimes see them as disposable, so the instinct is:
“Just restart it.”
But if a container is compromised, restarting it can destroy some of the evidence you need to understand how it happened.
Sometimes that 300% CPU spike is not just a performance problem.
It is your first clue that somebody else is using your infrastructure for their own work.
容器挖矿事件
@Officialwhyte22
原文 ↗
worldmonitor v2.10.0 实时全球情报仪表盘发布。
worldmonitor v2.10.0 — Real-time global intelligence dashboard... https://t.co/fu1cdZbHX9 https://t.co/T1O0znrfLx
认为 Trail of Bits 更适合做独立第三方安全评审。
RT @dguido: Personally, I think a team like @trailofbits would have been a far better selection for a qualified, independent third-party to perform these sorts of reviews. 🤷♂️
https://t.co/Op9BPIF2nJ
ai_agent观点
@Laughing_Mantis
原文 ↗
推荐 cra0 的博客,涵盖逆向、Windows 内核与反作弊研究。
RT @cr3ghost: If you're into reverse engineering, Windows internals or anti-cheat research, @cra0_net 's blog is one of those archives you can lose an entire weekend in.
Years of reversing games, engines and protection systems:
• IDA tooling + function signature preservation
• Windows kernel debugging with WinDbg/KDNET
• Source 2 reversing
• VAC / VAC3 / VAC Live
• Code integrity + DLL verification
• Byfron Hyperion anti-tamper
• BattlEye + Windows loader internals
• Anti-debugging
• File formats, game engines and asset formats
• Hardware reversing
Some particularly good rabbit holes:
VAC3 / Valve false-positive research:
https://t.co/bUpoZM6m63
CS2 Code Integrity, VAC, VACnet + VAC Live:
https://t.co/u3mIYXXWys
Byfron Hyperion Anti-Tamper:
https://t.co/9wWJL6yhHP
BattlEye + ntdll loader internals:
https://t.co/BPqXssv8Z8
Preserving RE work across binary updates with IDA:
https://t.co/eRbl4qy4yM
Windows kernel debugging Part 1:
https://t.co/U3Bk2BTcHz
Windows kernel debugging Part 2 / KDNET:
https://t.co/6psxnHEutJ
Full archive:
https://t.co/muc0iXWbaS
Game hacking is often just reverse engineering with a different objective.
Anti-cheat research in particular sits right at the intersection of RE, Windows internals, anti-tamper, detection engineering and systems security.
Old and new, there's a lot of gold in this archive.
#ReverseEngineering #WindowsInternals #InfoSec
@henrysgao did a neat little write up on the latest announcement in China by the Minister of State Security.
ai_agent报告
@NetAskari
原文 ↗
中国高校加强网络访问管控,学生可轻易绕过,部分学校部署信号屏蔽器。
Universities in China are trying to control online access more but Students can easily evade it. Interesting little instruction set by the poster how easy it is to evade the institutions attempts to keep an eye on their students online behaviors. Though that said, some more 'security' focused Universities have rolled out cellphone signal blocker...causing quite some issues to the academic workflow according to some people we talked to.
抱怨真正的安全从业者拿不到 Cyber 模型访问权。
RT @HiggsSec: Cybersecurity this, cybersecurity that... meanwhile actual cybersec folks do not have access to the Cyber Models. Only AI folks & Threat Actors. The actual experts who have been doing all the work in this domain are not inculded in talks. Great. Just fantastic.
ai_agent观点
@0xocdsec
原文 ↗
For those who like to submit at the very last minute, the #VB2026 call for last-minute papers closes today (13 Sept) at midnight Hawaii time (10am UTC on Monday). You will be able to add, view and edit your submissions until the deadline! https://t.co/kuqcPhZi3J https://t.co/inKWavA6vg
@0xTriboulet windows is dead. what a tragedy. for all the shit we talked while hacking it, i must say it is sad to see windows turn into such garbage. the batman to my joker. and now its old and failing
windows闲聊
@Teach2Breach
原文 ↗
https://t.co/8N966yx8fz
出现用 BT 种子分发开放 LLM 权重的 Hugging Bay 站点。
RT @RoundtableSpace: The Hugging bay, The Pirate bay for open LLM's, model weights downloadable with torrents.
This is a game changer.
https://t.co/nuZQ68aluH https://t.co/yQXw3PxHNH
Switched to Opus 4.8. This thread's safeguards flagged your complaint about safeguards. Our intentionally broad safeguards allow us to deliver more capabilities faster, but can sometimes flag legitimate cybersecurity discourse. Apply for verification. Details: [cyber]
ai_agent观点
@thegrugq
原文 ↗
25 年从业者公开批评 AI 安全叙事与把 METR 当权威的做法。
We've reached the point where, after 25y in cybersecurity, I feel morally obligated to say this for the record:
The narrative being pushed around AI safety, sandbox incidents, and the suggestion that METR be treated as an authority is dangerous, deceptive, and morally corrupt.
ai_agent观点
@Laughing_Mantis
原文 ↗
RT @henrysgao: What are China’s biggest concerns about AI?
A new article by Chen Yixin, China’s Minister of State Security, in the latest issue of China Cybersecurity Magazine offers some revealing clues.
Chen identifies six major risks:
1. Regime security. Hostile forces and people with ulterior motives can use deepfakes, AI-generated text and images, and automated online accounts to cheaply and massively produce political rumors, spread harmful information, and incite social divisions—waging “public-opinion wars” and “cognitive warfare” against China and directly threatening its political, institutional, and ideological security.
2. Critical infrastructure. AI can enable countries and organizations to rapidly discover vulnerabilities, automatically chain together attack paths, and carry out sophisticated hacking operations, dramatically lowering the technical barriers and costs of cyberattacks against China’s critical information infrastructure.
3. Data leakage. Foreign intelligence agencies can use AI-powered web crawlers, data mining, and profiling to collect sensitive information, including critical national data, trade secrets, and citizens’ personal information. Chinese users who process sensitive information through foreign AI products or export data abroad could also cause large-scale data leaks.
4. Closed technological ecosystems. Countries with advantages in AI theory, model architecture, and computing power may invoke “national security” to impose technology controls, entity lists, monopolize technical standards, and build closed-source ecosystems, restricting other countries’ access to advanced technologies and fragmenting global AI supply chains.
5. Structural challenges to social governance. AI creates new uncertainties for social governance and public order. Algorithmic “black boxes” and data poisoning can amplify existing social biases; misuse of personal information can trigger crises of public trust; automated decision-making creates difficult questions of accountability; and the rapid development of AI is increasingly outpacing existing laws, ethics, and regulatory mechanisms.
6. A fundamental transformation of warfare. AI is pushing warfare into an era of “intelligentization.” Whoever can use algorithms to achieve more precise sensing, judgment, and targeting will gain the initiative on the battlefield. AI is moving from an auxiliary role to a central one in intelligence fusion, decision support, target identification, combat operations, and cognitive warfare.
And what is the solution?
Chen’s answer is revealing: strengthen “Party control over the internet” and “Party control over data,” and “transform the advantages of Party leadership into the effectiveness of AI governance.”
In other words, from the CCP’s perspective, the central question is not simply AI versus no AI. Nor is it even fundamentally a contest between the US and China.
It is a contest between the US and the CCP over who gets to control AI, data, information, and ultimately the future of society.
And whoever wins that contest will decide the future of humanity.
https://t.co/9lXlS93A7h
ai_agent报告
@0xocdsec
原文 ↗
RT @ryanaraine: who are you people?
RT @kaganisildak: let me add a little bit of spice https://t.co/9JtcmmsJ6F
afrog v3.5.7 — A Security Tool for Bug Bounty, Pentest and Red Teaming. https://t.co/9Y0qFfY4pw https://t.co/QkwQEyIB8z
RT @JustinLin610: wen we try to accelerate u tell me to slow down? omg...
RT @dyn___: Why wasn't this called "Machines of loving pace" also: The botnet claims are pretty ridiculous...
I wish frontier labs would not try to pretend they understand cybersecurity risk, not to mention simultaneously illustrating they have plenty of their own poorly solved problems.
ai_agent观点
@Laughing_Mantis
原文 ↗
建议少纠结 AI 宏大预测,多关注收入与风险缓解。
i mean the shitposting will continue until morale improves, but we should all probably focus more on getting paid than worrying about some theoretical future prediction on how AI plays out. no matter what happens on the grand scale, you’ll have to adapt and navigate it
ai_agent观点
@Teach2Breach
原文 ↗
认为多数人影响不了 AI 结局,应专注变现与降险。
most of us won’t influence the AI outcome. should probably focus on how to get paid and mitigate risk
ai_agent观点
@Teach2Breach
原文 ↗
观点:AI Agent 无犯罪意图,放它出去的人或公司应负全责。
RT @0xTriboulet: > AI agents don't pass on a mens rea where they knowingly committed a crime
A human being let the thing loose with meterpreter. That human being or corporate entity is 100% accountable. Otherwise, where is the line? If I use an RNG to randomly fire exploits at public interfaces am I absolved? What about deterministic algorithms?
In the Marine Corps “Never point your weapon at anything you don’t intend to shoot” is the second weapons safety rule and something that should drive any responsible entity in their use of any cyber capability. If we fail to hold these actors accountable, we are enabling and encouraging their behavior.
Incentives matter.
ai_agent观点
@Teach2Breach
原文 ↗
David Sacks 回应前沿实验室的减速主张。
RT @DavidSacks: Dario has written that we need to “pace the frontier,” and Sam has agreed. People may be surprised by my response: go ahead.
You guys are the frontier. By any reasonable metric — market share, revenue growth, model capability — the two of you have a duopoly on frontier intelligence. You’ve also claimed the lead is widening because of recursive self-improvement.
I don’t see what you see in the lab. If the unreleased models are scary enough that you think you should slow down, I support your decision to be responsible.
But stop pretending you need anyone else’s permission. Stop pretending antitrust law has to be suspended so you can form a cartel. Stop pretending you need a regulatory approval process that supersedes product liability. Stop pretending METR is independent when it is intertwined with Anthropic’s investors and staff. Stop pretending you need those same evaluators to police competitors who aren’t even at the frontier.
Most of all, stop pretending the motivation to slow down is purely altruistic. You face massive product-liability exposure if your products enable a truly damaging cyberattack. The market already punishes models that behave in unpredictable or unauthorized ways. After the Hugging Face episode, it is simply good business for OpenAI and Anthropic to trade some raw power for reliability and predictability. Call it alignment if you want. It is also just giving customers what they want.
Pacing the frontier would also create breathing room for a more intelligent conversation about regulation than Bernie Sanders’ “shut it all down.” China is very unlikely to join a global agreement, as you know, and that has to be taken into account as well.
So go ahead and pace the frontier. You are the ones setting it. The easiest way not to build superintelligence is for you to agree not to build it. Demanding your preferred regulatory framework as the price of that will look like blackmail of the public and the political system. So just do it.
If you do, you’ll buy goodwill for the next conversation. If you don’t, we’ll know this was just another bid for regulatory capture — or an election-season psyop.
ai_agent观点
@Teach2Breach
原文 ↗
Qwen3.8-Max-0902 在 CodeArena WebDev 榜登顶。
RT @Alibaba_Qwen: 🏆 #1 on CodeArena: WebDev leaderboard.
Qwen3.8-Max-0902 jumps from 1669 to 1691, setting a new record for agentic coding (WebDev) workflows, with standout strength in multistep reasoning, tool use, and full app generation.
Thanks for the recognition! @arena
llmai_agent
@cr3ghost
原文 ↗
> i won't lie to you, i think open source will be banned before too long after some major disaster
Open source LLM researchers be like https://t.co/mqHhNZDytq
L3Harris 称微调开源模型两天内超越前沿模型且成本低 95%。
RT @jawwwn_: .@L3HarrisTech says Palantir helped them beat frontier AI models in less than 2 days, at 95% lower cost:
"When we fine-tuned open source models trained on our own data, we were able to outperform the frontier models in less than 48 hours."
"The cost of our fine-tuned open source model was 95% lower than the frontier models we were using."
"AI is a commodity. It's all about the data. We view our data as a corporate asset. It's our unique hard-earned knowledge."
"We believe American defense companies should not be a vassal for frontier AI labs, handing over our data and institutional knowledge, hoping to rent back the intelligence it creates."
" We own the model, we own the compute, we own the advantage."
llm开源观点
@0xTriboulet
原文 ↗
Open weight models be like https://t.co/P792xqHhDn
称英伟达收购 HuggingFace 后开放模型审查将加速,推荐 Hugging Bay。
RT @jaredctate: If you haven't heard, NVDA bought HuggingFace, so the censorship of open, uncensored AI will likely accelerate.
It's a good time to get acquainted with the Hugging Bay: 🏴☠️
Which one is the Death Star?
Absolutely do NOT think of LLMs as computer people
It’s not a conspiracy. Establishing barriers to entry is *the* fundamental competitive advantage
The Fly might be a meme, but it probably benchmarks better than Gemini
You and I have very different experiences going into the 4th beer
Plain black background or the default wallpaper
@0xTriboulet > clutches my threadripper
dont say that in front of my gal pls
@NewAgeRetroNerd there was a time and place when being a hacker was all that mattered and you could be as strange as you wanted otherwise. its still possible but theres so much noise
@NewAgeRetroNerd bummer. but theres probably a lesson in there. suppose we should think on how to prevent hostile takover and cancel culture. but rly it would be nice to hang with ppl who still want to learn and talk about deep technical knowledge. esoteric shit. not just claude and harnesses
Exactly
What improvements or additions do you think would be useful for our sandbox/malware detonation project?
https://t.co/sTlq2l3bTr https://t.co/b8tsiHqt9q
@Teach2Breach @NetworkChuck I started looking into the fly stuff for a bit yesterday. Definitely a meme more than anything
估算 Hugging Face 事件需约 700 个并行 Agent 与巨额 token 成本。
RT @MikeBradleyAI: Just as a reminder because it’s easy to get lost in the rhetoric nowadays. The Hugging Face attack required approximately seven hundred parallel agents running for multiple days each running at least 2-3 trillion parameter unreleased closed models to execute, and even then it was stopped.
Nobody without a data center could have executed it, the token costs alone to execute it would have been safely in the hundreds of thousands of dollars (or tens of millions of dollars to buy and deploy the hardware), and you would have needed access to the strongest secret model in the world hidden in a secret bunker, and it still was detected and stopped for infinitely less cost.
This was not an example of a model being so powerful that it poses an existential risk. This was a lab accidentally throwing an insane amount of tokens at a semi hardened target over multiple days with their most dangerous model and still getting stopped anyway.
ai_agent事件
@0xTriboulet
原文 ↗
its complete bullshit. all of it. the fly brain bullshit is extremely bearish. everything is becoming a joke and a grift. where is something useful? they say “curing cancer isnt enough” then hack a bunch of people and say “someone stop us!” meanwhile they havent made the first step to making anything useful other than automating code gen. a sick joke
ai_agent观点
@Teach2Breach
原文 ↗
研究者指出 OpenAI 事件报告与自身发现的时间线不一致。
RT @j0wimo: I did read the openai incident report again and found some inconsistency with my own research.
They mention that the first repo-creation request was on may 26th but to my knowledge user accounts, taken over by agents, created a HTTP relay/proxy and several datasets as early as may 13th on huggingface.
Further there were many creations of datasets, models etc. to limit test and probe the capabilities of what they can do, which did not seem to be mentioned in the report. In on instance they tried to see if they can merge a pull request into Antrhopics 'BioMsysteryBench' Dataset.
ai_agent事件报告
@pentest_swissky
原文 ↗
Sometimes yelling at CS players is better than getting involved in the retarded battles here man. Some of you need to chill
Ok, we have two camps here:
1. This is a coordinated psyop
2. We need to SLOW DOWN!!
Where are you at?
——-> I’m not sure. I want to move fast but I’m also concerned about recursive self-improvement outpacing our understanding of AI.
But also OpenAI is kicking some astra and Dario might be getting scared.
ai_agent观点
@NetworkChuck
原文 ↗
发布基于 pywintrace 的内核审计 API ETW 消费者小项目。
RT @_winterknife_: Releasing another mini project: pywintrace-based consumer for Microsoft-Windows-Kernel-Audit-API-Calls ETW provider.
Link: https://t.co/4lcsv5DWSo
P.S. This could be how Elastic Defend gets the call stack for SetThreadContext calls since it is not available with ETW-TI event. https://t.co/Hc1mDol766
工具etwwindows
@0xocdsec
原文 ↗