Offensive R&D Lead • Hacker • Advisor • Speaker Founder HackerMinded.net

Copenhagen, Denmark
William Gibson had ICE, Cyberpunk 2077 has the Blackwall. All tasked with keeping rogue AIs from breaking through. Sci-fi's answer to rogue AI seems to be to wall it off. The reality is that an AI cut off from data & purpose is useless. We can't firewall our way out of this one.
45
Nearly every photo id a KYC verification asks for is online & can be used as an AI prompt. Before, the word "specimen" WAS the security control. Now it's a handy variable telling LLMs where to infill. Pre-AI era controls are now on par with "I sent the password in 2 emails."
54
Tom Van de Wiele retweeted
For any aspiring hackers, please stay ethical it really isn't worth it.
46
66
1,123
44,386
I have deleted the airplane mode button and replaced it with a shortcut with an airplane on. Press it and it’s photographs the user, locks the phone and turns WiFi etc on.
My iPhone got stolen. The thief plugged it in to charge. That second, the front camera took a photo and emailed it to me with the exact GPS location. Not a third-party app. A built-in automation I set up in 5 minutes using the Shortcuts app that comes on every iPhone. The thief's face. The address where my phone was charging. In my inbox. Before the thief even unlocked the screen. I showed the photo and location to the police. They recovered the phone the same day. A cybersecurity consultant who sets up this automation for every client said: "This is the most effective anti-theft setup on any smartphone and 99% of iPhone users have never configured it. It takes 5 minutes. It uses the Shortcuts app that's already on your iPhone. It runs silently. And it catches the one thing every thief eventually does: plug the phone in to charge." He showed me 9 more iPhone anti-theft features most people never activate Stolen Device Protection, Find My network tracking, Activation Lock, Lost Mode, a trigger-word automation that works from any phone, and 4 other settings that make a stolen iPhone nearly useless to a thief and nearly guaranteed to come back to you. "Every iPhone has a $1,000+ anti-theft security system built in. Most owners have configured zero of it. They lose the phone. They panic. They wish they'd spent the 15 minutes it takes to set everything up. Don't be that person." Here's the complete anti-theft setup step by step 🧵
13
230
7,487
703,350
Goodbye zero-days, 2026 is the year of the zero-hour exploit.
13
38
463
24,104
Most CTFs are brute-forceable deterministic escape rooms that do not teach tactics, stealth or deception b/c there is no active IR or monitoring ergo very little transferable skills towards cyber defense. We need more defenders & builders that know secure arch, not pentesters.
I know this gets debated a lot lately, but it’s cool watching models and harnesses absolutely lay waste to CTFs. At the same time, I think there’s something being lost in speed running all of it. A lot of these CTFs humans walk away from with little 1–2% things they learned along the way. None of it seems huge at the time, but you stack enough of those reps over a career and eventually you’re able to stitch them together when you run into something weird. The real world is still messy. Brute force and speed are awesome until you hit something that requires novel thinking and there isn’t a clean path to the answer.
1
1
514
Tom Van de Wiele retweeted
Periodic reminder: Good security architecture minimizes the number of bugs and CVEs you have to care about.
10
45
233
17,751
The problem is that real skills are priced out of the market b/c the demand side cannot tell the diff. anymore between pros that know how to build/secure, & tool runners. Orgs are recruiting their security staff out of the PM & pentest pool so compliance & insurance run supreme
I really need more big names in cybersecurity to come forward and state the obvious: cybersecurity is real and works and yes we absolutely can contain an AI even if it’s extremely good at finding zero days.
2
610
Tom Van de Wiele retweeted
You guys, I JUST found out about recency bias, its my favorite thing ever
167
1,672
28,466
750,223
Sign of the times
‼️ Ubuntu is moving to weekly kernel updates because AI is finding Linux bugs faster than Canonical can ship the fixes.
1
429
Tom Van de Wiele retweeted
Say what you will about Windows (OS), but the NT kernel really is an engineering marvel that still puts Linux to shame in many ways. The quickest way to describe it for a programmer, is NT was more like an object-oriented language, with a strong security model from day one, whereas Linux is very…not. A lot of the “good” features in Linux feel bolted-on (SELinux, Capabilities, Namespaces) because…well they were. I love to imagine an alternate history where NT won. IMO, Microsoft *should* have made an “Open NT” in the early 2000s; not fully GPL-style open, but one where a large org could say…swap out a memory allocator for their own. (they sorta did this with limited source access, but it was too restrictive) You could imagine say…an early Amazon forking OpenNT to create an “AmazonNT” for EC2, where they have a modified scheduler, network stack, whatever. But, the security+compatibility contract keeps a stable baseline on the Microsoft side. Controversial take, but if we enter this era where users are giving AI agents increasingly higher levels of access control; the Linux kernel is legitimately a poor fit. Think about it; answer the question “What exactly is this AI agent allowed to do?” On Standard Linux, it’s disgustingly messy with lots of overlap. Do you use UIDs? GIDs? ACLs? CGROUPs? Policies? SELinux? Filesystem modes? There’s not a singular coherent graph of capabilities you can point to. Too many ways you can escape an initially narrow scope. NT, by comparison, can go the route of explicitly typed resources, and then you could have these really strong centralized audit trails when an agent goes haywire…etc. I know I’m rambling, but the point is…if you were greenfielding an OS kernel from scratch, in 2026, with the intent of being forward-looking, it would *not* look like Linux. Frankly, it’d probably look a lot closer to NT, or even a BSD fork…
497
295
4,315
302,119
Before LLMs we had Dr. SBAITSO & when it didn't know the answer it made no issue in disappointing you, which was often. That is before hex-editing the binary & boobytrapping the answers for our friends for a laugh. We had to write our own hallucinations in the 90s.
115
When websites still had personality and weren’t just a bunch of div blocks with a hamburger menu
In 2001, we really thought this was what the future of web design would look like.
4
269
Tom Van de Wiele retweeted
Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your iPhone are gone. Exploited in the wild by "DarkSword" malware. "The DarkSword attack program has leaked, with its core capability being: extracting forensic-level data from iOS devices via HTTP interfaces. In actual attacks, attackers can combine social engineering or watering hole attacks to lure users into falling victim, thereby stealing data from iPhone / iPad devices and uploading it to servers controlled by the attackers." Update iPhones immediately. Apple originally patched this, but rumours suggest even the latest versions are vulnerable, “pending confirmation,” across a wider range than the original 18.4–18.7 window. From a Chinese security researcher, SlowMist CISO, @im23pds nitter.net/im23pds/status/2101265…
Urgent security advisory for iOS users! Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases from iPhones. The reported attack begins when a target is socially engineered into opening a malicious page in Safari. That page is said to abuse a memory-corruption flaw in WebKit / JavaScriptCore to gain arbitrary read/write access from JavaScript, then bypass Pointer Authentication Codes (PAC) to run native code, break out of the WebContent sandbox, and escalate to kernel/root privileges. With that access, attackers can pull data from the device Keychain and from local crypto wallet apps. The claimed impact range is iOS 13 through iOS 26.5; that range has not been independently confirmed in full. Until more is known, treat any unpatched device as potentially exposed and update as soon as a newer build is available. Also avoid untrusted links in Safari, especially if you keep wallet keys or seed phrases on the phone.
36
156
1,214
344,682
The combination of the #Brucon conference and #Corelan training is about the best price/quality offering you can get right now for realistic exploitation training. I am sure it will be.. *looks around* HEAPs of fun! 😶‍🌫️
1
241
Tom Van de Wiele retweeted
On July 25, we hacked OpenAI. Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc. We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
354
1,397
11,855
2,800,576
Tom Van de Wiele retweeted
I just read something about LLMs self exfiltrating their weights via CPU temperature covert channels. I think people should ask their LLMs how computers, physics, and information theory work.
7
5
49
2,494
Tom Van de Wiele retweeted
Replying to @ZackKorman
I agree but also: (And previous incidents too) (Nobody seems to care) (Preventable incidents will continue forever)
2
7
77
1,259
Tom Van de Wiele retweeted
Corporate Infosec sends a phishing test email, I click, and somehow I'm the asshole because "[I] failed the test; had this been real it would have destroyed the company network"? If me clicking can destroy the network, I'm not the one in this conversation who sucks at their job.
65
124
1,397
146,634
Tom Van de Wiele retweeted
I’m not a lawyer, but Sam Altman and Dario Amodei may be creating a legal problem for their companies. If their AI products ever do cause serious harm, these public warnings of theirs could be presented as evidence that the risk was foreseeable and they knew about it.
403
464
6,037
152,865