Offensive cyber is our thing.

McLean, VA
Pinned Tweet
Our business model is this: - Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience or if they are total recluse-types who never want to attend some stupid “team building event” or whatever. This is largely an individual sport. And we want the Roger Federer(s) and Novak Djokavic(s) to work for us. We will hone their skills beyond what would be otherwise possible and polish them into absolutely deadly weapons. - Pay them so well (including serious equity), and task them with working on things so cool, that they would never even want to take an interview for a job at another firm (think Renaissance Technologies in the hedge fund world, but for computer network exploitation). We want to make these people very rich—which almost never happens to people with these skills in this industry. The only tradeoff is that they will have zero fame or public recognition, and they have to be okay with that (fame is overrated anyway) - Build the resulting primitives into the most sophisticated and powerful offensive cyber capabilities and platforms imaginable, in order to monitor, degrade and defeat the enemies of Western Civilization — If this sounds like what you’re after, reach out. Careers@IRISC2[.]com
12
1
98
15,794
We are hiring kleptography specialists PhD preferred careers@IRISC2[.]com
1
2
247
IRIS C2 retweeted
The 13th Annual NSA Codebreaker Challenge is LIVE! Join the mission and test your cybersecurity skills. Visit nsa-codebreaker.org to register and start your first phase today! #CodebreakerChallenge
49
83
213
21,477
No blog for this one. In short: We compiled SHA-256 into millions of native DNG opcodes, using the raw pixel grid as registers, wires, arithmetic cells, and a glyph framebuffer. Then made the file self-referential by storing the SHA-256 state of its block-aligned prefix and its final length in a fixed tail. Finally, a native GainMap added the Grim Reaper scene around the computation.
Cracked DNG too. And made it look cooler
1
1
10
863
Cracked DNG too. And made it look cooler
10
1,187
Part of what unlocked this was inspiration that came from randomly reading through a 25 year old Cisco patent
NEW: Turning the HEIC decoder into a SHA-256 computer irisc2.com/blog/heic-hashqui…
3
1,397
Not impressed with Opus 5.5
1
9
988
This FBI hack, if it is what it looks like, demonstrates the futility of old school red teaming exercises. I know some incredibly hard working and very talented red team operators. And they will be the first to tell you that they would never be given the budget, or perhaps more importantly, the authorized scope, to carry out the kind of penetration that allegedly took place in this case. 99% of red teams aren't even allowed to punch the firewalls/VPNs and run implants on them, because leaders are worried that the office might lose internet if something goes wrong. And yet that's one of the leading TTPs employed by the high-end threat actors these days.
10
26
293
17,323
OpenAI and Anthropic, as organizations, have endeavored to combine more A+ intellectuals under one roof than perhaps any other organizations in history. In many cases, we don't even know that these people work there. I have a few friends who have taken jobs at these companies and quietly dropped off of LinkedIn, and the internet more broadly. Some of these people are brilliant cyber folks, others are in biotech or pure math. Historically, the concept of combining so many giga-geniuses under a single organization has proven extremely challenging from an HR/cohesion/effectiveness standpoint (e.g. go read the history of America's national labs). The data that comes out of the management of these people will be extremely interesting.
2
3
855
The reality is that using AI for anything that actually matters is still a tremendously frustrating experience because all the models are extremely unreliable. You get a perfect result once, then do the exact same thing 3 weeks later, and spend $400, and it spits out slop. Using AI today is like using a computer from 1989. It just sucks. And I don't blame most people for hating it. GPT-6 is supposed to be "superintelligence", but it still cannot do basic expository writing that doesn't sound like a bunch of empty, hollow worthless slop. Give me a break.
4
498
The reality is that using AI for anything that actually matters is still a tremendously frustrating experience because all the models are extremely unreliable. You get a perfect result once, then do the exact same thing 3 weeks later, and spend $400, and it spits out slop. Using AI today is like using a computer from 1989. It just sucks. And I don't blame most people for hating it. GPT-6 is supposed to be "superintelligence", but it still cannot do basic expository writing that doesn't sound like a bunch of empty, hollow worthless slop. Give me a break.
2
2
4
639
The good news is, no one uses muse
And once a Mac is exploited, you can interact with any of the users "connected" devices also running Muse. ...meaning you remotely task their mobile (iOS) Muse client ...invisibly 📲🔓👀 What can you do? Welll, some very neat iOS stuff!
1
5
795
Cursor's context management is so awful. Just embarrassing 1 month after selling for $60B, the product is borderline unusable
1
12
1,073
VCs can't fix this btw The economics just aren't there This requires massive, well-administered government subsidies
Via Astralconspiracy
3
1
24
1,770
Tried to tell you
Replying to @zacbowden
Linux also has an extremely outdated and ineffective security model.
1
1
9
1,598
NEW: Apple is preparing to implement a kernel level EDR system in iOS When activated, the watchdog, known as com.apple.iokit.EndpointSecuritySE, which is still in beta, will monitor deep system telemetry in order to spot signs of exploitation More details:
23
157
1,582
140,452
A perfect example of what modern computers are really capable of if you optimize your code properly. All your 2.5 million code lines visible at once. 120Hz smooth scrolling. MSVC, Word or Chrome would choke super hard on a workload like this.
Ironed out the last performance issues with my full 2.5m line codebase explorer. 120hz awesomeness. Can only upload 60fps video tho. Much nicer uncompressed
52
329
7,652
283,462
Could a greater abundance of technical surveillance capabilities have possibly prevented 9/11? It certainly couldn’t have hurt We need Western Governments to be able to ensure that there is no electronic device that a terrorist can ever possess without being hacked and tracked
3
4
976