sharing reverse engineering knowledge

REhints retweeted
Our CFP is open and we're especially looking for hacking magic 👾🪩🪄 Learn more about the content we're looking for on our Sessionize! sessionize.com/districtcon
7
8
1,711
REhints retweeted
Replying to @ZackKorman
This topic is more complicated than it looks. As an industry, we've definitely made a lot of progress in cyber over the years. But this is different, very different from what we've dealt with before. Look at the spike in fixed vulnerabilities across all the big vendors. And this isn’t a one-off event, it's a continuous trend. What it shows is that our understanding of cybersecurity in general is right, but the way we've solved these problems in the past is not. AI is exposing all the obscurity and complexity across the tech stack, including hardware, in exactly the places where problems were traditionally hard for human researchers to find. At the same time, threat actors are getting a force multiplier from AI without investing in new resources or building new expertise. And on top of that, every new model outpaces the previous one, so yesterday's statements and assumptions quickly become wrong. This isn't a static risk. It's highly dynamic, and things are changing and escalating far faster than the industry, or the tech stack, can react.
2
4
37
2,127
REhints retweeted
New video: Breaking Obfuscated Binaries with AI Agents: An Attacker's Playbook I'll showcase my strategies for attacking strong protections that cannot be one-shotted. piped.video/watch?v=oGBj1v8t… Slides & samples: github.com/mrphrazer/binary-…
6
133
609
31,884
As Flare-On starts I am happy to announce the official Hex-Rays IDA MCP Server is out! 🥳 Details and links below ⬇️
9
73
381
19,380
I'm hiring an exceptional Offensive Security Researcher for my team at NVIDIA (Offensive Security Research - OSR). Firmware, microcode, RISC-V, hypervisors, and shipping mitigations like HW CFI, Memory Tagging, and Pointer Masking from the ground up. jobs.nvidia.com/careers?quer…
12
84
469
44,968
REhints retweeted
🧵📈🆙 Low Level PC/Server Attack & Defense Timeline update! I updated it in July (1st edition using AI help ;)) and forgot to upload/mention it 👇
1
3
18
2,624
Hacktron has a good point here: hacktron.ai/blog/hacking-ope… "Software has long benefited from a kind of security through complexity. The code and even the vulnerability could be public, but turning a bug into a reliable exploit still required rare expertise, significant time, and knowledge of the target environment. Known memory corruption vulnerabilities were expensive to operationalize, while zero-days were mostly reserved for the highest-value targets."
We are not stopping at OpenAI. Today we’re publishing HEIF Heist, a months-long investigation by our security research team into vulnerabilities in libheif. The research uncovered attack paths affecting OpenAI, Slack, Meta, GitHub Enterprise, Rails, Next.js, ImageMagick and others. heif-heist.com
1
9
74
13,567
REhints retweeted
Another point, the HW and FW security boundaries are our last frontier for building real hardwired boundaries for virtualization, memory isolation, and hardened agent sandboxing. In the end, the whole confidential computing movement is more about cloud cost optimization than anything else. It's just broken by design, you can't build a secure stack if what's underneath has been broken for many years.
3
21
2,018
REhints retweeted
Unfortunately, the complexity of the hardware and firmware supply chain has the same negative effect on how cryptographic artifacts are managed, or mismanaged, across the ecosystem. This is a reminder of the scale of the problem, based on just one documented data breach.
⛓️Confirmed, Intel OEM private key leaked, causing an impact on the entire ecosystem. It appears that Intel BootGuard may not be effective on certain devices based on the 11th Tiger Lake, 12th Adler Lake, and 13th Raptor Lake. Our investigation is ongoing, stay tuned for updates.
3
16
70
10,151
REhints retweeted
Your weekend reading assignment has arrived early. A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by @mikko. archives.phrack.org/dl/73/th…
2
55
159
30,437
REhints retweeted
The slides from my talk at Microsoft Bluehat Singapore are public here: thomasdullien.github.io/abou… It's my first BlueHat talk since the Vista days.
24
126
691
159,880
I've just (re)written TaskExplorer Think Process Monitor but for macOS, open source, & much more powerful 💪🏽 Highlights: • CLI + JSON export • On-device AI assistant • Code signing + VirusTotal context • Live process/file/dylib/network activity objective-see.com/products/t…
10
49
339
26,694
REhints retweeted
We're super excited to announce that hardcopies of Phrack 73 will be available at @UnpromptedAU in Sydney, @unpromptedconf in SF, and @tengu_sec in Japan! Catch the drop irl!
1
14
71
4,411
REhints retweeted
🧹 rev.ng now does intraprocedural type propagation! Enjoy less casts and better local variable types.
4
11
173
12,602
REhints retweeted
This tweet has aged a few months, and frontier progress has only strengthened my feelings in this direction. Twelve months ago my thought was that AI is just another tool, automating parts of the RE/VR process. Now I'm more of the impression that it operates like the creative mind of an experienced researcher, who thinks beyond established patterns and finds new attack paths. The most effective vulnerability researcher is no longer human.
Lately I've been thinking about how AI is changing vulnerability research and reverse engineering. VR and RE are some of the hardest workflows to parallelize. Even with great knowledge transfer and team practices, you usually default to one person per vuln or RE task. The work is just too context-heavy to split. AI breaks that ceiling. It's no longer "one researcher, one task", it's you working one angle while Claude annotates disassembly code, explores another path, or helps you piece together what the last result means. Watching this land in domains we assumed were fundamentally serial is wild.
8
11
80
8,816
Build the ultimate Windows kernel debugging setup! Automated VMs, ret-sync with IDA/Ghidra, and source-level kernel debugging. Your exploit lab for Cedric Halbronn (@saidelike)'s classes awaits! Debuggers 3011: Advanced WinDbg ost2.fyi/Dbg3011
1
49
276
9,877