Shift retweeted
Haven't touched Android research in 5 years, but Android and I just became friends again 🤝. Reported a cool 3-vulnerability chain going from untrusted -> root. AI had a major impact on this chain, more info about that soon.
10
20
267
12,110
Shift retweeted
Thank you to @UnpromptedAU & @BSidesCbr for inviting me to speak. Being back down under was lovely! You can find the slides for my n-day automated pipeline talk here. I’m at OAIC this week if you want to chat about exploit dev in 2026 and beyond. beautiful.ai/player/-P2q0r-B…
10
87
316
17,122
This is lovely. 🥰 Man is twice a child. Be sure to look after your parents and grandparents. It is our duty. 😊
🅶🅾🆁🅺
43
345
2,594
40,982
Shift retweeted
5
29
117
8,035
glm 6 wen gotta stack my dgx
5
491
Containers are no longer a security boundary. Over the past few months, we’ve seen a crazy amount of Linux kernel vulnerabilities and exploits. This has forced us to rethink the security of infrastructure that relies heavily on the underlying kernel, especially containers. As models become more capable, the barrier to escaping a container has fallen so much that adversaries can now generate working kernel exploits in a single shot. CVE-2026-80521 is one such example. We discovered it using dfs-large1 from @depthfirstlabs and generated the exploit in one shot with GPT-5.6 Sol. The exploit still works on the latest Ubuntu 26.04 release because the fix has not yet been backported. Read our full writeup: depthfirst.com/research/cont…
32
71
400
117,436
Shift retweeted
DO YOU LIKE COMPUTERS? DO YOU GET HIGH ON CLANK? JOIN US AT SL0P.FOO
3
12
49
4,002
All of China's PQC algorithms have been broken in one day.
Community note
NGCC first-round PQC candidates (84 public-key submissions) were announced Sept 20; reports detail mostly implementation bugs in reference code for some, not all candidates or any finalized algorithms. niccs.org.cn/niccs/Notice/p… ngcc.dev/reports/index.… github.com/ngcc-dev/ngcc-…
78
266
2,838
757,335
Shift retweeted
636606729769440499166579950236036751749912014371509557713570027508971809534551913252252094954941974952859310861988904737359709200557919 is a factor of RSA-896 saweis.net/posts/rsa-896.htm…
224
990
9,494
3,913,084
Shift retweeted
The slides from my talk at Microsoft Bluehat Singapore are public here: thomasdullien.github.io/abou… It's my first BlueHat talk since the Vista days.
24
126
692
161,417
Shift retweeted
reverse engineering in 2026 be like: /goal make sure no sub_* remains, everything needs to have a CORRECT name also recover all types and signatures and TRIPLE CHECK make no mistakes or you and your entire family will fucking die then walk the dog and come back to 💯👍 IDB('s)
10
21
404
23,694
Shift retweeted
Open source must win this race.
90
352
3,816
72,914
How to kill open source models in 3 simple steps: - Create panic about frontier models. - Have the biggest AI companies help write the “safety” rules. ← WE’RE HERE - Make those rules so burdensome that open source can’t compete. Art of the deal.
333
2,147
10,978
366,984
Binder finally moving to rust, what a time to live in :') lore.kernel.org/all/20260913…
9
52
5,520
Shift retweeted
PoC and a brief writeup for CVE-2026-49881 (fixed today in 2026 sept ASB) this vulnerability allows one-tap LPE to system_server from an unprivileged app on android 17, and some 16 versions github.com/Supersonic/TLPE
3
30
96
7,971
Shift retweeted
Today we published WeWorm, our zero-click worm that spreads across iOS and Android. All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack. We reported the bug to Tencent, and it's now mitigated for all users. We hope this sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them. AI gives us a chance to find and fix these bugs faster than ever. We should work together to make the world safer for everyone. Our story and demos: calif.io/research/weworm
40
297
1,455
231,271
Shift retweeted
I tweeted about my little terminal multiplexer project a few days ago and got all of 50 likes on the tweet (when I cheap-dunk on om*rchy I easily get 400; what a time to be alive) .. ANYWAY I didn't let that discourage me and I spent some time cleaning it up and getting it ready for the public! 🤖 slosh v0.1.5 is now available for everyone (macOS, linux, windows). check out the brand new slosh website as well! it gives a small tour of some slosh features and even lets you boot a riscv64 linux computer right in your browser to try out slosh without ever downloading it. (shout out to fabrice for making it possible🤓) we could use your help to make slosh even more awesome: bug reports/PR's welcome on Github (or join us on Discord for interactive discussion!) check it out: slosh.foo 🙏
8
18
93
18,070
Shift retweeted
תעשייה שמגלגלת 9.5 ביליון דולר בשנה ולא ראיתי אף אחד שמדבר עליה. היא מאוד קרובה לליבי, אבל איכשהו נשארה מתחת לרדאר בכל הדיבור על "מהפכת ה־AI": תעשיית הצ׳יטים למשחקי מחשב. >>
1
1
4
354
Shift retweeted
We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We're unable to complete the port due to lack of support for ARM hardware memory tagging in software, firmware and near certainly hardware. It appears Google cut an important security feature to save money. ARM hardware memory tagging (MTE) is used by GrapheneOS across the entire base OS including the kernel and every standard base OS process. It's only temporarily disabled for a few device-specific processes. It greatly improves protection against nearly all remote exploits and many local exploits. Pixel 8 launched with hardware MTE support in October 2023. We integrated it into our hardened_malloc project and began using it across the OS later that month. Android and the Pixel OS never started using it by default. Android Advanced Protection Mode in Android 16 enables it for a few processes. Apple's Memory Integrity Enforcement (MIE) is an always enabled feature on the iPhone 17. It's simply a high quality implementation of MTE using the latest standard extensions. It uses MTE in the most secure mode in the kernel and a large portion of userbase. They did a very good job integrating it. Apple's MIE and Android 16+ AAPM don't use MTE for user installed apps unless those explicitly opt in. GrapheneOS enables it for more apps automatically and has a toggle for users to opt-in for every user installed app. There's a per-app toggle to opt-out for incompatible apps which is uncommon. Neither iOS or Android encourage app developers to opt into MTE and other more aggressive security features used in the base OS. Apple's docs warn developers of performance and stability issues. Even Signal doesn't opt-in. Our approach enables forcing using MTE in the standard allocators regardless. Pixel 11 does have security improvements including moving to post-quantum secure verified boot (ML-DSA) and replacing Samsung Shannon IMS with AOSP IMS. Titan M3 should significantly improve protection against data extraction in Before First Unlock state. It's too bad they ruined it by cutting MTE. Pixel 11 series is a lot more expensive for an incremental improvement to the CPU, the same underpowered GPU and reduced RAM for the Pro base models. They finally caught up to the last generation of Qualcomm cellular radio. It's overpriced, the upgrades aren't impressive and losing MTE is appalling. Compared to the Pixel 11, a Snapdragon 8 Elite Gen 5 has ~40% higher single threaded CPU performance, ~80% higher multi threaded performance, over 100% higher GPU performance and a far better cellular radio. It also finally has MTE. The next gen is what will be in the first Motorola with GrapheneOS. Pixel 9a and earlier (including Nexus devices) were the Android Open Source Project reference devices. Pixel support was removed from AOSP with Android 16. It's now harder to support Pixels than many other devices and massive progress towards open source firmware and driver libraries was discarded. Compared to the stock Pixel OS, GrapheneOS ships AOSP patches months earlier and Linux kernel patches many months earlier. However, we rely on them for firmware and most driver updates. We also want to move to new kernel branches earlier. These things can be improved with our Motorola partnership. We strongly recommend against buying Pixel 11 devices. Pixel 8, 9 and 10 have much better overall security for GrapheneOS. Pixel 10 is cheaper with similar hardware and MTE. Pixel 11's Titan M3 should improve BFU security for users without a strong passphrase, but losing MTE craters AFU security. We haven't determined what to do about this situation. It may be best for us to skip the Pixel 11 series devices. We can shift our focus entirely to the upcoming Motorola devices instead. Pixel 10a was really a 9th gen Pixel, so hopefully the Pixel 11a does the same with 10th gen and includes MTE.
240
721
5,703
904,616
idgi why people flex for tps and not post train speeds and optimizations
4
725