Perpetual Student | SANS Fellow | Musician | Braggart Hater | Gray Hat Hacking | VR | 🏂 | deadcode | acidapp.ai

Berkeley, CA
Join us today at 12:30pm!
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!" Thanks for helping us reach 50K subscribers! piped.video/watch?v=WWQRirWA…
3
8
1,576
Stephen Sims retweeted
I'm hiring an exceptional Offensive Security Researcher for my team at NVIDIA (Offensive Security Research - OSR). Firmware, microcode, RISC-V, hypervisors, and shipping mitigations like HW CFI, Memory Tagging, and Pointer Masking from the ground up. jobs.nvidia.com/careers?quer…
12
84
469
44,965
Looking forward to this event! If you’re going to be there come find me to say hi.
Just two weeks until OAIC! Will Schroeder, Lee Chagolla-Christensen, Becca Lynch, Matthew Nickerson, Max Bazalii, and Aaron Grattafiori are up the first half of day 1! See the full agenda at offensiveaicon.com/schedule
1
17
2,087
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!" Thanks for helping us reach 50K subscribers! piped.video/watch?v=WWQRirWA…
1
16
67
6,269
Breaking Windows: Exploring Security Through Kernel Drivers nitter.net/i/broadcasts/1oKMvNMny…
34
94
5,132
Stream Reminder: @zodiacon (Pavel Yosifovich) will be joining me on the @offby1security stream tomorrow 18-September at 11AM PT for a stream on Breaking Windows: Exploring Security Through Kernel Drivers! piped.video/watch?v=3tP1HVwA…
Join us next Friday, September 18th at 11AM PT for the next @offby1security stream with the great Pavel Yosifovich (@zodiacon) for a session on, "Breaking Windows: Exploring Security Through Kernel Drivers!" piped.video/watch?v=3tP1HVwA…
3
10
34
3,062
Lesson learned... I forgot I switched to my "family" WiFi network when running an offensive campaign against intended test targets. The first bad indication was when my printer started printing, and then I found my Samsung Family Hub Fridge with a bricked screen and it's EoL.
7
2
55
5,315
Question: For pen testers and red teamers working internally at an organization, or working as a consultant, is your offensive AI solution:
57% Custom Harness/Workflow
11% Open-Source harness
16% Commercial product
16% Other (Please comment)
37 votes • Final results
2
1,069
Almost at 50K! I think that's great for a channel that focuses primarily on advanced content! Thanks to everyone who has subscribed and to all of the guests who have joined me for a stream!
2
3
22
1,398
I’ve been doing a lot of thinking about this over the past week. It’s getting very easy to become complacent and let AI do everything for us, especially when we’re all being pushed to 10x our output. It can be hard to justify spending hours getting into the low-level details when a model can often get you most of the way there in seconds. A lot of respected practitioners have already raised concerns about skill deterioration, and I think they’re right to worry about it. At the same time, AI is going to make software meaningfully more secure. As more companies integrate strong AI code scanning directly into CI/CD, a lot of low-hanging fruit is going to disappear. Even harder memory corruption bugs, unsafe API use, obvious authorization problems, and common implementation mistakes are going to get caught earlier and more consistently. That’s of course a very good thing. But I don’t think vulnerability research or hacking suddenly ends. The offense adapts, and the bar rises. That's always been the "fun" part for those of us in the offensive space. I’ve spent a lot of time lately benchmarking what AI code scanning and dynamic sandbox analysis are good at, and I think the harder problems increasingly move toward things like business logic flaws, strange state-machine behavior, race conditions, cross-service trust mistakes, authorization failures that only emerge across multiple components, protocol composition issues, and distributed-system behavior. I've been trying to write CTF challenges for learning that capture this. And then we’re adding entirely new attack surfaces like agents, tool use, model orchestration, persistent memory, agent-to-agent communication, and systems where one AI is implicitly trusting the output or state of another. AI will continue to help researchers explore these systems at a scale humans never could before. That probably means we’ll discover failure modes and bug classes that we haven’t even thought of yet. Which is why I think it’s more important now, not less, for people to keep putting in the work to understand how things actually work underneath. I catch myself taking the easy route with AI more often than I’d like. Fortunately, I’ve spent thousands of hours coding, debugging, reversing, exploiting, and generally fighting with systems, so I can still drop back down into the weeds when I need to. Thankfully, there are a lot of us in this pool. What worries me more is the next generation coming into the industry. How do they build that same intuition if AI removes so much of the struggle that used to force us to learn? There are fewer intern spots, fewer junior positions, etc... Because if you don’t understand what’s happening underneath, it becomes much harder to know when the AI is wrong, when a finding is overstated, how to properly validate an issue, how to turn odd behavior into a real vulnerability, or how to recognize an entirely new bug class. Vulnerability research has never really been about instant gratification. It takes time, patience, creativity, failure, and a certain amount of stubbornness. AI absolutely makes us faster. We should use it. We just shouldn’t let it make us stop thinking. My current belief is that both offense and defense are going to level up dramatically. Software will get more secure, but researchers and attackers will get more capable too. The bugs that matter will simply become harder, stranger, and more interesting. As a historically offensive practitioner that's exciting to me as it's curiosity that brought many of us into this space. I swear I reread this 10 times worried that it sounds like AI wrote it. I promise it didn't. :) My hope with this tweet is that it encourages those coming into the space, or who are new to the space, to put the work in to learn as much as you can. One thing that attracted many of us to this space is the challenges with solving complex puzzles. I encourage you to go back and read Hacking: The Art of Exploitation... .The Shellcoder's Handbook, and selfishly, the Gray Hat Hacking series! Sorry for the looooooooooooong tweet.
25
29
181
20,370
Question for music lovers… How do you feel about musicians using AI for songwriting and for music videos? I mean for writing songs, guitars, lyrics, vocals, and AI humans in videos. This is a non-cyber tweet, but it’s the other part of my career that means the world to me.
22% As an aid only
59% A hard no
19% Yes, it’s the future
54 votes • Final results
4
2
5
1,686
Stephen Sims retweeted
The Evilginx Chrome browser extension is now officially pending review. 🥳 Here's what's coming up in the 1.0.0 release: - View, search, create, edit, copy, and delete cookies. - Inspect and modify Local Storage and Session Storage. - Import and export cookies and page-storage entries as JSON. - Cookie Monitor that records cookies created or updated through Set-Cookie response headers. - Kickstart Evilginx Phishlet 1.0 YAML or Phishlet 2.0 HJSON development using the cookie and hostname records gathered by the monitoring feature. - Cookie Freeze feature allows you to test which of the captured cookies hold session authentication tokens. - Optionally disable Device Bound Session Credentials registration by removing two specifically named DBSC response headers. Once approved, I will release a hands-on tutorial video on YouTube. 🎬 Attaching several screenshots.
2
32
175
8,455
As many are seeing, AI ruins traditional CTFs. I'm seeing students solve all challenges in an hour or two. I'm working on new challenges that include logic bugs combined with 3-4 part chains to solve. Also, making it much more difficult to pull the files off the container.
8
11
137
8,967
The goal is not to stop them, but to slow it down significantly so that students who aren't using AI with the goal of learning have an equal chance of winning.
2
1
13
1,051
Join us next Friday, September 18th at 11AM PT for the next @offby1security stream with the great Pavel Yosifovich (@zodiacon) for a session on, "Breaking Windows: Exploring Security Through Kernel Drivers!" piped.video/watch?v=3tP1HVwA…
1
12
42
6,705
Join us this Thursday, September 10th at 7AM PT on the next @offby1security stream with @LindellYehuda for a session on "The Role of Cryptography in Security!" piped.video/watch?v=FF1aEhNR… Description: Join us for a conversation with renowned cryptographer, researcher, and professor Yehuda Lindell as we explore disconnects between cryptography and security. We'll discuss the challenges of turning academic research into real-world products, why secure systems still fail, lessons from building cryptography startups, and whether post-quantum cryptography is finally ready for prime time.
4
26
2,543
A researcher submits a CVSS 9.8 multi-part exploit chain that leads to Remote Code Execution. It's 4+ issues required to achieve the RCE. It's submitted & the affected party says, "Sorry, duplicate, the 1st part of your chain was already reported and a patch in the works."
25% Vendor should credit 9.8
19% Too bad 1st part kills it
45% Update to 9.8/credit both
11% Other, see comment
202 votes • Final results
6
3
20
4,575
I'm seeing more and more of this due to no barrier to entry to find vulns by random AI-users. I've always recommended that researchers look for a full-chain before submission, but it's a race condition. I'm also seeing a surge of patches with no notifications to users for rc's+.
1
5
959
2 DM's asking what I mean by rc's... Sorry, "release candidates..." Meaning that the patch is already available but the project team has not informed anyone about the reason for the patches.
2
774