CEO of a16y.ai. Dancing with bits

New York, USA
Guys & girls! Exactly a year ago I promised over 15 bugs in win32k. You're welcome to read and find out about my biggest research so far: #win32k #SmashTheRef bug class - github.com/gdabah/win32k-bug… Check out the paper and the POCs, there are some crazy stuff going on. Promise!
12
332
743
There’s this book conversations with god. But I prefer conversations with ai.
148
Gil Dabah retweeted
Hackathons are a good excuse to build a slightly unreasonable version of the future. So we built an entire computer inside the browser, designed for humans and agents to use together through WebMCP. No access to your local machine. Just send an agent a URL and give it a fresh computer to work with. Built by our awesome @ilay_alog 🦾🤖👑 !
We just submitted our project to the @OpenAIDevs WebMCP hackathon: The WebMCP Computer. WebMCP Computer is an operating system that lives inside the browser, with WebMCP as its native control layer. It is a computer that treats agents as first-class citizens, where files, processes, applications, windows, and the terminal are exposed directly through WebMCP. You can send anyone one URL that becomes a disposable computer for any agent task. We created a computer instance in ChatGPT Sites, open it with Codex’s in-app browser and try it here: computer.webmcp.com/ Some examples of what you can do with WebMCP Computer: 1/ Give a coding agent a fresh computer to clone a repository, edit code, run tests, and preview the result. 2/ Let an agent inspect logs, manage processes, change configurations, and repair a broken system. 3/ Give a research agent its own workspace to browse, download files, analyze data, and create a report. 4/ Create reproducible environments for evaluating and comparing different agents. 5/ Let humans and agents work together in the same environment, with the agent using WebMCP and the human using the GUI. The list of applications is endless, with more examples in our GitHub. The project is fully open source under the MIT license. github.com/nekuda-ai/webmcp-… devpost.com/software/webmcp-… Created by our awesome founding engineer @ilay_alog.
1
3
7
427
Gil Dabah retweeted
Big NEWS: Today we're launching Catch AI, an admin-assistant for busy executives. We started Catch with a simple idea: AI should actually do the administrative work executives hate doing themselves. Not suggest. Not summarize. Do. >>
211
109
889
864,270
Gil Dabah retweeted
Great time to share all the WebMCP tooling we’ve built lately: 1/ the first WebMCP directory webmcp.com 2/ WebMCP extension for developers (batteries included) chromewebstore.google.com/de… 3/ codex plugin to build WebMCP tools on your site github.com/nekuda-ai/webmcp-…
The WebMCP Challenge is here. We’ve teamed up with @ChromiumDev, @CloudflareDev, @ShopifyDevs, @vercel, @render, and @Netlify for a 10-day hackathon. Up for grabs: $35,000 in cash prizes, Codex Micros, ChatGPT Pro subscriptions, and more prizes from our supporters.
13
34
273
32,817
What a rotten deal we made with Iran. We get nothing (except laughter at our stupidity). They get everything, including delay and big cash!
1,379
12,971
33,940
FULL REMOTE CODE EXECUTION on default nginx 1.30.0 no config changes needed. 🫠 Verichains a deadly exploit chain combining Nginx-Rift (CVE-2026-42945) + Nginx-PoolSlip (CVE-2026-9256). 2-byte heap pointer overwrite & heap over-read then ASLR bypass to arbitrary command execution via system() on connection teardown.
Over the next few months, we'll be gradually publishing some of our internal security research. Starting with a bug chain that turns Nginx-Rift + Nginx-PoolSlip into full RCE. More to come. #Nginx #1day #RCE blog.verichains.io/p/two-byt…
5
115
880
118,944
Also worth to note that at my company we code review the results of AI generated code.
I've got an agent in a loop optimizing a renderer with the goal to minimize frame times (and tests to measure). It got times down from 88ms to 2ms and allocations down from ~150K to 500. Sounds good, right? Wrong. This is exactly why agent psychosis is a big fucking problem. As an experiment, I rewrote the Ghostty core render state in Go, with access to identically laid out data structures as Ghostty and the exact same validation tests. I made a purposely naive renderer (simple, correct, but slow). 88ms per frame with 150,000 allocations (horrendous, lol)! I then kickstarted a Ralph loop to bring the frame times down. I told it it can't modify input data structures or the public API or tests (they're correct), but it can do anything else it wants. It got to work. It has worked for about 4 hours. I've spent around $350 on this experiment so far. The results? 88ms => 1.5ms 150K allocs => ~500 allocs Incredible right? Nope. My hand-written renderer I ported has frame times (same benchmark) of ~20us (0.020ms) and 0 allocations in the update path. This is the problem with psychosis and lacking systems understanding. If you don't understand the system, you're going to accept that this is an incredible result. If you understand the system, you'll see better solutions immediately and can do roughly 75x better on throughput. The people who blindly trust agent output are in the former camp. They're sheeple, overdrinking from a fountain of mediocrity. Standard disclaimer: I use AI all the time. I like AI. The point I'm making is to not blindly accept results. Think. Analyze. Learn.
1
401
We’re cooked. Don’t use chrome any more!! 🤭
Tomorrow, I will drop Chrome exploit code showing how an attacker can execute arbitrary Javascript within the context of a domain they control.
1
4
2,257
We freeze versions and update a bit later. Unless it’s a critical security patch. Easier and safer.
Fork your dependencies, trim them to only your use case, never update unless it breaks for your users. I’ve been vocal about this for 10+ years. I’ve always said that updating is way riskier than latent bugs (which can be tracked and CVEs monitored). If you are updating a dependency, it’s on you to analyze every single commit in the full transitive set of dependencies. If you dont see anything compelling, dont update! I remember at HashiCorp once in awhile an engineer would try to update a dep or replace a DIY lib with an external one and id always ask “show me the commit we need.” Dont update for the sake of it. Feeling pretty swell about this mentality with all the supply chain attacks happening.
1
1
2
657
Why I am not surprised. Keep building like monkeys. It gets exposed with your cloud bills and now AI bills and next your security posture.
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. cfl.re/49BRUqW
1
400
Real rock star!!
You have no experience. You’ve never started a company. You’ve never had a full time job. Nike is going to kill you. You’re a kid. You don’t have technical skills. You shouldn’t build hardware. Apple is going to kill you. You can’t build hardware. You can’t measure heart rate non-invasively. Athletes don’t care about recovery. Under Armour is going to kill you. It won’t be accurate. You don’t listen. You’re an ineffective leader. You can’t recruit great talent. You’re going to have to pay every athlete. You can’t measure sleep non-invasively. It’s too expensive to research. Athletes are a small market. The product costs too much to make. The product costs too much to sell. Your valuation is too high. Consumers aren’t going to want it. Hardware is too hard. You should measure steps. Fitbit is going to kill you. You can’t build a marketing engine. You can’t raise enough money. You need a real CEO. Google is going to kill you. You can’t be a subscription. You can’t build a brand. You can’t do consumer in Boston. Your valuation is too high. You shouldn’t make accessories. You shouldn’t make apparel. Lululemon is going to kill you. You can’t predict Covid. Stay in your niche. You are going to run out of money. You can’t build a health platform. Amazon is going to kill you. You can’t measure blood pressure. You can’t get medical approvals. The market is too small. You don’t understand AI. The market is too competitive. It won’t work internationally. The supply chain is too complicated. You can’t build an AI. You can’t raise enough money. It’s too competitive. Healthcare isn’t going to want it. … Just keep going ✌️
1
1
424
Google just killed its AI rivals today! It’s just a matter of time now.
2
512
It’s time big bounties will be paid according to density and not only difficulty. If nobody found a vuln in said software for x months then it should go higher etc.
6
550
One day all those free models will be illegal.
1
289
One of the best hacking teams I know. And this is only the beginning!
We evaluated @Tenzai_Labs AI hacker across six major CTF competitions designed for humans. Result: Top 1% performance, outperforming 125,000+ human hackers across different domains - web hacking, ai hacking, low level system hacking. We wanted to see what @Tenzai_Labs's hacking agent is really capable of in the most complicated and competitive environments, where to excel, one needs to solve increasingly difficult challenges. The results we achieved surprised even me. This is incredible evidence of what AI agents with the right harness can do and I expect it to only get better from now. blog.tenzai.com/tenzais-ai-h…
3
825
so now we have security agents, ai agents and human agents. fun
1
1
295
Bounties pay too much for AI driven findings. This arbitrage will change in the next few months. They need to change it to be dynamic. The longer nobody finds anything the higher it goes.
4
492
It’s funny how world leaders speech like the world is made of kids who shouldn’t hear the truth. It’s damaging more than they would admit.
I am following with deep concern what is happening in the Middle East and in Iran during this tumultuous time. Stability and peace are not achieved through mutual threats, nor through the use of weapons, which sow destruction, suffering, and death, but only through reasonable, sincere, and responsible dialogue.
1
254
כן
137
851
13,664
744,293