Head of Offensive Security @xorasecurity #1 photography account about hacking. Previous: @bishopfox Red Team @risk3sixty Pentest Practice Lead

I would simply write memory-safe code
2
538
Too many people haven't spent time talking to people smarter than they are.
1
113
just wait until keeme k4.4
Replying to @imjustnewatai
Can this outperform the oppos5.5?
68
Listening to non-technical people get frustrated about LLM output is like listening to my in-laws insist that their iPhone switched to Korean all by itself.
2
86
Many non-technical people are blindly trusting LLM output the same way older generations blindly trusted "the Google" and cable news.
67
This is why more companies need to offer disposable, easily terminable email aliases. I don't have to fill out a whole form to stop getting @parallels marketing emails if I can just turn the delivery address off.
1
66
Despite being a "verified defender" with Daybreak, OpenAI still rejected me when I appealed a warning they sent for generating a simple shellcode loader for research. What does "verified defender" even count for, then?
3
298
Account passwords in a vault. Vault passwords in your brain and somewhere on paper. MFA everywhere. Easy.
127
Ryan Basden retweeted
Bump
12
21
163
9,423
Don't make me coin "slopreneur"
65
Ryan Basden retweeted
I upgraded the security of the paper password manager
13
34
310
96,198
jfc I thought I was on LinkedIn for a second
*Checks date* It’s 2026… this is an actual book, in a major book store, in the technology section, not a Spencer’s as a gag gift or something… We’ve learned nothing…
1
106
Regular reminder to find something you love that has nothing to do with security.
2
79
Staking out how I do and do not use LLMs for good. Just in case anyone was wondering if I'm interested in handing over my humanity for expediency. ryanbasden.com/ai.html
100
Last week, I reconstructed a fully unauthenticated RCE exploit for wp2shell using (almost) nothing but Opus and the official public research.
1
2
292
I was curious, given the amount of detail in the discoverers' original blog post, how hard it would be for Claude to find the missing piece, and what that meant for the traditional model of public disclosure in the age of LLMs.
1
118
Turns out the hardest part was a tiny bit of gaslighting Claude and realizing that it had all the pieces to go from 95% to 100%, it just didn't realize that. Blog post and, of course, exploit code: empiricsecurity.substack.com…
1
118
“Hey, I could tell by your face that you were kind of frustrated on that call” Bro my facial expressions are humanitarian aid compared to what I was actually thinking
4
559
Claude when I stop typing in the chat field and hit Ctrl-G to open Vim

ALT Dramatic Man GIF

2
81