Offensive Security / AI @Umbriel_AI. Ex-AI RT and OffSec at NVIDIA, RT lead @ Meta. Ex-Principal Consultant and Researcher @ NCC Group/iSEC Partners. Neg9//CTF.

Colorado
Current Status feels like this is no longer going to be fiction...
1
2
2,688
Aaron Grattafiori retweeted
Registration for the inaugural SkiSides is now open. 20–22 January 2027 Whitefish, Montana Technical talks, organizer-led discussions, a collaborative hackathon, and real time with people working where AI meets cybersecurity. skisides-2027.eventbrite.com #SkiSides
1
3
4
393
Wow. F5.... LOL. What a complete joke. 1998 called and it wants it's vuln back.
F5, BIG-IP, a 20-year-old primitive, a security appliance, an "authentication" mechanism - and a CISA promise ring. Yes, it's CVE-2026-94127. Give us strength. Speak soon xo labs.watchtowr.com/is-this-a…
2
3
30
7,289
Aaron Grattafiori retweeted
A quick article showing how the Jev OPSEC ranker works, and looking at how Jev can be used for identifying potentially sensitive file paths and content at speed.
Article

Experimenting with Jev for Offensive Security

A few days ago I published a quick demo of using the new Jev model to measure OPSEC strength of a command being typed into Mythic: Since posting the video I have had a few questions about just how

3
72
429
22,536
Aaron Grattafiori retweeted
I put my @UnpromptedAU slides up at justdionysus.github.io/slide… — a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
4
68
236
31,534
Aaron Grattafiori retweeted
Hacktron pwned OpenAI through a libheif bug, ok fine. A few days later (back from the Oktoberfest) I found a *newer* libheif 1.23.x behind an image API during one of my own engagements, so I went digging. I ended up finding an undocumented remote iref/dimg heap-grooming primitive: controlled reference graphs produce repeatable malloc(16) allocations in glibc’s 0x20 class, with controlled lifetime, attacker data and predictable reuse. And guess what? Then a fresh libheif 1-day dropped with no public PoC, so I took it from source diff to TAI UAF -> reclaim -> stale free -> safe-linked tcache poison -> _ZdlPvm@GOT -> system() -> RCE (github.com/strukturag/libhei… - I do not share the POC as well but in 2026 it's not a big challenge anymore right ?) > 1 primitive gives remote heap shaping, the other shows what a compatible corruption bug can become. And all of this came from an API testing... less OWASP testing, more PWN ! <3 Full write-up: boffsec-services.com/posts/l…
3
56
323
16,930
Aaron Grattafiori retweeted
The irony is that guardrails that deny any kind of poc generation results in so much harm to the vendors because they get flooded with AI hallucinations that would not survive if the models did even attempt a basic POC. Unfortunately models are poisoned with the idea that any …
3
3
22
3,473
Aaron Grattafiori retweeted
Barack Obama at his last press briefing with reporters, 2017: "I have enjoyed working with all of you. That does not, of course, mean that I've enjoyed every story that you have filed, but that's the point of this relationship. You're not supposed to be sycophants. You're supposed to be skeptics. You're supposed to ask me tough questions. You're not supposed to be complimentary, but you're supposed to cast a critical eye on folks who hold enormous power."
1,115
24,663
124,505
5,664,417
Aaron Grattafiori retweeted
If someone runs an eval that costs millions in compute, an agent takes a detour out of the sandbox, and now millions of dollars of compute are pointed at hacking you, I have bad news without LLMs, if someone was willing to spend millions targeting you, they were probably getting in. This has always been the dilemma with nation states like China. If someone can dramatically outspend you, well… I realize there’s a separate argument around local models and agents, but I see leadership at all kinds of companies suddenly trying to defend against whatever swarm scenario matches the latest high profile incident. You should probably worry more about someone pointing a 27B local model at your home built, public facing web apps than the first scenario.
12
20
127
15,950
"626 tests pass" I really hope OpenAI fixes this with their upcoming release. It's ridiculous. So many of the tests are absolutely crap too. Conspiracy to inflate token output or crappy RL side effect? You decide.
1
12
902
With all the focus around TypeSafe/Jev/System One lately- this research is super timely (or, before it's time because @noperator is very clever!). Also check out his Phrack article for complementary research. 🔥
Umbriel's Caleb Gross (@noperator) spoke at Blackhat this year ("Sift or get off the PoC: Applying information retrieval to vulnerability research"). The talk is now live! See it here: piped.video/watch?v=1ADD60wy…
1
3
14
2,905
Aaron Grattafiori retweeted
Just two weeks until OAIC! Will Schroeder, Lee Chagolla-Christensen, Becca Lynch, Matthew Nickerson, Max Bazalii, and Aaron Grattafiori are up the first half of day 1! See the full agenda at offensiveaicon.com/schedule
4
18
3,423
Aaron Grattafiori retweeted
pleased to share the entire arXiv site as a dataset on HuggingFace huggingface.co/datasets/sece… 3,148,796 papers, every version, in LaTeX, PDFs, PostScript, HTML, 16 TB in total
131
518
4,351
394,558
Aaron Grattafiori retweeted
The @UnpromptedAU crew did an amazing job. It had the feel of a local BSides but with 400 people and a global lineup of talks. @chompie1337’s BinChomp talk was pro @moyix packed 45m of joyful hacking into 15m Tristan Steele and Jasper Van Woudenberg showed their AI w/ HW tech
1
4
29
1,952
Aaron Grattafiori retweeted
That's a wrap! Thanks to our sponsors, our speakers, and our volunteers for making this a great conference 😎. See you next year!
2
2
17
3,527
Aaron Grattafiori retweeted
Here are my fav talks at the first @UnpromptedAU: @chompie1337 shared her 1-day exploit factory. Although she focused on Windows, many of the ideas also apply to other platforms and systems. She's a fantastic speaker who made a deeply technical topic accessible and easy to understand, even for noobs like me. @moyix's thesis is that AI has made reverse engineering much easier, and therefore security through obscurity is dead. I completely share this view. I won't say more because I don't want to spoil Brendan's talk, but man, he really loves what he does, and that love is contagious. Now I want to hack with a cat too! Ash Fox shared how his team at Google is building an AI red teamer. This one hit very close to home! I really enjoyed hearing how they teach their agents to maintain OPSEC. I also loved his idea of "living off the agents", leveraging existing agents to move laterally. @justdionysus shared the story of his first week at Calif, when he bypassed Apple's MIE with AI. I'm 100% biased, but Dion had the most beautiful slides at the conference. I'm fucken jealous -- how the hell he could make them look that good. It's a great conference, small enough to feel like a real community where everyone knows one another, but big enough to make new friends. It reminds me of Ekoparty in the early 2010s. Sydney is lovely, too. I'll definitely be back.
2
22
144
10,567
Aaron Grattafiori retweeted
Absolutely incredible work by @mdowd and @UnpromptedAU putting together an amazing collection of people and talks. Favorites were @chompie1337 and @justdionysus – great speakers with deep expertise in exploit dev. Hope to come back next year for another round!
1
5
57
2,856
Aaron Grattafiori retweeted
Dion Blazakis from Calif is next with "AI assisted exploit development: An XNU case study"
6
33
2,566
Aaron Grattafiori retweeted
Umbriel's Caleb Gross (@noperator) has an article in the latest Phrack 73 issue (@phrack) "Word Machines for Weird Machines" - check it out when you get the chance!
5
20
4,050