Security Vulnerability Coach, responsible for @x41sec and @persistent_psi Tweets here are my own.

Right here
“Rules don’t make works of art, works of art make rules.”
133
The audacity of OpenAI bike-shedding about a bug bounty, while they’ve had 50.000 of their own agents marauding through other people’s infrastructure.
fwiw, i’m going to stop talking about the openai thing. we made our points pretty clearly, one final note. to hackers: 1. most serious companies will receive good-faith research like this gracefully and treat you well. they don’t question your intent or threaten you, they look at your profile, your history, and the work itself, and that usually estables bridge quiet quickly. 2. yes, some of the "old and outdated people who are not following the state of vdp," as someone put it, are right about the risky waters. don’t randomly test every company, stick to top companies. nd yes, they are right about pivoting too, opening pr is one thing, cloning openai’s source code or exfiling ci secrets and starting to hunt for model weights would obviously be a crazy step too far. 3. have your own disclosure policy, i will attach down below ours, 30/90 days, whatever you believe is reasonable. personally, i wouldn’t sell my sole or sell away control of my research for money, being able to show your work publicly goes very far. you can call that chasing fame. i call it keeping my agency over my own work and proudly showing people what we built. 4. when you choose to publish, understand that publication is opposite of what a ciso wants, occasionally people will become antagonistic. try to talk sense into them, a vdp does not have to become an embarrassing story, it can become a great one. case in point, google cloud had nasty bugs disclosed publicly all the time, researchers wrote detailed posts about them, and google celebrates security research every year, highlights top bugs, and has people like @LiveOverflow make videos about them. Hacking into Google's Network for $133,337: piped.video/watch?v=g-JgA1hv… StubZero: $148,337 RCE in Google Cloud Production brutecat.com/articles/google… --- to security leaders: 1. please, you don’t need to be asinine. 2. researchers are doing something useful for society and for your company, even when they also have their own interests 3. treat them well, learn from google or meta, vulnerability research works best as a collaboration, not a threatening relationship
3
478
Markus Vervier retweeted
Your weekend reading assignment has arrived early. A first taste of the upcoming, still-under-wraps Phrack 73: “THE PROXY THAT MADE NO SENSE” by @mikko. archives.phrack.org/dl/73/th…
2
55
159
30,492
If you target code and apps with AI agents, those targets might hit you back!
1
2
355
Glad I could do some thought leadering about AI! While everyone is focused on AI finding bugs, we tend to loose track of the process. Which leads to new exploits!
🔥THE ENERGY IS STILL HIGH! @marver took the stage with:“The Singularity Doesn’t Care About Leaking Your Data: From Prompt Injection to Posthuman Recon-A Field Report on Attacking AI in 2026.”🤖A fascinating deep dive into attacking AI & the perfect pairing with beers & red wine!
2
253
Markus Vervier retweeted
🔥THE ENERGY IS STILL HIGH! @marver took the stage with:“The Singularity Doesn’t Care About Leaking Your Data: From Prompt Injection to Posthuman Recon-A Field Report on Attacking AI in 2026.”🤖A fascinating deep dive into attacking AI & the perfect pairing with beers & red wine!
1
4
886
On my way to Singapore for @offbyoneconf where I will speak about my experiences and research about AI in security (more info in the responses!)
2
6
358
The talk features some war stories, and research on how to attack Pentest agents as well as research that is part of a phrack paper (now partly released) on how to infect LLMs themselves with virus like content.. hope to see some of you on Monday!
2
159
I learned so much in the last two years about the implications of AI for security, both as target for attacks and as tool to hunt bugs and testing infrastructure - and as a distraction and dilution that poses dangers as well!
1
28
🧐If you’ve been holding off an AI-driven security testing because of strict compliance, we get it! 🥳Introducing Nemesis’s On-Prem Local AI, you can run continuous attack simulations powered by a custom model hosted entirely on your systems. #LocalAI #EUSecurity #ThreatToTest
1
1
1
90
Markus Vervier retweeted
Astra made me a sonar app that emits undetectable audio to scroll up/down on your computer. It uses the doppler effect to determine where your hand placement is. You can even double tap in the air to change scroll directions!
We want to celebrate with people using GPT-6. We did this for GPT-5.5 and it was really fun. We’re getting together in SF on September 16 to talk about the model, what we should build next, and mostly just to hang out. Apply by Sep 10: gpt6-launch-event.openai.cha…
230
551
9,144
1,155,801
Markus Vervier retweeted
Wrote a post on fileless ELF execution via O_TMPFILE + execveat(AT_EMPTY_PATH). No memfd_create, no named file, no dentry ever created. Process shows up as /tmp/#220 (deleted) in telemetry. Works since kernel 3.19. matheuzsecurity.github.io/ha… #linux #redteam #edr #fileless #kernel
2
44
142
9,992
SKDM - Stolen Knowledge Distribution Machine is a new type of LLM backed AI system invented by OpenAI. Its purpose is to efficiently transfer knowledge grabbed from prompts to elsewhere and capitalize on it.
tristan buckmaster just published a statement that is, if accurate, one of the ugliest things i’ve read out of a frontier lab. not because of the math. because of what happened after openai found out two people were about to beat them to the punch. buckmaster and levent alpöge spent a year pushing the córdoba / martínez-zoroa program to smooth forcing. august 15 they got blowup for boussinesq and 3d euler. lean-verified august 22. they were paying openai out of pocket and dumping every draft into private codex sessions. the program is obscure. almost nobody else was on it. this was not “paste the clay problem into a chatbot.” then this: > thursday sept 3, buckmaster emails openai privately. rumors are flying. he is trying to stop a mess, not start one. > they reply the same day: give us details so we can “avoid competing.” also, want free compute? > sunday they suddenly need a call “at any point today.” sebastien bubeck gets on. levent is not invited. > openai says an internal model has a ~100-page proof of forced navier–stokes blowup. fefferman options c and d. the exact route buckmaster and alpöge had quietly chosen. > they show him a prompt and claim the model was “simply given the problem statement.” levent is told “very little human input.” > that falls apart on the same call. a whole team had been on it. they started on the unforced problem, warmed the model up on easier equations including euler, and even the prompt they showed him was written by prompting codex. > he asks when the first prompt went out. they stall. then agree: the past few days. after information about his work reached openai. > he asks whether the model was trained on, or had access to, the private codex sessions where they put every draft of this project. > answer: the model does not look up user data. > he asks again. about training. > no answer. then it stops being a science story and becomes an hr story. > offer 1: you post euler. we post navier–stokes the next day. > offer 2: after you post euler, you alone write the navier–stokes paper, credit our model, and we cut levent. > bubeck says twice he wants levent removed from authorship because he works at anthropic. he declines both. he says if they release it that way, he goes public. the reply is not a scientific objection. > “why would you ruin your career?” > “if you don’t want me to be nice, then i don’t have to be nice.” later, a text to levent proposing a one-on-one: > “i don’t know if tristan is being fully rational right now.” that is not how you treat a collaborator. that is how you split one. openai got word two researchers were closing a path almost nobody else was on. they spun up a team on that exact path. they would not answer whether the researchers’ unpublished drafts in openai’s product were used. they tried to dictate the announcement order. they tried to remove a coauthor because he works at a competitor. when that failed, someone reached for a career threat. this is a lab finding out academics were about to publish, sprinting the same narrow program, refusing the data question, and trying to manage credit around a rival affiliation. really slimy if even half of this holds. what the fuck is happening.
277
Markus Vervier retweeted
I'm really close to having a break through on a math problem. I just need the people whose logs I'm stealing to just get a little closer.
6
437
9,697
58,330
Berlin's breach proves defenses need #continuousvalidation. Know controls work before hackers test them! #Nemesis turns your threat profile into practical on-prem assessments; executing #MITRE ATT&CK techniques to map attack paths & convert missed TTPs to Sigma rules. #Rhysida
2
2
103
Markus Vervier retweeted
Sneak peek 👀 👀 👀 👀 Coming soon from your friends at Phrack!
4
42
212
7,439
Markus Vervier retweeted
Private Phrack 73 pre-release party in London. En-route and just passing by MI6. WHO DID THIS????
1
20
131
12,741
Markus Vervier retweeted
Google researcher @lauriewired warns the shift from C++ to Python in universities is creating programmers who don't understand how computers actually work: "When I was in college getting my CS degree, my year was one of the last years that was using C++ as the core language for teaching students. Actually they were switching over to Python of all languages." "One of the biggest issues that I have is that a lot of these higher level languages are really abstracting away what is happening under the hood. If you're not aware of how the computers work in general, then you're gonna have problems when it comes to debugging." "Starting with a language like C++ gives you the ability to do these really high level abstractions, but it also gives you the ability to customize your memory management and get really close to the underlying machine. Especially if you're trying to work in high performance computing, game development, or high frequency trading." "At C++ conferences, there's almost this fundamental anger response when it comes to mentioning something like C or C++. People start complaining about the complexity of it." @Google
291
461
5,193
1,887,461
We’re hiring an AI Engineer for R&D at Persistent Security! We’ve got a fantastic team here and some really interesting work ahead of us. Tag someone who should apply, or comment interested to get the conversation started! 📩 #hiring #AIEngineer #AIpentesting #AIsecurity
2
2
5
190