adam @appsec.bsky.social · 09/09/2026Less than a week to make major strides with Navier–Stokes. 🤯 We've spent decades asking what computers can't efficiently compute. What happens when the computers start answering that question? 000
adam @appsec.bsky.social · 09/09/2026IANAM (I am not a mathematician) but... if @OpenAI or @anthropic.com target P=NP next, things could get really interesting. A proof that P=NP would have enormous implications for cryptography - breaking computational assumptions that even quantum-resistant crypto is designed around. 000
adam @appsec.bsky.social · 08/09/2026I'm speaking at @blueteamcon.com 2026 in Chicago. "Too Big To Review" - what happens to AppSec when AI turns your engineering team into a 10x output machine and your review capacity stays the same. Spoiler: hiring more security engineers isn't the answer. blueteamcon.com 041
adam @appsec.bsky.social · 08/09/2026"Since August 28th, we have been training a new internal model that has exhibited unprecedented performance in our benchmarks, including mathematics." 🤯 It took TEN DAYS to solve a millennium problem. This is AGI in the making, wow. openai.com/index/navier...openai.comOn the Navier–Stokes Millennium Prize ProblemWe’re sharing an AI-generated solution to the Navier–Stokes Millennium Prize Problem, including a writeup and a formal proof in Lean. 001
adam @appsec.bsky.social · 27/08/2026Check out the open letter from OpenAI plus 100+ firms warning that AI models will soon enable far more sophisticated cyberattacks. A short "defenders' window" exists to fix vulnerabilities and arm defenders with AI tools before that happens. openai.com/collective-c... 022
adam @appsec.bsky.social · 25/08/2026I scored 2910 on Patch or Panic and ranked 13 CVEs correctly, the vulnerability severity game by @pixee.ai. Can you beat me? cve.wiki/s/98cab768ee... cve.wikicve.wikiI scored 2910 on Patch or Panic13 CVEs ranked correctly. Can you beat 2910 points? 000
adam @appsec.bsky.social · 21/08/2026My absolute favorite Christopher Walken role of all time. youtube.com/watch?v=7qJu... Poolhall Junkies. Underrated movie. I haven't seen it in a while, but randomly thought of this scene today. Go give it a watch if you haven't seen it.youtube.comPoolhall Junkies - Christopher Walken - King of the Jungle speechYouTube video by moncorp1 Inc 000
adam @appsec.bsky.social · 25/06/2026🚂 Speaking at Hobocon this July, a hacker conference on a moving train. "All Aboard IDOR Express" - how when submitting a CFP, I found an IDOR showing me all of the security conference's submissions. OWASP A01. 🚂 July 17–18, KC ↔ Chicago. www.hobocon.com Nothing like a captive audience. 000
adam @appsec.bsky.social · 16/06/2026My talk "Too Big to Review" was just accepted at @blueteamcon.com 2026 🎉 September 12th in Chicago - come hear how we scaled AppSec at AWS without scaling the team. #AppSec #BlueTeamCon 011
adam @appsec.bsky.social · 25/01/2026New blog post - Automation for AppSec blog.adamschaal.com/posts/2026-0...blog.adamschaal.comAutomation for AppSec at AWS (Part 1)How automation and generative AI are transforming application security at AWS, from deterministic checks to context-aware reviews. 021
adam @appsec.bsky.social · 24/12/2025The night of October 20th, I woke up ice-cold. My bed had cooled all the way to 55° F and I couldn't adjust it at all. The irony: this was due to an AWS failure. Read more about removing my bed's cloud dependency. blog.adamschaal.com/posts/2025-1...blog.adamschaal.comRooting My Eight Sleep Pod 3A technical deep-dive into rooting and customizing my Eight Sleep smart mattress. 021
adam @appsec.bsky.social · 05/12/2025I dockerized a proof-of-concept for CVE-2025-55182 (React2Shell) here - github.com/clevernyyyy/... Original POC by github.com/msanft.github.comGitHub - clevernyyyy/CVE-2025-55182-DockerizedContribute to clevernyyyy/CVE-2025-55182-Dockerized development by creating an account on GitHub. 020
adam @appsec.bsky.social · 01/12/2025Super excited for the World Cup draw on Friday. ⚽️ 🥅 Can't wait to see what matchups we can attend! 000
adam @appsec.bsky.social · 25/11/2025Writing is something I'm always challenging myself to be better at. This fall, my friend @themattvirus.bsky.social and I were pleased to attend BruCON, a security conference in Belgium and I've finally managed to put together my BruCON review: blog.adamschaal.com/posts/2025-1...blog.adamschaal.comBruCON 2025 – Beer, Waffles, and a Product Review CabalNotes from BruCON in Belgium, our talk with Matt Virus, beer-and-waffles lore, and a solo CTF run to 22nd place. 020
adam @appsec.bsky.social · 15/11/2025I always appreciate the little details in the DEF CON 402 ornaments from @tvidas.bsky.social like this one from 2020. Hard to believe how long our community has been together, really thankful for the friends I've made in dc402.org. ⚡ talks in December! 020
adam @appsec.bsky.social · 23/10/2025Yes, @themattvirus.bsky.social and I visited the Louvre on our trip to BruCON. Yes, we cased the jewels, and noted that their cameras were obsolete [1] for our talk, but no, we did not steal them. [1] www.artnews.com/art-news/new... 020
adam @appsec.bsky.social · 25/09/2025Speaking at BruCON in t-minus 12 hours with @themattvirus.bsky.social. We've prepared as much as we can with waffles, beer, and club mate, we are almost fully Belgian now. 🇧🇪 020
adam @appsec.bsky.social · 21/06/2025At AWS, our GenAI development is moving at 🚀 warp speed. With new tools popping up faster than browser tabs in my macbook, my team created Nebula – a system to track all our GenAI initiatives. Today, we just launched an AI assistant to help upload new tools to Nebula tracker. 000
adam @appsec.bsky.social · 04/06/2025Thrilled to share that @themattvirus.bsky.social and I are speaking at BruCON this year! The lineup is 🔥 so far and we can't wait to reconnect with our amazing European hacking friends. Always a highlight to be among that fantastic community. www.brucon.orgbrucon.orgBruCON | Security and hacker conference and trainingBruCON is an annual security and hacker conference In Belgium with two days of an interesting atmosphere for open discussions of critical infosec issues, privacy, information technology and its cultur... 000
adam @appsec.bsky.social · 02/06/2025🎯NIST's updated security guidelines finally hit the mark. 1. No more forced password changes 2. Longer passwords beat complexity rules 3. Security responsibility shifts to providers where it belongs. Common sense security FTW. pages.nist.gov/800-63-4/sp8...pages.nist.govNIST Special Publication 800-63BNIST Special Publication 800-63B 001
adam @appsec.bsky.social · 18/03/2025Believe. www.nytimes.com/2025/03/14/a...nytimes.com‘Ted Lasso’ Is Coming BackApple TV+ announced on Friday that the Emmy-winning comedy will return for a fourth season. Jason Sudeikis will be back to reprise the title role. 000
adam @appsec.bsky.social · 14/03/20251/n - Today at kernelcon.bsky.social, we were notified that our registration was down. We immediately jumped on our phones to check and sure enough, clicking our registration buttons led to a 503. However, our eventzilla admin page was up, and we could access our event through that site, hmm?kernelcon.bsky.socialKernelcon (@kernelcon.bsky.social)OMAHA’S HACKER CON https://infosec.exchange/@kernelcon 🏆Training: 4.1-2 🚦Con: 4.3-4 🔀 New venue: Hilton downtown Omaha 🏎️ CFP IS closed! 📝 http://reg.kernelcon.org 100
adam @appsec.bsky.social · 11/03/2025For 311 day, don't forget to kick it Omaha Stylee and get your tickets to @kernelcon.bsky.social! youtu.be/rokq0CIfXXk?... kernelcon.orgyoutu.beOmaha StyleeYouTube video by 311 - Topic 000
adam @appsec.bsky.social · 05/03/2025Kernelcon Agenda is LIVE! kernelcon.org/agenda Room block closes on March 7th, please go get your rooms and tickets now.kernelcon.org 000
adam @appsec.bsky.social · 01/03/2025🤦♂️ What is going on? therecord.media/hegseth-orde...therecord.mediaExclusive: Hegseth orders Cyber Command to stand down on Russia planningThe secretary of Defense has ordered U.S. Cyber Command to stand down from all planning against Russia, including offensive digital actions, sources tell Recorded Future News. 000
adam @appsec.bsky.social · 21/02/2025I hate pointing out flaws in a system and the subsequent team expecting my team to own the outcome of escalating for a fix. Ownership is maybe the most important trait of a team leader. 000
adam @appsec.bsky.social · 03/02/2025More details on kernelcon.org/robo-race. There might be some custom swag for participants who bring their own robot for the competition!kernelcon.org 000
adam @appsec.bsky.social · 23/01/2025This is really exciting... I can't wait to see what our community comes up with. Prizes for fastest and best dressed robot! And for the robo-curious we will have our own to play with. 000
adam @appsec.bsky.social · 13/01/2025Had a ton of fun speaking at Shmoocon this year, I really enjoyed this con and wish the best for Heidi, Bruce, and the volunteers in future endeavors! 010
adam @appsec.bsky.social · 28/11/2024I'm loving my Rivian so far. I picked up the Tri-motor in Storm Blue. If you're interested in an EV, especially one not produced by Elon, we each get $750 if you use my referral code. code: ADAM1508922 Now that they've teamed up with VW, I think they'll be even more popular. #rivian 010
adam @appsec.bsky.social · 18/10/2023Wow, this is crazy. A "researcher" uses an LLM to find a vulnerability in curl that is COMPLETELY hallucinated. What a waste of time. hackerone.com/reports/2199... 011
adam @appsec.bsky.social · 19/08/2023Had a great time in Germany with @themattvirus.bsky.social speaking at Chaos Communication Camp. I would love to come back in four years! 001
adam @appsec.bsky.social · 31/07/2023My wife and I every time I have an upcoming talk. Looking forward to #cccamp23! 000
adam @appsec.bsky.social · 07/07/2023Yay, @themattvirus.bsky.social and I just had our talk accepted to #cccamp23 in Germany. On the hunt for tickets now, but sounds like a ton of fun! 111
adam @appsec.bsky.social · 06/07/2023Happy to finally join blue sky. Hopeful for potential, but kind of hedging bets all over right now. 150