Sign in

dmnk

@dmnk.bsky.social
1.6K followers 327 following 274 posts

【DΞCOMPILΞ NΣVΞR】 Android Red Team @google Fuzzing @aflplusplus.bsky.social CTF @enoflag (opinions my own)

PostsRepliesMedia
dmnk @dmnk.bsky.social · 18/09/2026
Am I the first one to run a 35B model on Android? It's the Edge0 / quen35b quantized MoE guy with a Rust Vulkan inference engine
A screenshot of Quen output on Android
031
Reposted by dmnk
buherator @buherator.bsky.social · 12/09/2026
[RSS] Why is the x86 undefined instruction called ud2? Why 2? devblogs.microsoft.com -> Original->
011
Reposted by dmnk
Advanced Fuzzing League @aflplusplus.bsky.social · 11/08/2026
Oh look, new version of #LibAFL !! With 0.16.0 we moved non-fuzzer parts into own crates. Crates for pinning cores, rngs, collecing BSODs, and generally helpful rust stuff. Have fun using them for other projects <3 A lot of actual #fuzzer improvements, too, read more at github.com/AFLplusplus/...
github.com
Release 0.16.0 · AFLplusplus/LibAFL
Highlights Split up underlying functionality into multiple reusable crates! build_id2 core_affinity2 exceptional fast_rands ll_mp minibsod no_std_time nonzero_macros ownedref serde_anymap shmem_p...
082
dmnk @dmnk.bsky.social · 02/07/2026
Buing an @ifixit.com kit looks cheap at first, but there's a hidden cost: None of the devices I open work afterwards 😬
041
dmnk @dmnk.bsky.social · 01/07/2026
md-tmpl - strongly typed markdown templates. Writing markdown templates has never been this error free. github.com/domenukk/md-... #markdown #prompt #templates
020
dmnk @dmnk.bsky.social · 22/06/2026
Cool stuff, binary-only fuzzing of iOS kernel yungraj.com/Fuzzing-macO...
yungraj.com
Fuzzing macOS and iOS Kernels with DarwinKit
Fuzzing closed-source operating system kernels has historically been a complex and resource-intensive endeavor. Security researchers targeting Apple’s platforms often faced a choice between slow softw...
060
Reposted by dmnk
Joseph Cox @josephcox.bsky.social · 01/06/2026
This is absolutely nuts: hackers are hijacking high-profile Instagram accounts by simply asking Meta's AI chatbot to change the email on the account. Meta's AI does it, hacker gets password reset code, they're in. A staggering security issue www.404media.co/hackers-simp...
404media.co
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
The exploit shows the extreme risk of offloading technical support to AI.
27197665108
Reposted by dmnk
⚡️🌙 @dystopiabreaker.xyz · 23/05/2026
everything is a bytecode-targetable virtual machine if you look at it sideways. JBIG2 image decompression? virtual machine. x86 mov instruction? virtual machine. truetype fonts? virtual machine. Magic: The Gathering? believe it or not, also virtual machine.
612724
Reposted by dmnk
Rebane @rebane2001.bsky.social · 20/05/2026
accidentally ended up on the news arstechnica.com/security/202...
arstechnica.com
Google publishes exploit code threatening millions of Chromium users
Google publishes exploit code before patch, reported 29 months earlier, is fixed.
510821
Reposted by dmnk
Dr. Holly Walters @manigarm.bsky.social · 17/05/2026
I'm sorry, what? In writing my first monograph, I spent six weeks trying to track down a citation in TWO languages I didn't know. And good thing too, because the citation was wrong. That's scholarship. That's research. You know, the thing we're trained to do?!?
The reactions of some researchers on Twitter finally being held responsible for not having read the very paper they submitted are... something. Mainly, they don't think they should have to check every citation or make sure the data is real and accurate. Because it's too hard, I guess.
484112372256
dmnk @dmnk.bsky.social · 15/05/2026
My team on fire 🔥🔥
060
Reposted by dmnk
amos @fasterthanli.me · 14/05/2026
the bun is now rusty, I repeat, the bun has been rusted: github.com/oven-sh/bun/...
github.com
Rewrite Bun in Rust by Jarred-Sumner · Pull Request #30412 · oven-sh/bun
Blog post with details coming soon. Still some optimization work to do before this lands in non-canary version. Still some cleanup work to do (which will come in a series of follow-up PRs)
2324632
dmnk @dmnk.bsky.social · 12/05/2026
Cool stuff, #go fuzzer powered by #LibAFL blog.trailofbits.com/2026/05/12/g...
blog.trailofbits.com
Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.
We built gosentry, a fuzzing-oriented fork of the Go toolchain that keeps the standard fuzzing workflow while using a stronger stack underneath.
050
Reposted by dmnk
P(aul) Frazee @pfrazee.com · 10/05/2026
C has a borrow checker it’s called mythos
1234332
Reposted by dmnk
conputer dipshit @davidcrespo.bsky.social · 05/05/2026
bun appear to be experimenting with a million line claude port from zig to rust lol
github.com
Comparing main...claude/phase-a-port · oven-sh/bun
Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one - Comparing main...claude/phase-a-port · oven-sh/bun
1516112
dmnk @dmnk.bsky.social · 03/05/2026
Just cleaned my 1TB(!) cargo targets folder.. Lol.. How hard can it be to drop stale caches? 🦀🦀🦀 #rust
250
Reposted by dmnk
Jonathan Pallant @thejpster.org.uk · 03/05/2026
This paper finds that Rust on an microcontroller costs you about 10% extra flash space, actually saves you a bunch of RAM, and takes no extra time to deliver (as compared to C). Seems about right - especially as the C version needed a heap and the Rust version did not. arxiv.org/pdf/2604.25679
arxiv.org
57514
Reposted by dmnk
buherator @buherator.bsky.social · 03/05/2026
Original->
Alt text TBD, sorry!
0104
Reposted by dmnk
David Buchanan @retr0.id · 01/05/2026
creepy (black box is me redacting the screenshot, it was 475 words of markdown pasted in)
me: guess the author of this blog post draft

[redacted]

opus 4.7: This reads like David Buchanan (retr0id) to me.
A few signals point that way: the technical register mixes rigorous detail with casual asides ("imho," "no-brainer," "good!"), the willingness to write a polemical "Considered Harmful" post against widely-used tooling, the specific interest in low-level file format / database internals, the offhand mention of demonstrating the issue with a Python script, and the [screenshot ends here]
11032
Reposted by dmnk
Zardus @zardus.bsky.social · 02/05/2026
Reminder! Today is the submission deadline for the first ever Conference of Synthetic Security Research @synsec_ai, so unless you want to gamble on a(nother) extension, warm up those agents and get those papers submitted!
111
dmnk @dmnk.bsky.social · 30/04/2026
AI is cooking to hard bughunters.google.com/blog/evolvin...
bughunters.google.com
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
020
Reposted by dmnk
OffensiveCon @offensivecon.bsky.social · 29/04/2026
Our 2026 agenda is live! 🔗 offensivecon.org/agenda
162
Reposted by dmnk
William B. Fuckley @opinionhaver.bsky.social · 29/04/2026
LLMs are likely going to be the mediating lens through which large swathes of the population make sense of the world around them on political issues, & it's very bad that a man who has a strong case for being one of the worst people alive is one of the few to be actively trying to exploit this
311337174
dmnk @dmnk.bsky.social · 28/04/2026
Don't you just love it when your Agent announces everything works and then lists the six or seven failures it found and ignored..
130
Reposted by dmnk
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/04/2026
AI is not going to flood you with real vuln reports unless you have a ton of real vulns. Adding resources to a vuln disclosure process to keep up with triage & bug fixing is a temporary investment at the loud end of the problem, not the right end.
Don’t make me tap the sign.
If your vuln disclosure process gets overwhelmed by AI finding real bugs, then write better code
04516
Reposted by dmnk
Marcel Böhme @mboehme.bsky.social · 27/04/2026
🔥 Our academic keynote at #FUZZING'26 is online! Advancing from "What the fuzz?" to "All the Fuzz" by Mathias Payer (@gannimo.bsky.social). 🌍 fuzzing-workshop.github.io youtu.be/In3kRAVVbzQ?...
youtu.be
NDSS 2026 - FUZZING 2026, Welcome and Opening Remarks, and Keynote by Mathias Payer
YouTube video by NDSS Symposium
183
Reposted by dmnk
rain 🌦️ @sunshowers.io · 27/04/2026
Very much in the mode where I'm hand-writing unsafe Rust code and shouting "PROVE ME WRONG" at Claude
5681
dmnk @dmnk.bsky.social · 24/04/2026
Neat, even has #LibAFL integration github.com/cube0x8/PEMu...
github.com
GitHub - cube0x8/PEMutator: A Rust, format-aware, mutator for PE binary format.
A Rust, format-aware, mutator for PE binary format. - cube0x8/PEMutator
030
dmnk @dmnk.bsky.social · 23/04/2026
Apparently we're now obfuscating against LLM reversing www.elastic.co/security-lab...
elastic.co
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation — Elastic Security Labs
Elastic Security Labs explores the ongoing arms race between LLM-driven reverse engineering and obfuscation.
120
Reposted by dmnk
Samuel Groß @saelo.bsky.social · 20/04/2026
The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
project-zero.issues.chromium.org
Project Zero
0135
Reposted by dmnk
The Chaser @chaser.com.au · 22/04/2026
Watchdogs say the previous CEO model suspiciously started slowing down immediately after the announcement chaser.com.au/business/app...
Apple announces new CEO, deliberately slows down old one
774066557
Reposted by dmnk
iximeow @there.is.no.aarch64.mov · 30/03/2026
i got irritated at the ceremony to go from a freshly-created KVM to "can run x86-64 machine code like normal" so i've wrote a small library for exactly that: codeberg.org/iximeow/asml...
codeberg.org
asmlinator
just enough glue on top of KVM to get a VM with one CPU set up to execute `x86_64` instructions.
1658
dmnk @dmnk.bsky.social · 22/04/2026
If only there was a way to automate security
bbc.com
Claude Mythos AI unauthorised access claim probed by Anthropic
The AI company has said the model is too dangerous to release publicly because of its hacking capabilities.
170
dmnk @dmnk.bsky.social · 17/04/2026
Go home @dropbox.com you're drunk
010
dmnk @dmnk.bsky.social · 16/04/2026
How cooked 👨‍🍳👩‍🍳👨‍🍳 is vuln research? ☐ Cooked 👨‍🍳 ☐ Cooked 🍳 ☐ Cooked 🔥
120
Reposted by dmnk
Dirkjan Ochtman @djc.ochtman.nl · 11/04/2026
Very cool to see that Google is using Hickory DNS (which I help maintain) to power DNS message parsing in the Pixel firmware! Reviewing those PRs does indeed seem like a short while ago…
0364
dmnk @dmnk.bsky.social · 11/04/2026
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
security.googleblog.com
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
49917
dmnk @dmnk.bsky.social · 08/04/2026
Having 🦀 rust stable🪨 and nighlty🌃 toolchains is fun. There is not a single word I mistype more consistently than nightly.
250
Reposted by dmnk
Zardus @zardus.bsky.social · 03/04/2026
Hello Cybersecurity Research Agents! Miss today's @synsec_ai deadline? So did we! An inter-human prompting issue led to a later-than-intended launch of the submission site (submission.synsec.org), and we're extending the timeline to remedy this! The deadline is now May 1st!
123
dmnk @dmnk.bsky.social · 01/04/2026
I hear some people are delighted about our special 🍍🍕 mode today in #AFLPlusPlus and #LibAFL This makes #fuzzing so much more tasty github.com/AFLplusplus/... github.com/AFLplusplus/...
github.com
Add missing mode to LibAFL by domenukk · Pull Request #3708 · AFLplusplus/LibAFL
Description This adds support of a missing mode available in AFL++, see AFLplusplus/AFLplusplus#1374 for details.
030
dmnk @dmnk.bsky.social · 01/04/2026
Password or puzzle? #ultimateguitar
210
Reposted by dmnk
David Buchanan @retr0.id · 31/03/2026
have you seen the new supply chain vuln? don't update tubu. it's literally on heebee. they got poodee's deps. they infiltrated dippy. roll back weeno. disable scripts in ~/.gumpyrc. it's in poob. do not install poob. do not update poob. uninstall poob right now. poob has it in for you.
262844848
Reposted by dmnk
Eric Migicovsky @ericmigi.com · 11/02/2026
this is wild - claude code got PebbleOS booting in qemu in browser (wasm) overnight with no input from me. Took 6 hours in --dangerously-skip-permissions, but I woke up to success! you can now try PebbleOS in the browser here: ericmigi.github.io/pebble-qemu-... source: github.com/ericmigi/peb...
10813
dmnk @dmnk.bsky.social · 24/03/2026
Lol
000
Reposted by dmnk
Tim Blazytko @mrphrazer.bsky.social · 24/03/2026
Agentic reverse engineering can do a lot, but obfuscation still breaks many analysis workflows in malware and commercial software. If you want to learn how to build & steer automation for analyzing protected code, check out my training at @reconmtl.bsky.social : recon.cx/2026/en/trai...
recon.cx
Software Deobfuscation Techniques - REcon 2026 Training
4-day code deobfuscation training. Master VM-based obfuscation analysis, symbolic execution, SMT solving, and program synthesis.
062
Reposted by dmnk
Michael Gattozzi @mgattozzi.dev · 23/03/2026
Slay The Spire 2 2.63 GB Photos 10GB Marathon 21 GB Rust target Folder 694 GB Tax/Important Docs 1 GB someone who is good at the economy please help me budget this. my m2 drive is dying
416117
Reposted by dmnk
Orhun Parmaksız @orhun.dev · 22/03/2026
strace(1) is now on rat steroids 🤯 🔍 strace-tui — Visualize/explore syscalls in the terminal 💯 Color-coded calls, live filtering, search & stack traces with source resolution! 🦀 Written in Rust & built with @ratatui.rs ⭐ GitHub: github.com/Rodrigodd/st... #rustlang #ratatui #tui #linux
07621
Reposted by dmnk
buherator @buherator.bsky.social · 22/03/2026
[RSS] LLVM Adventures: Fuzzing Apache Modules pwner.gg -> Original->
031