Sign in

dmnk

@dmnk.bsky.social
1.6K followers 327 following 274 posts

【DΞCOMPILΞ NΣVΞR】 Android Red Team @google Fuzzing @aflplusplus.bsky.social CTF @enoflag (opinions my own)

PostsRepliesMedia
dmnk @dmnk.bsky.social · 28/09/2026
I doubt they wrote the skill my hand
030
dmnk @dmnk.bsky.social · 18/09/2026
Am I the first one to run a 35B model on Android? It's the Edge0 / quen35b quantized MoE guy with a Rust Vulkan inference engine
A screenshot of Quen output on Android
031
Reposted by dmnk
buherator @buherator.bsky.social · 12/09/2026
[RSS] Why is the x86 undefined instruction called ud2? Why 2? devblogs.microsoft.com -> Original->
011
dmnk @dmnk.bsky.social · 10/09/2026
But yes no clue what I'm still doing here lol
000
dmnk @dmnk.bsky.social · 10/09/2026
Random people cross post their stuff here with way fewer random comments for better or worse
100
dmnk @dmnk.bsky.social · 10/09/2026
static.klipy.com
Tumbleweed Rolls Across Desert Highway
ALT: Tumbleweed Rolls Across Desert Highway
000
Reposted by dmnk
Advanced Fuzzing League @aflplusplus.bsky.social · 11/08/2026
Oh look, new version of #LibAFL !! With 0.16.0 we moved non-fuzzer parts into own crates. Crates for pinning cores, rngs, collecing BSODs, and generally helpful rust stuff. Have fun using them for other projects <3 A lot of actual #fuzzer improvements, too, read more at github.com/AFLplusplus/...
github.com
Release 0.16.0 · AFLplusplus/LibAFL
Highlights Split up underlying functionality into multiple reusable crates! build_id2 core_affinity2 exceptional fast_rands ll_mp minibsod no_std_time nonzero_macros ownedref serde_anymap shmem_p...
082
dmnk @dmnk.bsky.social · 02/07/2026
Buing an @ifixit.com kit looks cheap at first, but there's a hidden cost: None of the devices I open work afterwards 😬
041
dmnk @dmnk.bsky.social · 01/07/2026
md-tmpl - strongly typed markdown templates. Writing markdown templates has never been this error free. github.com/domenukk/md-... #markdown #prompt #templates
020
dmnk @dmnk.bsky.social · 22/06/2026
Cool stuff, binary-only fuzzing of iOS kernel yungraj.com/Fuzzing-macO...
yungraj.com
Fuzzing macOS and iOS Kernels with DarwinKit
Fuzzing closed-source operating system kernels has historically been a complex and resource-intensive endeavor. Security researchers targeting Apple’s platforms often faced a choice between slow softw...
060
dmnk @dmnk.bsky.social · 06/06/2026
Same weather as European summer this week
020
Reposted by dmnk
Joseph Cox @josephcox.bsky.social · 01/06/2026
This is absolutely nuts: hackers are hijacking high-profile Instagram accounts by simply asking Meta's AI chatbot to change the email on the account. Meta's AI does it, hacker gets password reset code, they're in. A staggering security issue www.404media.co/hackers-simp...
404media.co
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
The exploit shows the extreme risk of offloading technical support to AI.
27197645106
dmnk @dmnk.bsky.social · 27/05/2026
I wrote a semi popular app at some point. We had a small banner on the bottom. It really helps getting you stars, and that really helps ranking the app up, getting you more downloads, getting you more stars, ... For smaller apps it's important (at least was back in the day)
100
Reposted by dmnk
⚡️🌙 @dystopiabreaker.xyz · 23/05/2026
everything is a bytecode-targetable virtual machine if you look at it sideways. JBIG2 image decompression? virtual machine. x86 mov instruction? virtual machine. truetype fonts? virtual machine. Magic: The Gathering? believe it or not, also virtual machine.
612724
Reposted by dmnk
Rebane @rebane2001.bsky.social · 20/05/2026
accidentally ended up on the news arstechnica.com/security/202...
arstechnica.com
Google publishes exploit code threatening millions of Chromium users
Google publishes exploit code before patch, reported 29 months earlier, is fixed.
510821
Reposted by dmnk
Dr. Holly Walters @manigarm.bsky.social · 17/05/2026
I'm sorry, what? In writing my first monograph, I spent six weeks trying to track down a citation in TWO languages I didn't know. And good thing too, because the citation was wrong. That's scholarship. That's research. You know, the thing we're trained to do?!?
The reactions of some researchers on Twitter finally being held responsible for not having read the very paper they submitted are... something. Mainly, they don't think they should have to check every citation or make sure the data is real and accurate. Because it's too hard, I guess.
484112342255
dmnk @dmnk.bsky.social · 17/05/2026
static.klipy.com
I Love You Binh: Man Cries on Phone
ALT: I Love You Binh: Man Cries on Phone
010
dmnk @dmnk.bsky.social · 15/05/2026
My team on fire 🔥🔥
060
Reposted by dmnk
amos @fasterthanli.me · 14/05/2026
the bun is now rusty, I repeat, the bun has been rusted: github.com/oven-sh/bun/...
github.com
Rewrite Bun in Rust by Jarred-Sumner · Pull Request #30412 · oven-sh/bun
Blog post with details coming soon. Still some optimization work to do before this lands in non-canary version. Still some cleanup work to do (which will come in a series of follow-up PRs)
2324632
dmnk @dmnk.bsky.social · 12/05/2026
Cool stuff, #go fuzzer powered by #LibAFL blog.trailofbits.com/2026/05/12/g...
blog.trailofbits.com
Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.
We built gosentry, a fuzzing-oriented fork of the Go toolchain that keeps the standard fuzzing workflow while using a stronger stack underneath.
050
Reposted by dmnk
P(aul) Frazee @pfrazee.com · 10/05/2026
C has a borrow checker it’s called mythos
1234332
Reposted by dmnk
conputer dipshit @davidcrespo.bsky.social · 05/05/2026
bun appear to be experimenting with a million line claude port from zig to rust lol
github.com
Comparing main...claude/phase-a-port · oven-sh/bun
Incredibly fast JavaScript runtime, bundler, test runner, and package manager – all in one - Comparing main...claude/phase-a-port · oven-sh/bun
1516112
dmnk @dmnk.bsky.social · 06/05/2026
Make no mistakes
000
dmnk @dmnk.bsky.social · 03/05/2026
Just cleaned my 1TB(!) cargo targets folder.. Lol.. How hard can it be to drop stale caches? 🦀🦀🦀 #rust
250
Reposted by dmnk
Jonathan Pallant @thejpster.org.uk · 03/05/2026
This paper finds that Rust on an microcontroller costs you about 10% extra flash space, actually saves you a bunch of RAM, and takes no extra time to deliver (as compared to C). Seems about right - especially as the C version needed a heap and the Rust version did not. arxiv.org/pdf/2604.25679
arxiv.org
57514
Reposted by dmnk
buherator @buherator.bsky.social · 03/05/2026
Original->
Alt text TBD, sorry!
0104
Reposted by dmnk
David Buchanan @retr0.id · 01/05/2026
creepy (black box is me redacting the screenshot, it was 475 words of markdown pasted in)
me: guess the author of this blog post draft

[redacted]

opus 4.7: This reads like David Buchanan (retr0id) to me.
A few signals point that way: the technical register mixes rigorous detail with casual asides ("imho," "no-brainer," "good!"), the willingness to write a polemical "Considered Harmful" post against widely-used tooling, the specific interest in low-level file format / database internals, the offhand mention of demonstrating the issue with a Python script, and the [screenshot ends here]
11032
Reposted by dmnk
Zardus @zardus.bsky.social · 02/05/2026
Reminder! Today is the submission deadline for the first ever Conference of Synthetic Security Research @synsec_ai, so unless you want to gamble on a(nother) extension, warm up those agents and get those papers submitted!
111
dmnk @dmnk.bsky.social · 30/04/2026
AI is cooking to hard bughunters.google.com/blog/evolvin...
bughunters.google.com
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
020
Reposted by dmnk
OffensiveCon @offensivecon.bsky.social · 29/04/2026
Our 2026 agenda is live! 🔗 offensivecon.org/agenda
162
Reposted by dmnk
William B. Fuckley @opinionhaver.bsky.social · 29/04/2026
LLMs are likely going to be the mediating lens through which large swathes of the population make sense of the world around them on political issues, & it's very bad that a man who has a strong case for being one of the worst people alive is one of the few to be actively trying to exploit this
311337174
dmnk @dmnk.bsky.social · 28/04/2026
To be or not to be
000
dmnk @dmnk.bsky.social · 28/04/2026
Don't you just love it when your Agent announces everything works and then lists the six or seven failures it found and ignored..
130
Reposted by dmnk
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 27/04/2026
AI is not going to flood you with real vuln reports unless you have a ton of real vulns. Adding resources to a vuln disclosure process to keep up with triage & bug fixing is a temporary investment at the loud end of the problem, not the right end.
Don’t make me tap the sign.
If your vuln disclosure process gets overwhelmed by AI finding real bugs, then write better code
04516
Reposted by dmnk
Marcel Böhme @mboehme.bsky.social · 27/04/2026
🔥 Our academic keynote at #FUZZING'26 is online! Advancing from "What the fuzz?" to "All the Fuzz" by Mathias Payer (@gannimo.bsky.social). 🌍 fuzzing-workshop.github.io youtu.be/In3kRAVVbzQ?...
youtu.be
NDSS 2026 - FUZZING 2026, Welcome and Opening Remarks, and Keynote by Mathias Payer
YouTube video by NDSS Symposium
183
Reposted by dmnk
rain 🌦️ @sunshowers.io · 27/04/2026
Very much in the mode where I'm hand-writing unsafe Rust code and shouting "PROVE ME WRONG" at Claude
5681
dmnk @dmnk.bsky.social · 24/04/2026
Neat, even has #LibAFL integration github.com/cube0x8/PEMu...
github.com
GitHub - cube0x8/PEMutator: A Rust, format-aware, mutator for PE binary format.
A Rust, format-aware, mutator for PE binary format. - cube0x8/PEMutator
030
dmnk @dmnk.bsky.social · 23/04/2026
If you ask me, obfuscation can go away
010
dmnk @dmnk.bsky.social · 23/04/2026
Apparently we're now obfuscating against LLM reversing www.elastic.co/security-lab...
elastic.co
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation — Elastic Security Labs
Elastic Security Labs explores the ongoing arms race between LLM-driven reverse engineering and obfuscation.
120
Reposted by dmnk
Samuel Groß @saelo.bsky.social · 20/04/2026
The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
project-zero.issues.chromium.org
Project Zero
0135
Reposted by dmnk
The Chaser @chaser.com.au · 22/04/2026
Watchdogs say the previous CEO model suspiciously started slowing down immediately after the announcement chaser.com.au/business/app...
Apple announces new CEO, deliberately slows down old one
774065556
Reposted by dmnk
iximeow @there.is.no.aarch64.mov · 30/03/2026
i got irritated at the ceremony to go from a freshly-created KVM to "can run x86-64 machine code like normal" so i've wrote a small library for exactly that: codeberg.org/iximeow/asml...
codeberg.org
asmlinator
just enough glue on top of KVM to get a VM with one CPU set up to execute `x86_64` instructions.
1658
dmnk @dmnk.bsky.social · 22/04/2026
If only there was a way to automate security
bbc.com
Claude Mythos AI unauthorised access claim probed by Anthropic
The AI company has said the model is too dangerous to release publicly because of its hacking capabilities.
170
dmnk @dmnk.bsky.social · 17/04/2026
Go home @dropbox.com you're drunk
010
dmnk @dmnk.bsky.social · 16/04/2026
We need a fail whale 🐋
000
dmnk @dmnk.bsky.social · 16/04/2026
How cooked 👨‍🍳👩‍🍳👨‍🍳 is vuln research? ☐ Cooked 👨‍🍳 ☐ Cooked 🍳 ☐ Cooked 🔥
120
dmnk @dmnk.bsky.social · 12/04/2026
🙏🙏🙏
000
dmnk @dmnk.bsky.social · 11/04/2026
I'll ask around, but can't promise anything :)
020