Sign in

Mark Griffin

@seeinglogic.bsky.social
63 followers 40 following 34 posts

Dev/hacker | Improving human understanding of code | A picture's worth 1KLOC

PostsRepliesMedia
Mark Griffin @seeinglogic.bsky.social · 27/07/2026
ICYMI: First Binary Ninja sale in 10 years, 35% on everything, including renewals(!!) Ends 1 Aug @ noon ET
010
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 08/05/2026
Feb. 6-7, 2027 | See you there 🪩✌️
1147
Reposted by Mark Griffin
RE//verse @re-verse.io · 16/03/2026
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?lis...
084
Mark Griffin @seeinglogic.bsky.social · 17/02/2026
Junkyard was an absolute pleasure to host again, it was awesome to see it take off... we even had a Roller Coaster Tycoon exploit this year! In case you missed the show, @caseyjohnellis gave a great writeup of the EOL targets and exploits shared: cje.io/2026/02/07/f...
cje.io
For the Love of the Game: DistrictCon's Year 1 Junkyard
Notes from judging DistrictCon's Junkyard Year 1 — a Pwn2Own-style exploit contest targeting end-of-life devices. Disco balls, DNA sequencers, gym treadmills, and self-propagating game worms. Includes...
020
Mark Griffin @seeinglogic.bsky.social · 10/12/2025
VSCode has leaned forward on a lot of fantastic usability enhancements... But their recent "terminal autocomplete suggestion" setting has definitely been a mixed bag for me (distracting and suggests bad completions). To disable: settings > "terminal suggest" and uncheck
screenshot of VSCode's integrated terminal auto-suggest
000
Mark Griffin @seeinglogic.bsky.social · 12/10/2025
Want to see the vulnerabilities added for AIxCC? Interested in seeing how well-known C & Java repositories differ in structure/distribution of code? Check out the interactive repo visualizer we made for exploring the scale & detail of AIxCC challenges: archive.aicyberchallenge.com/repoviz/
Screenshot of the 3D repository visualizer showing AIxCC challenge code and associated bug
010
Mark Griffin @seeinglogic.bsky.social · 30/09/2025
Finally ran my own experiment on 2 LiveCTF challenges after seeing an AI bot beat top players on them. Granted, these are the 2 we saw AI solve, but I was still surprised by the success of current models with a single prompt. Sharing so others can try it themselves: seeinglogic.com/posts/livect...
seeinglogic.com
The Beast Opens its Eye: AI at LiveCTF 2025
In the most recent LiveCTF event, we witnessed a turning point: a player brought a custom AI bot that beat both human competitors to the punch… and in the two matches that the bot won, it wasn’t even ...
030
Mark Griffin @seeinglogic.bsky.social · 20/09/2025
Team Atlanta's report explains how their CRS took first in AIxCC: team-atlanta.github.io/papers/TR-Te... And you can just read the code! github.com/Team-Atlanta... The report covers a ton: LLM usage, orchestration, and patching... but really shines in its coverage of practical fuzzing issues.
github.com
GitHub - Team-Atlanta/aixcc-afc-atlantis
Contribute to Team-Atlanta/aixcc-afc-atlantis development by creating an account on GitHub.
000
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 18/09/2025
Interested in Submitting to Junkyard? Want to hang out with fellow researches? Workshopping ideas? Come hang out with the Junkyard Team for a Virtual Happy Hour! Wednesday October 1, 8pm ET (5pm PT) (1, maybe 2 hours?) RSVP: luma.com/949joy6c
luma.com
What The Hack? · Luma
Chris 'flyingtoasters' Holt will host a virtual happy hour to kick off cyber security awareness month, and start the final countdown for Junkyard submissions.…
034
Mark Griffin @seeinglogic.bsky.social · 19/08/2025
ICYMI: 5 systems built to compete in DARPA's AI Cyber Challenge are now Open Source: archive.aicyberchallenge.com Everything from prompt templates, to terraform code, to implementations of very recent research techniques, it's all there.
archive.aicyberchallenge.com
AIxCC Competition Archive | AIxCC Competition Archive
The comprehensive archive of DARPA's Artificial Intelligence Cyber Challenge
011
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 15/08/2025
Our Call for Papers is officially OPEN! We are looking for - Hacking Magic 👾🪄 (cool research, novel TTPs, tool releases, etc.) - Policy Roundtable Topics ⚖️ (specific cyber topics focused on geopolitics, ethics, legal frameworks, governance, etc.) www.districtcon.org/cfp
1138
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 13/08/2025
districtcon.org/junkyard Call for Bugs is still open! Initial submissions close on Oct 24 - submit your best bug in an old deprecated system today 🐛
045
Mark Griffin @seeinglogic.bsky.social · 12/08/2025
The #defcon hardcopy of @phrack.org is a thing of beauty! As usual, the content has excellent technical depth & spirit... I really felt a connection reading Orange Tsai's musings on CTF and his role as a "bug archeologist." Hats off to everyone involved; it will always have a spot on my bookshelf.
Cover art from the DEF CON special hardcopy release of Phrack issue #72.
060
Mark Griffin @seeinglogic.bsky.social · 10/08/2025
If you're not at #defcon right now and feeling some CTF FOMO, you can still tune in and watch the semifinal and final matches of LiveCTF at livectf.com Scroll down for a bracket with matches in your local time, and tune in!
Logo for LiveCTF (livectf.com)
021
Mark Griffin @seeinglogic.bsky.social · 08/08/2025
Live-streamed head-to-head speed CTF sidecar to the DEF CON CTF... it's gonna be awesome!
000
Mark Griffin @seeinglogic.bsky.social · 04/08/2025
If you’re headed to DEF CON, don’t miss the AIxCC exhibit. Not just to see me; though I’ll be there and at LiveCTF... But to meet with some great minds in AI/cybersecurity space, and hear how the data from the competition will might drive a lot of future research. But yes, also come by to see me!
001
Mark Griffin @seeinglogic.bsky.social · 15/07/2025
Just got back from speaking at @summerc0n.bsky.social which was great fun! They really have a unique vibe that's only possible from a small conference with a loyal following. Personally I appreciate the conference's sense of style and personality, and their meme game is impeccable! 😂
000
Mark Griffin @seeinglogic.bsky.social · 25/06/2025
Extremely interesting comparisons in cybersecurity... The 1️⃣ thing to focus on? Talent. Talented people have outsize impacts in software and cybersecurity. And expertise drives better policy (eventually)! Pipelines to build more experts pay compounding returns.
031
Mark Griffin @seeinglogic.bsky.social · 20/06/2025
Had a great time talking with @zardus.bsky.social about getting started in cybersecurity: www.youtube.com/watch?v=n9QW... Primary thrust: Try something that interests you, then keep trying things. Every time, you'll either succeed, learn something, or meet new people, and this builds over time.
youtube.com
seeinglogic and zardus talk about getting into the cybersecurity industry
YouTube video by pwn.college
011
Mark Griffin @seeinglogic.bsky.social · 06/06/2025
Dear Bluesky friends: where do you buy hacker shirts? Looking for something fresh, and there's definitely a line between cool and trying too hard.
000
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 28/05/2025
🚨 CALLING ALL VULNERABILITY RESEARCHERS 🚨 The Junkyard is officially open! This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs! Prizes range from $100 to $5,000 for categories like: ☄️ Most Impactful System 👾 Best Meme Target 👏 Most Engaging Presentation
12018
Mark Griffin @seeinglogic.bsky.social · 22/05/2025
Someone said to me recently "we're going to need people to babysit LLMs that do the work people used to do"... And my knee-jerk response was "I dunno, that sounds like a certain kind of hell to me." Apparently some folks are already testing the waters... github.com/dotnet/runti...
github.com
[iOS][globalization] Implement CompareInfo.Version for hybrid globalization by Copilot · Pull Request #115762 · dotnet/runtime
Issue Currently, CompareInfo.Version throws a PlatformNotSupportedException on iOS/macCatalyst when running in hybrid globalization mode. This implementation provides the Unicode version informatio...
010
Reposted by Mark Griffin
DistrictCon @districtcon.bsky.social · 06/05/2025
We're thrilled to announce we're coming back for DistrictCon Year 1! 🗓️ Jan 24-25, 2026 📍Capitol Hilton Early bird tickets will be sold in September, and GA tickets in November! Call for Talks, Policy roundtables, and Bugs coming soon 😎 www.districtcon.org
districtcon.org
DistrictCon
02512
Mark Griffin @seeinglogic.bsky.social · 28/04/2025
Wrapping up my posts on Python #fuzzing by going through different ways to generate structured/complex inputs: seeinglogic.com/posts/struct... I focused on Python because there isn't as much written on it, but the concepts apply to any language and across tools!
seeinglogic.com
Pattern in the Noise: Structured Fuzzing with Python
“What happens if I need to fuzz something that doesn’t take strings or buffers as inputs” is the question I’ve come to dislike most when talking to people about fuzzing.
000
Mark Griffin @seeinglogic.bsky.social · 23/04/2025
Skip the hype, watch top CTF players for whether LLMs are changing the game (or not). @hgarrereyn.bsky.social tells it like it is and shares his code to boot 👏
000
Mark Griffin @seeinglogic.bsky.social · 16/04/2025
@livectf.bsky.social just posted their challenges and the solutions from the DEF CON quals: github.com/Live-CTF/Liv... This means 6⃣ challenges to replay, with solutions from some of the best CTF teams in the world. Challenge-4 (sokobin) lets you push bits around on the stack to get the flag 🤯
github.com
GitHub - Live-CTF/LiveCTF-DEFCON33
Contribute to Live-CTF/LiveCTF-DEFCON33 development by creating an account on GitHub.
021
Reposted by Mark Griffin
livectf.bsky.social @livectf.bsky.social · 10/04/2025
*tap*, *tap* This thing on? It's that time again! Prepare yourself for another DEF CON CTF qualifiers with a LiveCTF component this weekend! Thanks to @Nautilus_CTF for having us back and running another year! Keep an eye out here and at livectf.com for more details.
livectf.com
LiveCTF
Past events:
043
Mark Griffin @seeinglogic.bsky.social · 30/03/2025
Enjoyed this deep-dive on attempting to exploit AIxCC's NGINX heap bugs: roundofthree.github.io/posts/nginx-... Dense material, but enjoyed that they: - Gave detailed allocator comparison - Tried application-specific approaches - Combined bug primitives - Used a now-public vulnerability dataset!
roundofthree.github.io
Exploitation of AIxCC Nginx bugs: Part I
This blog post will analyse the exploitability of the temporal safety vulnerabilities in Nginx AIxCC. AIxCC is a DARPA competition to find vulnerabilities in codebases using AI. The competitors are no...
000
Mark Griffin @seeinglogic.bsky.social · 28/02/2025
Heard a lot of people wondering how good RE//Verse would be, and I can say... It's been awesome. Similar in vibe to Infiltrate and OffensiveCon, plus a super positive hosting crew. Great talks so far, I'm biased but really liked @mahal0z.bsky.social 's on improving decompilation ⛵
051
Mark Griffin @seeinglogic.bsky.social · 23/02/2025
What an amazing crew, everyone was great and a pleasure to work with. Unbelievable resolve and effort... to run a con with the lights out!
010
Mark Griffin @seeinglogic.bsky.social · 19/02/2025
Just pushed an update to Ariadne that makes it compatible with Binary Ninja's dev branch. Thanks to unknowntrojan on GitHub for the PR! github.com/seeinglogic/...
github.com
GitHub - seeinglogic/ariadne: Ariadne: Binary Ninja Graph Analysis Plugin
Ariadne: Binary Ninja Graph Analysis Plugin. Contribute to seeinglogic/ariadne development by creating an account on GitHub.
000
Mark Griffin @seeinglogic.bsky.social · 13/02/2025
Report from CISA & friends on the Software Understanding Gap leading to national security-level issues: media.defense.gov/2025/Jan/16/... This is what I'm working on improving, right in the IDE. Reach out if you or your team wants to understand code better, I'd like to hear about your problems.
media.defense.gov
120
Mark Griffin @seeinglogic.bsky.social · 16/01/2025
Looking back, what made ShmooCon so awesome? My two cents: 1) community 2) high quality talks on a wide variety of topics. Greg Conti & co made this to depict the 801 talks over the last 20 years... and I added arrows to show where my two snowflakes are on the mountain. We'll miss you, ShmooCon.
Data art of a stacked area chart arranged to look like a mountain scene. Annotations added to show categorization of author's talks in 2020 and 2024. Original source: https://www.kopidion.com/projects.html
010
Reposted by Mark Griffin
RE//verse @re-verse.io · 09/01/2025
Our 2025 RE//verse talk schedule is now live! Talks start Friday, but don't forget to check the Thursday schedule and arrive early enough for the kick-off event! re-verse.io/schedule.html?utm_sourc…
re-verse.io
RE//verse
RE//verse is a premier reverse engineering, vulnerability research and malware analysis conference. We offer trainings and talks from industry-leading experts.
01110
Mark Griffin @seeinglogic.bsky.social · 09/01/2025
See you at Shmoo! A huge thanks to the Shmoo crew... it has been one of my favorite cons and has a special place in my heart as my first big con to speak at. To commemorate the Final ShmooCon, please give this a listen and substitute "Countdown" with #shmoocon in your head: youtu.be/9jK-NcRmVcw 🚀
youtu.be
Europe - The Final Countdown (Official Video)
YouTube video by EuropeVEVO
020
Mark Griffin @seeinglogic.bsky.social · 18/12/2024
For the coders who just need a laugh right now... This was even better than I expected 😂 Also, I love "pippo" even though I don't think I've ever seen it used before... www.youtube.com/watch?v=yup8...
youtube.com
NANOWAR OF STEEL - HelloWorld.java (Source Code Video) | Napalm Records
YouTube video by Napalm Records
000
Mark Griffin @seeinglogic.bsky.social · 13/12/2024
Just pushed some #Python fuzzing example code to go along with the tutorial posts from my blog. Check it out to see: - A basic template you can reuse and adapt - How to build basic valid inputs from fuzz data - Demo of property testing & differential fuzzing Repo: github.com/seeinglogic/...
github.com
GitHub - seeinglogic/python-fuzzing
Contribute to seeinglogic/python-fuzzing development by creating an account on GitHub.
120
Mark Griffin @seeinglogic.bsky.social · 06/12/2024
Best time of year is here, adventofcode.com time 🎄 Fantastic refresher, speed challenge, or for trying new languages/ideas. The problems are fun, and start easy but get harder. Plus they aren't linked, so don't worry about starting late or skipping a day. Let me know if you give it a try!
adventofcode.com
Advent of Code 2024
000
Mark Griffin @seeinglogic.bsky.social · 06/11/2024
Curious about property-based testing or differential fuzzing for #Python? How about a method to help catch hidden assumptions in AI-generated code? Check out how to apply expert testing methods to find unexpected correctness bugs in non-trivial code: seeinglogic.com/posts/checki...
seeinglogic.com
Fuzzing Python for Correctness: Checking on ChatGPT
One of the biggest issues with LLM-generated code is a lack of trust, mostly stemming from a lack of understanding from not having written it personally, and reduced confidence that the code handles e...
000
Mark Griffin @seeinglogic.bsky.social · 25/10/2024
Hello, Bluesky! I'm into the intersection of #visualization #hacking #coding , if you like that sort of thing, then check out my blog or connect with me! www.seeinglogic.com
010