jayden (@0jayden_) 's Twitter Profile
jayden

@0jayden_

ID: 2345657364

calendar_today15-02-2014 19:55:36

1 Tweet

15 Followers

2 Following

Veria Labs (@verialabs) 's Twitter Profile Photo

đź§µ We just discovered critical RCE vulnerabilities in popular AI coding tools including Claude Code and Gemini CLI. The issue: These tools use OAuth for MCP (Model Context Protocol) authentication, but don't validate authorization URLs from servers.

.;,;. (@smiley_ctf) 's Twitter Profile Photo

We're officially top 3 in the world on CTFtime for 2025, up from 13th last year! yay This year, we also: - hosted the first ever smileyCTF, with 1,000+ teams playing - went to in-person CTFs in Switzerland, Las Vegas, NYC * 2 - qualified for SECCON and LakeCTF 2026 finals

We're officially top 3 in the world on CTFtime for 2025, up from 13th last year! yay

This year, we also: 
- hosted the first ever smileyCTF, with 1,000+ teams playing
- went to in-person CTFs in Switzerland, Las Vegas, NYC * 2
- qualified for SECCON and LakeCTF 2026 finals
stuxf (@stuxfdev) 's Twitter Profile Photo

We spun out of the #1 hacking team in the US and built AI that finds what even the best hackers miss. During one engagement, it found 6 different ways to take over any user's account on a popular webapp. Completely autonomously. Then suggested fixes for every single one. Today

We spun out of the #1 hacking team in the US and built AI that finds what even the best hackers miss.

During one engagement, it found 6 different ways to take over any user's account on a popular webapp. Completely autonomously. Then suggested fixes for every single one.

Today
.;,;. (@smiley_ctf) 's Twitter Profile Photo

We just qualified 2 teams for DiceCTF Finals, with one of our teams getting 2nd place overall! Congrats BunkyoWesterns on winning and we'll see everyone in NYC! insert line about llms ruining ctfs here

We just qualified 2 teams for DiceCTF Finals, with one of our teams getting 2nd place overall! Congrats <a href="/BunkyoWesterns/">BunkyoWesterns</a> on winning and we'll see everyone in NYC!

insert line about llms ruining ctfs here
jayden (@0jayden_) 's Twitter Profile Photo

Starting a series where we write up interesting vulns our agent at Veria Labs finds: First up, 1-click RCE in Goose, Block's coding agent with 33k+ stars: verialabs.com/blog/securing-… Goose was vulnerable to CSWSH, allowing an attacker-controlled website to run arbitrary commands.