Jordy Zomer (@pwningsystems) 's Twitter Profile
Jordy Zomer

@pwningsystems

Security Engineer @ Google, likes fuzzing, static analysis and VR.

The opinions stated here are my own, not those of my company.

ID: 4251390837

linkhttps://pwning.systems/ calendar_today22-11-2015 18:22:24

1,1K Tweet

2,2K Takipรงi

242 Takip Edilen

Ian Beer (@i41nbeer) 's Twitter Profile Photo

My writeup of the 2023 NSO in-the-wild iOS zero-click BLASTDOOR webp exploit: Blasting Past Webp - googleprojectzero.blogspot.com/2025/03/blastiโ€ฆ

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

Wrote a MCP server for #CodeQL, tried it out with Cursor and it's quite fun so far! I think the next step would be adding support for query-models. Allowing an LLM to easily add sources/sinks to existing queries could be very promising๐Ÿ˜ github.com/JordyZomer/codโ€ฆ

Rodrigo Branco (@bsdaemon) 's Twitter Profile Photo

I would like to praise Gabriel Negreira Barbosa outstanding contributions to the security community and hacking, not only as editor of the magazine for the past 6+ years, but also for his sharing of perspectives, guidance and technical contributions. In this edition we wrote another small

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

Implementing a custom #CodeQL extractor + libs for an unsupported language is pure torture but hey I found some bugs already so I guess itโ€™s worth it

johannes (@wiknerj) 's Twitter Profile Photo

Branch Race Conditions Predictor causes recent predictions to be added after more recent privilege switches (โ†’ wrong privilege, eIBRS๐Ÿ’ฅ) prediction flushes (โ†’ retained valid, IBPB๐Ÿ’ฅ) finish. Sandro eventually figured it out ๐Ÿ™Œ

Robert Swiecki (@robertswiecki) 's Twitter Profile Photo

My team (AI Systems Security) at Google Zรผrich๐Ÿ‡จ๐Ÿ‡ญis hiring a Security Engineer for AI Vulnerability Research! We're looking for experts to tackle asset exfiltration, tampering and computational resources abuse. Apply: google.com/about/careers/โ€ฆ

Dillon Franke (@dillon_franke) 's Twitter Profile Photo

Slides from my talk are here: dillonfrankesecurity.com/OffensiveCon-2โ€ฆ And the recording is here! youtu.be/USQtPedx9Xg?feโ€ฆ

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

Iโ€™m writing a CodeQL like language for fun that works on Binary Ninja IR, by lowering OOP primitives to datalog for โ€œfunโ€ canโ€™t wait to finds some bugs with it! ๐Ÿ˜๐Ÿ˜

Rodrigo Branco (@bsdaemon) 's Twitter Profile Photo

I really like that hacking zines are now in this trend of having printed copies! It is about time. I got a few to give to folks that can't buy. Lets spread it.

chompie (@chompie1337) 's Twitter Profile Photo

I've been asked countless times how to learn VR & xdev. The answer is always: "do something you think is cool". It's hard to figure out what to do. Try the PhrackCTF which I've now open-sourced. It's not a contrived CTF - modeled after real vulnerabilities github.com/xforcered/Phraโ€ฆ