Francisco Ribeiro (@blackthorne) 's Twitter Profile
Francisco Ribeiro

@blackthorne

Hacker, Researcher, Engineer.

Previously: XTX Markets, Google, DeepMind, Mimecast, Cisco et al.

ID: 9874712

calendar_today02-11-2007 04:06:28

11,11K Tweet

1,1K Takipçi

2,2K Takip Edilen

SpecterOps (@specterops) 's Twitter Profile Photo

Stop asking LLMs to “find vulns.” Start using them to understand code. Andrew Luke walks through using Claude Code as a force multiplier in app assessments - faster analysis, fewer false positives, better outcomes. Check it out: ghst.ly/4rA3uJd

Nicolas Krassas (@dinosn) 's Twitter Profile Photo

Autonomous penetration testing using a swarm of AI agents. Orchestrates recon, classification, exploitation, and reporting specialists with ReAct reasoning — supports bug bounty, continuous monitoring, and CTF modes. Built with Go, Claude API, and 7+ native security tools.

Steve Weis (@sweis) 's Twitter Profile Photo

Great write up of how Trail of Bits was able to find vulnerabilities in Google’s zero knowledge prover and generate a fake proof: blog.trailofbits.com/2026/04/17/we-…

Marcel Böhme👨‍🔬 (@mboehme_) 's Twitter Profile Photo

From an economic perspective, once we are back to equilibrium, bugs in critical software will be just as difficult to find as they were before AI agents (and before fuzzing). More details: arxiv.org/abs/2402.01944… (Security as a function of incentive)

Vaishnavi Tikke (@vtikke) 's Twitter Profile Photo

GOOGLE BUILT A VULNERABILITY SCANNER AND OPEN-SOURCED IT most devs ship code without knowing half their dependencies are ticking time bombs osv-scanner fixes that it scans your entire project lockfiles, containers, even vendored c/c++ code and maps every dependency against the

NullSecX (@nullsecurityx) 's Twitter Profile Photo

Exploiting llama.cpp’s RPC Server - From Null Buffer to RCE Against PIE + Full RELRO + NX | CVE-2026-34159: The vulnerability is a one-line logic bug in the RPC server’s tensor deserialization pipeline. Youtube: youtube.com/@NullSecurityX Blog: pwntricks.com/ZeroClick-RCE-…

Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

Here's its writeup. Hard bug; both GPT-5.4 and Opus 4.7 tried for multiple days each and failed. gist.github.com/moyix/09d885bc…

Calif (@calif_io) 's Twitter Profile Photo

Welcoming gift for _ZN4DionC1Ev: QEMU and UTM Escape Blog: open.substack.com/pub/calif/p/ma… PoCs: github.com/califio/public… youtube.com/watch?v=WWfxGy…

0xor0ne (@0xor0ne) 's Twitter Profile Photo

Exploring the relationship between compilers, obfuscation, and de-obfuscation by Robert Yates (quarkslab) blog.quarkslab.com/obfuscation-vs… #infosec

Exploring the relationship between compilers, obfuscation, and de-obfuscation by Robert Yates (<a href="/quarkslab/">quarkslab</a>)

blog.quarkslab.com/obfuscation-vs…

#infosec