Jordy Zomer (@pwningsystems) 's Twitter Profile
Jordy Zomer

@pwningsystems

Security Engineer @ Google, likes fuzzing, static analysis and VR.

The opinions stated here are my own, not those of my company.

ID: 4251390837

linkhttps://pwning.systems/ calendar_today22-11-2015 18:22:24

1,1K Tweet

2,2K Followers

242 Following

Ian Beer (@i41nbeer) 's Twitter Profile Photo

My writeup of the 2023 NSO in-the-wild iOS zero-click BLASTDOOR webp exploit: Blasting Past Webp - googleprojectzero.blogspot.com/2025/03/blasti…

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

Wrote a MCP server for #CodeQL, tried it out with Cursor and it's quite fun so far! I think the next step would be adding support for query-models. Allowing an LLM to easily add sources/sinks to existing queries could be very promising😁 github.com/JordyZomer/cod…

Rodrigo Branco (@bsdaemon) 's Twitter Profile Photo

I would like to praise Gabriel Negreira Barbosa outstanding contributions to the security community and hacking, not only as editor of the magazine for the past 6+ years, but also for his sharing of perspectives, guidance and technical contributions. In this edition we wrote another small

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

Implementing a custom #CodeQL extractor + libs for an unsupported language is pure torture but hey I found some bugs already so I guess it’s worth it

johannes (@wiknerj) 's Twitter Profile Photo

Branch Race Conditions Predictor causes recent predictions to be added after more recent privilege switches (→ wrong privilege, eIBRS💥) prediction flushes (→ retained valid, IBPB💥) finish. Sandro eventually figured it out 🙌

Robert Swiecki (@robertswiecki) 's Twitter Profile Photo

My team (AI Systems Security) at Google Zürich🇨🇭is hiring a Security Engineer for AI Vulnerability Research! We're looking for experts to tackle asset exfiltration, tampering and computational resources abuse. Apply: google.com/about/careers/…

Dillon Franke (@dillon_franke) 's Twitter Profile Photo

Slides from my talk are here: dillonfrankesecurity.com/OffensiveCon-2… And the recording is here! youtu.be/USQtPedx9Xg?fe…

Jordy Zomer (@pwningsystems) 's Twitter Profile Photo

I’m writing a CodeQL like language for fun that works on Binary Ninja IR, by lowering OOP primitives to datalog for “fun” can’t wait to finds some bugs with it! 😁😁

Rodrigo Branco (@bsdaemon) 's Twitter Profile Photo

I really like that hacking zines are now in this trend of having printed copies! It is about time. I got a few to give to folks that can't buy. Lets spread it.

chompie (@chompie1337) 's Twitter Profile Photo

I've been asked countless times how to learn VR & xdev. The answer is always: "do something you think is cool". It's hard to figure out what to do. Try the PhrackCTF which I've now open-sourced. It's not a contrived CTF - modeled after real vulnerabilities github.com/xforcered/Phra…