Joey Henkel
@joey_henkel
CISSP GPEN GWAPT GCIH Security+ MSIA | Pentester (Cloud, Network, Web & Mobile) | Red, Blue & Purple | Security Engineer | 17+ InfoSec Experience
ID: 43259539
29-05-2009 03:10:47
1,1K Tweet
177 Followers
638 Following
Stop asking LLMs to “find vulns.” Start using them to understand code. Andrew Luke walks through using Claude Code as a force multiplier in app assessments - faster analysis, fewer false positives, better outcomes. Check it out: ghst.ly/4rA3uJd
We found a critical vulnerability in OpenAI Codex affecting all Codex users, allowing exfil of a victim’s GitHub tokens to our C2 server. This granted lateral movement and R/W access to a victim’s entire code base 😈 This was a crazy one by Tyler Jespersen at BeyondTrust Phantom Labs™
A few months ago, I found a really cool technique to make prompt Injection more deterministic. Ciarán Cotter convinced me to write it up. Enjoy! blog.starstrike.ai/posts/achievin…