Romain Gaucher (@rgaucher) 's Twitter Profile
Romain Gaucher

@rgaucher

Security and code, scaling. Research @ Semgrep.

ID: 18391473

linkhttp://romain.lol calendar_today26-12-2008 16:57:14

3,3K Tweet

1,1K Followers

795 Following

David Tolnay (@davidtolnay) 's Twitter Profile Photo

If you are running into broken GitHub integrations today, it's because GitHub issuecomment IDs have just passed the maximum value of i32. For example Rust Language's rfcbot is currently out of commission with an i32 overflow.

If you are running into broken GitHub integrations today, it's because GitHub issuecomment IDs have just passed the maximum value of i32.

For example <a href="/rustlang/">Rust Language</a>'s rfcbot is currently out of commission with an i32 overflow.
mdowd (@mdowd) 's Twitter Profile Photo

Hey, for anyone who wanted to see this slide deck, it was a keynote about the 0day market, but it commented on public research vs saleable products. I have put it here: github.com/mdowd79/presen… // cc chompie Rodrigo Branco

Andrej Karpathy (@karpathy) 's Twitter Profile Photo

📽️ New 4 hour (lol) video lecture on YouTube: "Let’s reproduce GPT-2 (124M)" youtu.be/l8pRSuU81PU The video ended up so long because it is... comprehensive: we start with empty file and end up with a GPT-2 (124M) model: - first we build the GPT-2 network - then we optimize

📽️ New 4 hour (lol) video lecture on YouTube:
"Let’s reproduce GPT-2 (124M)"
youtu.be/l8pRSuU81PU

The video ended up so long because it is... comprehensive: we start with empty file and end up with a GPT-2 (124M) model:
- first we build the GPT-2 network 
- then we optimize
Robert Hansen (@rsnake) 's Twitter Profile Photo

There is rumbling afoot of a series of articles coming that will be targeting and possibly even naming and shaming both CISOs and VCs. Without naming my sources and not that it's important to do so anyway, because the following article does a good job of giving a high level lay

Timothée Chauvin (@timotheechauvin) 's Twitter Profile Photo

Excited to announce my preprint "eyeballvul: a future-proof benchmark for vulnerability detection in the wild". I create a benchmark to evaluate the vulnerability detection capabilities of long-context models on entire codebases, containing over 24,000 vulnerabilities, then

Excited to announce my preprint "eyeballvul: a future-proof benchmark for vulnerability detection in the wild". I create a benchmark to evaluate the vulnerability detection capabilities of long-context models on entire codebases, containing over 24,000 vulnerabilities, then
Tavis Ormandy (@taviso) 's Twitter Profile Photo

This strange tweet got >25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n

This strange tweet got &gt;25k retweets. The author sounds confident, and he uses lots of hex and jargon. There are red flags though... like what's up with the DEI stuff, and who says "stack trace dump"? Let's take a closer look... 🧵1/n
Patrick Collison (@patrickc) 's Twitter Profile Photo

Was chatting with a well-known founder yesterday about the "founder mode" discussion. We were both wondering if people would misinterpret it, and undervalue the importance of hiring great leaders. Steve Jobs, the canonical example of "founder mode", was also gifted at

Sean Heelan (@seanhn) 's Twitter Profile Photo

Having seen xbow in action: if you’re making a living from bug bounties, and relying on generic vulnerability classes, I would consider alternative career plans

Nathan Lambert (@natolambert) 's Twitter Profile Photo

New export controls incoming, Bloomberg reporting: "But if an AI company wants to fine-tune a general-purpose open weight model for a specific purpose, and that process uses a significant amount of computing power, they would need to apply for a US government license to do so in

New export controls incoming, Bloomberg reporting:
"But if an AI company wants to fine-tune a general-purpose open weight model for a specific purpose, and that process uses a significant amount of computing power, they would need to apply for a US government license to do so in
Charlie Marsh (@charliermarsh) 's Twitter Profile Photo

ty, our upcoming static type checker and language server for Python, is accidentally on the front page of HN. We're rapidly closing in on an initial "experimental preview release"...

ty, our upcoming static type checker and language server for Python, is accidentally on the front page of HN.

We're rapidly closing in on an initial "experimental preview release"...
Romain Gaucher (@rgaucher) 's Twitter Profile Photo

We just released our deep look at Claude Code and Codex on real web apps for finding vulns. Some good, some pretty bad! semgrep.dev/blog/2025/find…

Charlie Eriksen (@charlieeriksen) 's Twitter Profile Photo

Ok, so this MUST be the attackers behind Nx at play. I just started analyzing the exfil mechanism through GitHub repos, and wow... This is bad news. We've got a worm on our hands.

Romain Gaucher (@rgaucher) 's Twitter Profile Photo

Anterograde amnesia. Opus 4.1 happily raising a javascript URI XSS vector in the CSS's url() function. Nope. What's next, vbscript: ?

Andrej Karpathy (@karpathy) 's Twitter Profile Photo

Quick new post: Auto-grading decade-old Hacker News discussions with hindsight I took all the 930 frontpage Hacker News article+discussion of December 2015 and asked the GPT 5.1 Thinking API to do an in-hindsight analysis to identify the most/least prescient comments. This took

Quick new post: Auto-grading decade-old Hacker News discussions with hindsight

I took all the 930 frontpage Hacker News article+discussion of December 2015 and asked the GPT 5.1 Thinking API to do an in-hindsight analysis to identify the most/least prescient comments. This took
Semgrep (@semgrep) 's Twitter Profile Photo

The Node.js sandbox library vm2 has disclosed a critical vulnerability that allows attackers to escape the sandbox and execute arbitrary code. The exploit is public, the CVSS score is 9.8, and any use of vm2 v3.10.1 or earlier should be considered affected. Immediate upgrade is