Evan Sultanik (@esultanik) 's Twitter Profile
Evan Sultanik

@esultanik

Ph.D. computer security researcher @TrailOfBits. Editor of and frequent contributor to #pocorgtfo. My CV is a PDF that’s also an NES ROM sultanik.com/nesresume/

ID: 18007683

linkhttps://www.sultanik.com/ calendar_today10-12-2008 00:42:29

3,3K Tweet

1,1K Takipçi

474 Takip Edilen

Trail of Bits (@trailofbits) 's Twitter Profile Photo

We assessed the YOLOv7 vision model and identified 11 security vulnerabilities that could enable RCE, DoS, and model differentials. We do not recommend using the codebase for mission-critical applications or applications that require high availability. buff.ly/47aP751

Trail of Bits (@trailofbits) 's Twitter Profile Photo

Today, we are disclosing LeftoverLocals, a vulnerability that allows listening to LLM responses through leaked GPU local memory created by another process on Apple, Qualcomm, AMD, and Imagination GPUs (CVE-2023-4969) buff.ly/48RDP68

CERIAS at Purdue U. (@cerias) 's Twitter Profile Photo

This Wednesday, April 10th, 4:30pm ET: "In Pursuit of Silent Flaws: Dataflow Analysis for Bugfinding and Triage" Evan Sultanik Evan Sultanik - Trail of Bits Trail of Bits ceri.as/sultanik Live on Zoom.

This Wednesday, April 10th, 4:30pm ET: "In Pursuit of Silent Flaws: Dataflow Analysis for Bugfinding and Triage" Evan Sultanik <a href="/ESultanik/">Evan Sultanik</a>  - Trail of Bits <a href="/trailofbits/">Trail of Bits</a> ceri.as/sultanik Live on Zoom.
Evan Sultanik (@esultanik) 's Twitter Profile Photo

I hate to be “reviewer #2”, but I’m a bit disappointed that my prior work was not cited sultanik.com/blog/revisitin…

Ange (@angealbertini) 's Twitter Profile Photo

Any crazy libmagic (file) or yara rules out there that blew your mind? blog.trailofbits.com/2022/07/01/lib… covered quite a lot of file libmagic syntax. cc Gynvael Coldwind (@gynvael.bsky.social) @hexacorn Evan Sultanik Philippe Lagadec

sergey bratus (@sergeybratus) 's Twitter Profile Photo

It's great to see Multiplier by Trail of Bits being open-sourced! github.com/trailofbits/mu… I believe it exemplifies the kind of foundational, next-generation tools we need for proper software understanding, maintenance, and sustainment.

Ange (@angealbertini) 's Twitter Profile Photo

When working on Magika (Google's AI-powered content-type detection), I checked other file formats KBs and detection engines to create filesets to train the model on. I gave a talk at HackLu to share an overview of the existing engines. speakerdeck.com/ange/overview-…

Trail of Bits (@trailofbits) 's Twitter Profile Photo

Our new whitepaper covers secure-by-design steps that CEXes can take to keep users' accounts (and funds) safe from account takeover (ATO) in 2025. (Read more 👇)

Our new whitepaper covers secure-by-design steps that CEXes can take to keep users' accounts (and funds) safe from account takeover (ATO) in 2025.
(Read more 👇)