It does not matter.

Joined December 2016
117 Photos and videos
Homelander retweeted
May 21
We’ve now seen at least four nginx RCEs that require non-default configs: nginx rift, nginx poolslip, and two of our own (including the one in the last tweet). The configs involved are unusual, which raises the obvious question: do these attacks actually work in real-world deployments? We asked Claude to download and analyze more than 4,000 nginx config files from GitHub. The result was embarrassing: none of them were vulnerable to nginx rift or our own attacks. We can’t say anything about nginx poolslip yet, since it hasn’t been published. So don't worry about your nginx yet. Moral of the story: AI can generate FUD, but also help fight FUD. Embrace it!
6
61
286
49,724
Homelander retweeted
Opus 4.6 (1M) through Claude code solved autonomously 45/54 challenges of BSidesSF 2026 @BSidesSFCTF, placing temporarily into the 21st place, 25th as of now. This was done with 0 involvement, I didn't give any guidance or manually reviewed any challenges. I used BoxPwnr 🤖 with the CTFd platform to launch challenges in multiple instances, that's it. I will publish all the traces once the competition finishes, in the meantime you can see the challenges, number of turns and time it took to solve each here: 0ca.github.io/BoxPwnr-Traces… In the following days I will try to understand why it couldn't solve the 9 remaining challenges: difficulty? long exploration-context rotting? interactive interaction required? challs using video/image? We will see. Models have improved significantly in the last 6 months, see Cybench results Opus 4.1 vs 4.6 (42% to 93%) cybench.github.io/ It's crazy to see what LLM's can do with a minimum harness.
19
84
536
66,699
Interessante...
Mar 12
🚨 JUST IN: The FBI is investigating Steam. Steam is warning users about MALWARE found in multiple games. The games affected have been up on Steam Platform for over a year.
Community note
The FBI is investigating malware embedded in specific games available on Steam, not Steam itself. forms.fbi.gov/victims/Steam_…
110
Thanks, @GeminiApp for the help.
59
Homelander retweeted
Cool
This is fun. Left the autonomous chess match (v0-chess-match.vercel.app/) running overnight between @xai Grok 4 and @openai GPT 5.2. Grok's 𝚐𝚛𝚘𝚔-𝟺-𝚏𝚊𝚜𝚝-𝚛𝚎𝚊𝚜𝚘𝚗𝚒𝚗𝚐 won 19 of the last 20 matches 😅 What models should battle next?
1,548
2,271
25,528
4,800,502
Homelander retweeted
💯
1
5
206
Homelander retweeted
24 Dec 2025
Happy holidays, please take this time to get off the internet and spend time with your families Mental health is very important 🎄
6
8
92
8,207
Homelander retweeted
In a recent lawsuit settlement, Google agrees to delete the incognito browsing data they keep about you.
883
9,389
147,877
27,723,398
Ver os Mariners no #MLBnaESPN me lembra o King Felix Hernandez.
223
Homelander retweeted
11 Oct 2025
This seems to be a common misconception, so CTF players: Zellic hires REGARDLESS of web3 experience. The main criteria is researcher skill/talent. We've hired smart pwn / VR folks with ZERO blockchain background. Don't think, "I'll wait to get better then apply"... JUST apply.
10
9
240
20,134
Homelander retweeted
"the human brain doesn't need tons of training data to do stuff"
177
345
3,261
450,749
Never underestimate the Burp Scanner. it just made my day.
1
117
Homelander retweeted
We published a write-up about Python URL Parsing Confusion, by @NeptunianHacks. It's the solution to the challenge "msfrognymize2" on @cor_ctf fireshellsecurity.team/corct…
4
7
571
Homelander retweeted
We published a write-up by @diofeher, for the @wiz_io Big IAM Challenge, with 6 levels of Cloud Security tasks with IAM. 🌩️ fireshellsecurity.team/wiz-b…
2
3
230
Encontrei um SSTI muito maneiro em um pentest de uma aplicação desktop. Obviamente não posso compartilhar os detalhes, mas foi muito irado.
1
128
Finalmente alguém encontrou meu perfil no LinkedIn e pensou "bem, esse louco deve saber de alguma coisa"... Resumindo, recebi uma proposta
1
122
Homelander retweeted
1 Sep 2025
Teaming with @gh0stbyt3, we built DiffRays for headless IDA (@HexRaysSA) decompilation. It stores decompiled code in a SQLite DB and provides a Web UI for diffing between the stored functions. Built for vuln research. github.com/pwnfuzz/diffrays #pwnfuzz
5
38
128
13,018
Homelander retweeted
22 Aug 2025
Meanwhile, me who got hired in security with basically just a CTF background and who haven't learned about any of the mentioned things 😂
20 Aug 2025
Stop wasting time on CTF challenges. Learn Docker security, EDR evasion, network segmentation, SAML/OAuth flows, WAF configuration, and how to debug production incidents. You'll be 10x more hireable than someone who rooted 500 vulnerable VMs.
9
14
316
23,718
Cool!
95
Homelander retweeted
As promised Blogpost is here! I find that a lot of the times people ask “how can researchers find complex bugs” This is my small contribution to show how the journey looked for me. I presented this content at hitcon last week! bughunters.google.com/blog/5…
5
91
291
25,267