Embedded device security researcher / VR / Pwn2Own

Joined September 2018
79 Photos and videos
Josh retweeted
As far as we can tell, no. There is only anecdotal evidence, along with claims from AI pentesting vendors. If a strong model can do everything by itself, then what exactly have these vendors been building? It is understandable that people would prefer a story in which the harness, workflow, and surrounding infra matter a great deal. It's also why people keep flexing "0-days" in OpenSSL, FFmpeg, or nginx, despite limited real-world impact. That said, Niels Provos was not trying to sell anything, and he and several people have reported good results with IronCurtain despite using relatively weak models. Most importantly, what Google achieved with Chrome suggests that a good harness may be quite valuable. Google does not appear to have access to anything more capable than Mythos, which means they likely scanned Chrome using Mythos itself or something less powerful. Yet they still uncovered hundreds of bugs. There is, however, another explanation. Google may simply have better Chrome/V8 experts who can extract more value from Mythos. This remains our preferred hypothesis. What provides a real advantage: domain knowledge accumulated over many years, or a harness vibe-coded in an afternoon? We think the answer is fairly obvious.
Replying to @calif_io
Are there public measurements of how much improvement good harness offers?
5
13
81
14,348
Defcon quals writeups haven't started to trickle out yet?
2
401
Josh retweeted
May 24
DEF CON patched our QEMU nday, what about a 0day? kqx.io/post/qemu-0day
49
236
25,565
Josh retweeted
I originally prepared this bug for Pwn2Own Berlin. A few days before the contest, a CVE got assigned. So, here is my technical analysis and exploitation strategy for CVE-2026-40369: a 12-byte kernel increment, exploitable both as an LPE and SBX. voidsec.com/cve-2026-40369-bโ€ฆ
1
61
207
16,001
Anyone doing DistrictCon's Junkyard this year? ๐Ÿ‘€
1
2
449
๐Ÿ‘๐Ÿ‘๐Ÿ‘๐Ÿ”ฅ
May 15
RIP for all 6 entries. The last-minute patch turned out quite solid. So I decided to give my exploit a proper goodbye. Enjoy! github.com/kiddo-pwn/ffffireโ€ฆ
8
2,000
Holy...
There it is! Orange Tsai (@orange_8361) of DEVCORE Research Team was able to exploit Microsoft Exchange! If confirmed, they win a whooping $200,000 and 20 Master of Pwn points. Off to the disclosure room to explain how they did it and seal the deal. #Pwn2Own #P2OBerlin
15
2,416
Josh retweeted
p2o so far seems to be mostly...previous p2o players or if new, players on well-established p2o teams? not many plausible "from no skills -> p2o success based almost entirely on model capability" examples afaict
5
1
34
3,757
๐Ÿ‘๐Ÿ‘๐Ÿ‘
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
4
537
Josh retweeted
everyone, i need your help, anyone can hook us up with the "ESXi version 9.1.0.0"? your RT is really appreciated, this is Urgent AF.

ALT Scream Cat GIF

3
19
43
12,939
Pretty sure the vendor reports before the competition starts are likely actively hurting the competitors that have flown out just to have their bounty halved as the issues are now considered 'known'. Equally, you can't just sit on a full chain. Far from the ideal situation...
1
2
3
1,349
It would be helpful to see the distribution of entries across targets this year. Which had more entries than others? Even with AI, my experience is that the hard targets remain hard, and I suspect the entry count we'll see will reflect that.
Okay let's go home guys @thezdi
15
1,736
Josh retweeted
Apr 6
Good morning! Just published a blog post exploiting a VMware Guest To Host. A UaF Heap Feng Shui base address leakage to bypass ASLR and a stack-based buffer overflow to achieve RCE. r0keb.github.io/posts/VMwareโ€ฆ
3
77
321
18,333
Josh retweeted
New post is up! This one uses CVE-2025-20741 (a heap overflow in the MediaTek MT76xx driver) to show how a bit of kernel alchemy can turn a heap OOB write into a number of stronger exploit primitives, up to page-level r/w via pipe_buffer corruption :) blog.coffinsec.com/0day/2026โ€ฆ
4
100
380
27,424
VuLneRbiLitY reSeaRcH iS cOoKed
1
1
27
2,564
Josh retweeted
FreeBSD, the kernel nobody thinks about until it's time to demonstrate what it looks like to attack something that skipped out on the last 20 years of modern defenses.
3
29
231
20,669
๐ŸŽ‰
2
10
3,266
'You're absolutely right...'
1
4
526
Josh retweeted
Exploiting the Synology BeeStation (BST150-4T), CRLF injection, auth bypass, and SQLite injection to RCE (CVE-2024-50629~50631) kiddo-pwn.github.io/blog/202โ€ฆ Credits @kiddo_pwn @infosec
1
34
160
8,590