🇻🇳 number 1. I like making you uncomfortable with my unpopular opinions. My opinions are my dog's, btw. So if you want to argue, argue to my dog.

Joined February 2014
22 Photos and videos
As much as I fucking hate those in-the-wild exploit guys, and want to defend vendors, vendors lately have failed to live up to the expectation of good-faith researchers with respect to a consistent quality in response. Which, is gonna fuck themselves up. This is such a hectic era
166
Why half of security twitter these days sounds like people having inferiority complex getting butt-hurted by AI doing better than them at some tasks, and the other half sounds like a bunch of tech bros proud of AI doing better than them at some tasks. Such a wild time we're in.
1
8
975
"All the defenses you must break to exploit Chrome" sounds a bit over if you are a beginner reading this 😅 And no, we don't have to break them all to exploit Chrome. Trusted sources told me that AI was able to do it with some prompting effort, so chill y'all.
All the defenses you must break to exploit Chrome
1
4
27
7,077
Before ChatGPT existed: "I and python3 and pwntools and gcc found the 0day". Just sayin' 🤗
My new hate is this flurry of people now becoming l33t 0day researchers overnight. "I found this 0day"... no... you AND THE AI found the 0day. This industry has always had people taking credit for others work. Be open and honest people, it's fine to admit that AI is playing a part (call out this BS where you see it!).

ALT Dustin Hoffman GIF

4
336
I think I need to drink more orange juice so I can be at this OG level...
That's my chain — a full chain w/ logic bugs only! No memory corruption, no AI, and of course no collisions at all 😉
5
692
Sorry my twitter didn't work so just have to do it this way cuz the machine is woke af
Replying to @qriousec
We’ve been through all kinds of situations: exploits failing, vendors turning off services during demos, patches being released the night before a demo, and more but we happily accepted and continue to play. And if you don’t participate in the game, who cares about your opinion?
1
2
1,172
Lmao bro really uses --single-thread and thought it's realistic 😂
Well since Google sucks fat donkey dick (still annoyed they waited >2 months to reject my RCE payload because i used the --single-thread flag in repro)... This was disclosed yesterday: issuetracker.google.com/u/1/… It was my 1st attempt to report the vuln that allows for RCE on every Chromium browser since Dec 2018. This one was rejected because I was still learning how to prove Chrome reachability. Ended up filing a new report a week later after figuring out a trick to bypass Chromium's validation on video files and being able to prove reachability.
39
5,926
Amazing. And I like where this is going
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing
341
Is it just me or chromium.googlesource.com/ch… is blocking people? Some URLs are accessible but some aren't. gclient sync fails for some sub repos. freetype2 and buildtools

2
310
Okay super stupid: Just login to chromium.googlesource.com/ne… problem solved

157
Can't even read build instructions chromium.googlesource.com/ch…

125
When people hear about these new stories about how autonomous AI can be in vulnerability research, many say: "Oh, X and Y has been doing this for N months/years". Thing is: show, don't tell, guys. Talk is cheap, show the world the exploit, the prompt, and the patch :)
197
Broooo, us Vietnamese still don't know what the FUCK we did to be counted in that ENTIRE WORLD shit 😂
#BREAKING Iran’s Foreign Ministry: "The process [war] that has begun will soon engulf Europe. The fire, that the US and the Zionist regime ignited, will engulf the entire world."
276
Lol lazy "n-DaY rEsEaRcHeRs" are probably be butthurting like crazy 🤣🤣🤣 everybody trying to chase fame or money and there are these precious people. We Vietnamese say: cayyyyy 🤣
Why only the screenshots and the sloppy post? 1. Our work isn’t here for every ooneee dayyyyyyyyyy “researcher” looking to weaponize it. 2. We’re not selling anything. 3. We’re not a firm or startup, and we’re definitely not chasing fame to attract investment. So who are we?
1
2
254
This world has been so fucking crazy people tend to think every fucking thing must be for some profit and not fun. Guys, just have some fucking fun and chill out 🤣
134
Unpopular opinion: the state of drama recently may be the exact reason why we as SeCuRiTy ReSeArChErS are still able to keep our job. Lmao 😂
2
348
The amount of popcorn I've been consuming is getting to a tipping point of becoming hazardously unhealthy due to the absurd amount of drama on the internet lately 😂 I eat popcorn for breakfast now.
Yeah, so pretty much this entire drama thing is FFmpeg are a bunch of nerds and have spawned a philosophical conversation on the implications of bug bounty and offensive security. Nerd stuff Google submits a CVE thingie to them, but FFmpeg is mad because while people finding CVEs is nice, they don't actually meaningfully contribute to their project. A CVE is important, but it does little when they don't have super cool things like money or help. FFmpeg basically sees it as a way for Google to jerk themselves off and say "omg Im so helpful" when they're not They also criticize security nerds for trying to bug bounty open source non profit community drive projects because while doing nothing to actually patch stuff. Security nerds just scream "ooga booga Im a hacker" People in comments are mad saying, "omg just patch it and work more and for free". Other people, "wow that's a really good point". Other people say, "I don't understand what's going on" Will FFmpeg force Google to submit a patch? Will nerds understand what FFmpeg is trying to convey? Will I ever get a good night's rest while having a newborn baby? Find out next time and more on the next episode of Dragon Ball Z
3
629
VR is painful af and I am a noob. Just saying.
2
11
2,940
Duc Phan retweeted
If u think that Windows research is all we do, think again! In our first IOT blog, @voix44er details the Wolfbox EV charger setup, attack surface, his #Pwn2Own Automotive 2025 bug, exploitation, and best of all, displaying our name on it (in styleee...)! pixiepointsecurity.com/blog/…

19
69
6,240