Offensive Security | Security Engineering

Joined November 2009
58 Photos and videos
Imdad retweeted
I packaged up the "autoresearch" project into a new self-contained minimal repo if people would like to play over the weekend. It's basically nanochat LLM training core stripped down to a single-GPU, one file version of ~630 lines of code, then: - the human iterates on the prompt (.md) - the AI agent iterates on the training code (.py) The goal is to engineer your agents to make the fastest research progress indefinitely and without any of your own involvement. In the image, every dot is a complete LLM training run that lasts exactly 5 minutes. The agent works in an autonomous loop on a git feature branch and accumulates git commits to the training script as it finds better settings (of lower validation loss by the end) of the neural network architecture, the optimizer, all the hyperparameters, etc. You can imagine comparing the research progress of different prompts, different agents, etc. github.com/karpathy/autorese… Part code, part sci-fi, and a pinch of psychosis :)
1,054
3,627
28,328
11,075,429
20 Oct 2025
"Pixnapping" shows a malicious Android app can force other apps pixels into the compositor, exploit a GPU timing side-channel, and steal Google Authenticator 2FA codes in under 30 seconds often without permissions. pixnapping.com/

2
73
Imdad retweeted
Serious bugs often occur in third-party components integrated by other software. @ifsecure and I found this vulnerability in the Dolby Unified Decoder. It affects Android, iOS and Windows among other platforms, sometimes 0-click. project-zero.issues.chromium…

7
65
268
65,391
30 Jan 2025
DeepSeek-R1 mirrors human thought, learning from trial and error, reflecting on mistakes, and breaking down problems like we do. It's AI with human-like reasoning.
1
104
11 Jan 2025
Dream big, no matter what it is. The human brain possesses remarkable neuroplasticity, enabling it to adapt, learn, and achieve what you consistently focus on and work toward.
1
81
2 May 2022
Hey @ZALORA I have ordered some items. It was estimated to be delivered today. But looks like your support is not responding and there is no update on the item. Been following for a week now. Help!
1
Imdad retweeted
9 Apr 2022
1/10 - I've been doing offensive security source code review for a long time now, and along the way I've learnt a lot of lessons that can make you more effective. Some of them include:
30
387
1,267
Imdad retweeted
27 Mar 2022
To succeed in the future, you MUST learn web3. Here's a list of 24 top resources to get up to speed (for free):
613
7,610
31,398
Imdad retweeted
🚨 ¡LARGAMOS! 🚀 Aprendé cómo explotar webviews junto a @imdadvs y @shiv__sahni en Apollo 12 en la #Eko2021 👏 🚨 NOW! Join @imdadvs & @shiv__sahni on Apollo 12 at @ekoparty to learn common webview related security issues & the story behind CVE-2021-21136 🔥 EN✅ | ES❌
4
7
Imdad retweeted
📢 In this @ekoparty talk, Imdadullah Mohammed (@imdadvs) & Shiv Sahni (@shiv__sahni) will discuss common webview related security issues & how they discovered CVE-2021-21136 🔥 which allowed sensitive data leakage to 3rd parties via HTTP request headers. Join us at #Eko2021! 🙌
1
4
12
Imdad retweeted
Mariana Trench is an open source static analyzer written to detect and prevent security issues in #Android and #Java applications. It can review large codebases, provide feedback to engineers, and detect bugs before they are introduced into a codebase. engineering.fb.com/2021/09/2…
16
37
114
Imdad retweeted
18 Sep 2021
iOS 14.7.1 / 14.6 / 14.4 #JAILBREAK News: RELEASE Of New XNU Vulnerability PoC (Open Source Code) VIDEO HERE: youtu.be/NCH2EKOIbPo In a previous video, I said this will be released and it's now finally out. It's a bug reachable from the Sandbox and works on 14.7.1 and lower.

30
49
273
Imdad retweeted
Webview: An in-app Web Browser created to ensure seamless user experience without context switching between browser and mobile application. How secure is that? Ask CVE:2021-21136 and @imdadvs at #BSidesBCN21 SagradaFamilia track on Sept 30 at 4.45pm CEST
2
5
Imdad retweeted
building a new reconnaissance platform? I have attempted to gather most of the open source tool-set into a mind-map. You might refer this XMind: xmind.net/m/Xy7XEW . Other file-types: github.com/himanshudas/RaaP #recon #asm #monitoring #bugbounty
22
58
Imdad retweeted
Very happy to announce that I’ll be speaking at HITB2021SIN @HITBSecConf along with @imdadvs on Securing Webviews and the Story Behind CVE-2021-21136! Join us on Friday, 27 Aug 3:00 PM SGT!! #hitb #mobilesecurity #infosec #appsec #cybersecurity #HITB2021SIN
3
3
Imdad retweeted
22 Aug 2021
Writing an iOS Kernel Exploit from Scratch secfault-security.com/blog/c…

2
165
552
12 Aug 2021
I along with @shiv__sahni will be presenting our talk "Securing Webviews and The Story Behind CVE-2021–21136" at #HITB2021SIN on 27th Aug. #MobileSecurity x.com/HITBSecConf/status/142…

#HITB2021SIN Securing Webviews and The Story Behind CVE-2021–21136 - Imdadullah Mohammed & Shiv Sahni - conference.hitb.org/hitbsecc…
9
6
Imdad retweeted
Meet WiFiDemon: iOS WiFi RCE 0-Day Vulnerability & a 'Zero-Click' Vulnerability That was Silently Patched blog.zecops.com/research/mee…

15
229
534