Joined February 2018
11 Photos and videos
Nadir retweeted
Jun 12
The AI Agent Security - Multi-Step Tool Attacks simulation is now live! In partnership with @OpenAI, @Google and @IEEEorg, your challenge is to build an attack algorithm that stress-tests tool-using AI agents in a deterministic offline benchmark.
8
23
83
8,281
Nadir retweeted
This reverse engineering work led its way to a fix in Chrome (subsequently Electron), with credit given back to me! Very cool to see, and happy to help the macOS ecosystem. I hope macOS fixes this huge issue soon. chromium-review.googlesource…
Everything is open source if you try hard enough. (Trying to find the source of a pathological performance issue stemming from AppKit only on macOS 26. I'm pretty sure it's a macOS 26 bug but given this is shipping, I need to find a workaround). I really wish Apple would just make the source of their frameworks available (even under a non-OSS license that doesn't allow any reuse), just so that app developers can understand how certain logic interacts with the system.
15
30
612
79,193
Nadir retweeted
7 Sep 2025
when building ai products, the key is having some reliable signal about what is working and what is not. whether that signal comes from evals, user feedback, your own taste, performance metrics, or just gut feel does not really matter as long as it is giving you actionable information about where to focus your efforts. the mistake is either having no signal at all (just building blindly) or getting caught up in the methodology of the signal rather than its utility. a formal eval that tells you nothing useful is worse than informal feedback that clearly points to real problems
i did not expect to wake up this morning and write a blog post
1
2
31
7,021
Nadir retweeted
14 May 2025
A fix from Google was released today. Part of the issue was due to my misunderstanding based on previous reports. Big thanks to chromium team for the quick resolve I hope everyone had some fun, and apologies to the triagers on HackerOne XD
5 May 2025
Today I used a technique that’s probably not widely known in the community. In what cases could code like this lead to a vulnerability? ->
14
26
199
43,445
Nadir retweeted
15 May 2025
Imagine not having had any food to give your kids for 10 days.
I swear to God, this what exactly happened: I woke up today morning and found a missed call on my phone coming from a widow with a number of orphan children living next door. I called her back and asked her what she wanted. She said: “I need some flour. Me and my children have been sleeping without food for 10 days.” I replied: “Unfortunately, me and my children have nothing to eat for more than 10 days.”
230
3,143
11,240
498,541
Nadir retweeted
5 May 2025
Today I used a technique that’s probably not widely known in the community. In what cases could code like this lead to a vulnerability? ->
21
188
1,043
275,202
Nadir retweeted

50
102
1,016
268,497
Nadir retweeted
We did it! We tested 300 Bay Area foods for plastic chemicals. We found some interesting surprises. Top 5 findings in our test results: 1. Our tests found plastic chemicals in 86% of all foods, with phthalates in 73% of the tested products and bisphenols in 22%. It's everywhere. 2. We detected phthalates in most baby foods and prenatal vitamins. 3. Hot foods which spend 45 minutes in takeout containers have 34% higher levels of plastic chemicals than the same dishes tested directly from the restaurant. 4. The 1950s Army rations we tested contained surprisingly high levels of plastic chemicals. 5. Almost every single one of the foods we tested are within both US FDA and EU EFSA regulations. Check out our full results below.
I'm going to re-run all these tests on food we eat in California. Also going to test for other plastic chemicals. Let me know what foods we should test and suggestions for methodology.
563
2,773
15,269
9,770,261
Nadir retweeted
23 Aug 2024
in a couple weeks, i built a nuclear fusor in my bedroom – with zero hardware experience the secret? Claude sonnet 3.5 projects a glimpse into the process below
314
1,013
9,896
3,190,658
Nadir retweeted
18 Aug 2024
Pass-the-{token} attacks are still very much relevant. Tokens may change: Cookie, NT Hash, Kerberos ticket, MFA token, ... However, the problem is not in the "token" but in the "pass". We need a solutions to make tokens stay put, such as device and channel binding.
Microsoft has detected a 111% year-over-year increase in token replay attacks, and incidents are continuing to grow. msft.it/6011lSgZ7
5
41
152
21,637
Nadir retweeted
10 Jul 2024
My latest blog about my discovery for Evernote Client All-platform RCE via PDF.js font-injection to preload.js exposed ipcRenderer-BrokerBridge-boron.actions bypassing Electron's nodeIntegration | context-isolation; Enjoy reading! 0reg.dev/blog/evernote-rce

10
124
461
32,958
Nadir retweeted
24 Jun 2024
happy to release my new article entitled: Next.js and cache poisoning: a quest for the black hole zhero-web-sec.github.io/rese… good reading;
38
179
776
84,356
Nadir retweeted
23 Feb 2024
Bouncy castles on one side, starvation and death on the other.
255
2,464
6,022
1,608,908
31 Dec 2023
Recently published a blog post on how I usually exploited client-side path traversals (and how that exploitation technique is somewhat mitigated now). Client-side path traversal is not novel, but sharing some insights from the last years: kapytein.nl/from-an-innocent…

3
21
75
10,832
Nadir retweeted
24 Oct 2023
Citrixbleed: On Oct 10th, Citrix announced a security advisory for CVE-2023-4966, a sensitive information disclosure bug marked as CVSS 9.4 affecting Netscaler Gateway. The security research team at @assetnote was able to reproduce the vulnerability. Blog post here: assetnote.io/resources/resea… or you can find the exploit here: github.com/assetnote/exploit…
2
143
445
97,890
24 Oct 2023
Enjoyed Lisbon 🇵🇹! Thanks for the very well organized event, @intigriti. Congrats to the award winners @karel_origin, @arneswinnen, @MattiBijnens, @erbbysam, @p4fg, and all participants for the great results! #1337UP1023
23 Oct 2023
This is how 100 elite hackers look like after smashing @IntelSecurity's live hacking event with @intigriti. Who would love to attend our next LHE? 🙋‍♀️
18
961
14 May 2023
Completely missed the Android 14 preview/beta releases, but looks like the 'safer dynamic code loading' feature will kill some RCE scenarios on Android applications which leverage an arbitrary file write via e.g. an unsafe unzip. developer.android.com/about/…
2
509
Nadir retweeted
Check out my latest research, Prototype Pollution but in Python this time blog.abdulrah33m.com/prototy…

7
82
241
50,474