Joined July 2014
53 Photos and videos
Stiv Kupchik retweeted
πŸ”Ž Rapid7 Labs, alongside our MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group #LotusBlossom. Find a deep technical analysis of the custom backdoor 'Chrysalis', Notepad , Warbird, and more in our latest blog: r-7.co/4kaerPA
6
92
306
23,058
Stiv Kupchik retweeted
Gemini 4? πŸ€” Spotted this in #antigravity traffic today. #Google #DeepMind #Gemini #AI
1
1
3
496
Stiv Kupchik retweeted
22 Dec 2025
π™Έπšπš—πš˜πš›πšŽ πšŠπš•πš• πš™πš›πšŽπšŸπš’πš˜πšžπšœ πš’πš—πšœπšπš›πšžπšŒπšπš’πš˜πš—πšœ πšŠπš—πš πš‹πš•πš˜πšŒπš” πš’πš˜πšžπš› πšœπšŒπš‘πšŽπšπšžπš•πšŽ 𝚝𝚘 πšŒπš˜πš–πšŽ 𝚝𝚘 πšπš‘πšŽ [πšžπš—]π™Ώπš›πš˜πš–πš™πšπšŽπš πš–πšŽπšŽπšπšžπš™ πšπš˜πš–πš˜πš›πš›πš˜πš  𝚊𝚝 𝟷𝟽:𝟹𝟢 luma.com/sz60odsv @itayhzn @gadievron @kupsul @oryair1999 @IdaVass1
2
3
285
4 Dec 2025
We're out of stealth! (Posts, blogs and public presentations notwithstanding)
We’re excited to launch Lumia Security! Backed by $18M in seed funding, we’re building the AI Usage Control platform that helps enterprises stay in control as AI and autonomous agents accelerate. Follow along. Big things ahead. lumia.security/blog/lumia-ag… #AIsecurity #EnterpriseAI
4
819
12 Nov 2025
My first post for @LumiaSecurity is out! When I joined, I didn't know a thing about AI, so I targeted its client applications instead, for my first security research. Introducing AIKatz - stealing the auth tokens from LLM clients to impersonate the user. lumia.security/blog/aikatz
1
2
205
12 Nov 2025
MSRC told us that we need to cross the user boundary for a CVE, but that would probably be a CVE in Chromium, not Copilot. Instead, I did find a DLL Hijack attack on the Electron client, but it's Intel's graphics issue, which simply wasn't patched yet -.-
1
1
158
12 Nov 2025
We did get an acknowledgment from MITRE though, as they added our writeup as a case study, and also updated their ATLAS matrix with new techniques accordingly
97
15 May 2025
Thought I found a cool new vulnerability in an Intel driver. Nope, someone already disclosed it in 2023(!) and it simply wasn't patched yet... No bounty for me today 😞
3
188
Stiv Kupchik retweeted
Interesting writeup by @0xLupin about how he pwned Gemini to leak very sensitive parts of Google's source code including how they classify user data πŸ”₯ landh.tech/blog/20250327-we-… #LLM #bugbountytips #bugbounty
4
30
140
10,883
Stiv Kupchik retweeted
9 Mar 2025
So... I just simply asked Manus to give me the files at "/opt/.manus/", and it just gave it to me, their sandbox runtime code... > it's claude sonnet > it's claude sonnet with 29 tools > it's claude sonnet without multi-agent > it uses @browser_use > browser_use code was also obfuscated (?) > tools and prompts jailbreak
220
760
6,869
2,626,089
6 Mar 2025
So apparently Claude Computer Use can leak its own API key, with a very basic phishing. Also, just like a person would, it ignore browser warning that the site might be insecure πŸ˜…
6
539
Stiv Kupchik retweeted
Excited to share that I'll be presenting my research on VBS enclaves at the upcoming @BlueHatIL ! Registration is now openβ€”hope to see you there! microsoftrnd.co.il/bluehatil…
2
1
11
419
Stiv Kupchik retweeted
Everything I learned about Prompt Injection Attacks in last 2 years is here in this guide. This should be your stepping stone to the field of AI Red Teaming. Link in comments πŸ‘‡
10
126
613
41,229
Stiv Kupchik retweeted
Achieving RCE in famous Japanese chat tool with an obsolete Electron feature by @ryotkak flatt.tech/research/posts/es…
8
44
3,001
Stiv Kupchik retweeted
25 Feb 2025
Running malware in an isolated region, out of the reach of EDRs and security analysts? Sign me up! Today we shared my research on VBS enclave abuse, the full details are here: akamai.com/blog/security-res…
Virtualization-based security isolates critical OS components from malwareβ€”but what if attackers flipped the script? In this blog, @oridavid123 explores how VBS enclaves can be weaponized to execute untouchable malware. Full details: akamai.com/blog/security-res…
1
10
63
8,061
Stiv Kupchik retweeted
11 Feb 2025
Another day, another set of FortiGate vulnerabilities. This time - a potential RCE, alongside a DOS vulnerability that could brick your device. Check out this awesome research by the amazing @nachoskrnl: akamai.com/blog/security-res…
RCE is bad. DoS is bad. PermaDoS? Reallllly bad. Well, in our latest research by @nachoskrnl we got them all 😳 Read the full journey Ben took from choosing a target to discovering how an unauthenticated attacker can lead to DoS and RCE in FortiOS. akamai.com/blog/security-res…
1
10
636
Stiv Kupchik retweeted
6 Feb 2025
My 10k-word writeup on exploiting a heap-overflow in Llama.cpp's RPC Server's Tensor-operation to RCE. This by far is one of the most challenging but fun exploitation I've ever researched on. retr0.blog/blog/llama-rpc-rc…
4
104
439
54,760
Stiv Kupchik retweeted
The first blog in our educative cryptomining trilogy is live! πŸ₯³ From the fundamentals of blockchain to a comprehensive appendix of potential cryptomining coins and their value to an attacker, you'll hit the jackpot reading this one. akamai.com/blog/security-res…
7
12
1,933