Joined April 2020
5 Photos and videos
liba2k retweeted
One of our security researchers demonstrated a local root shell on Linux using a page-cache poisoning primitive in AF_RXRPC’s RxGK path. We call it DirtyCBC: a sibling to DirtyFrag in the broader CopyFail / DirtyFrag / Fragnesia family. The issue is fixed on mainline. The candidate path was surfaced through Delphos’s agentic analysis workflow, then manually verified and exploited end to end. AES-256 was not broken. It just wasn’t the boundary that mattered. RxGK decrypted data in place before authentication completed. Under the right conditions, that write could land in the page cache. The HMAC check still failed and the connection was aborted, but the page-cache mutation had already happened. Two RESPONSE packets were enough to place a tiny ELF into the cached first page of a readable SUID-root binary. The file on disk stayed unchanged. The next exec produced a root shell. Full writeup and PoC on the Delphos Labs GitHub. delphoslabs.com/blog/3614237…
5
67
291
61,651
30 Oct 2025
We’re hiring 🚀 Security Researcher & Software Engineer @ Delphos Labs Build AI-powered systems for reverse engineering — tools where AI understands software, automates binary analysis, and scales how we reason about code. 🔗 jobs.ashbyhq.com/delphos-lab… #securityresearch #hiring

85
liba2k retweeted
XZ backdoor (liblzma.so.5.6.1) fully exposed in minutes with Delphos Labs. Black-box binaries? No more. Traditional tools would still be unpacking. That’s software, verified.

Black-box binaries? Over. We ran the xz-utils backdoor (liblzma.so.5.6.1) through our AI and it lit up: runtime JMP patching, custom byte-table crypto, encrypted IPC—caught in minutes. Full teardown 👉 delphoslabs.com/uploads/f382… What would you audit next? #xzbackdoor #ReverseEngineering
3
5
534
liba2k retweeted
Binary highlight: “Cyberpunk 7777 / QubePi” ELF. Text-menu game with hard-coded Postgres creds. Every login/chat/coord sent in clear on 5432—no TLS, no sanitization. Delphos auto-exposed the creds & flow in minutes. Sample: delphoslabs.com/uploads/26cc… #ReverseEngineering
1
3
8
455
16 Jul 2025
At @DelphosLabs, we're building tools to automate reverse engineering, no source code required. Help shape what we build next 👇 docs.google.com/forms/d/e/1F… It takes just a few minutes. Anonymous unless you opt in. Thanks for your input! 🙏

2
68
liba2k retweeted
Machine Learning Meets Malware. If cognition becomes an API call and malware can be reverse-engineered by an LLM, then what’s left of “zero trust”? Caleb Fenton joined @patio11 for a chat on AI, nation-states, and the new front in software security. 🎧complexsystemspodcast.com/ep…
1
5
4
272
liba2k retweeted
If you like building platforms and infrastructure and want to get in on the ground floor of a cyber security startup doing AI and reverse engineering, DM me.
2
6
909
16 Apr 2023
Why not 3d printing #ChatGPT
2
2
281
16 Apr 2023
Of course the code doesn't work, but it's a start :D
2
90
liba2k retweeted
Happy Friday everyone! Want a ProcMon for macOS? Ever wish you had your own Endpoint Security client you could task? Want to peer behind the macOS EDR curtain? Have a go and let us know what you think! github.com/redcanaryco/mac-m…
9
174
440
54,732
liba2k retweeted
29 Dec 2022
New Tiny #tinyML #AIoT module M0S coming out~ Based on BL616, WiFi6 BT5.2 Zigbee, 384MHz #RISCV RV32GCP, 4MB Flash 512KB SRAM, and USB2.0 HS in tiny 10x11mm stamp module! It would be <2$ ~
33
197
1,034
180,608
1 Oct 2022
A device that no one REALLY needs, but fun project anyway. Here is my Caliper/Digital indicator WiFi adapter. github.com/liba2k/VINCA_read…
1
5 Apr 2022
The talk that @assaf_carlsbad and I presented at #INS22 is up on youtube. youtube.com/watch?v=ge_TnLfT…

8
25
liba2k retweeted
Yesterday @liba2k and I presented our talk "Breaking Secure Boot with SMM" at @1ns0mn1h4ck. The slides, exploit code, and some additional resources are now online and available here: github.com/liba2k/Insomni-Ha… Thanks to everyone who attended, we hope to see you all again next time!
2
58
157
liba2k retweeted
In what seems like nearly perfect conjunction with the latest @binarly_io disclosure, today we publish the 6th installment of our UEFI blog post series where we dissect 6 new vulnerabilities in HP's firmware that allow privilege escalation to SMM. sentinelone.com/labs/another… @liba2k
2
21
37
liba2k retweeted
Yet another batch of SMM vulnerabilities. Blog post to be published soon. support.hp.com/us-en/documen…
1
7
43
liba2k retweeted
Zen and the Art of SMM Bug Hunting: me and @liba2k wrote yet another entry in our blog post series about UEFI firmware security. This time we cover SMM bug classes, discuss potential mitigations and reveal some tools & tactics we employed to uncover them. sentinelone.com/labs/zen-and…
1
38
84