Head of Security Engineering @ WitnessAI / CEO @ OffCell Research

Joined April 2011
7 Photos and videos
Pinned Tweet
16 Aug 2023
I wipe all my tweets every so often.
1
6
7,860
Are there any agents yet that can organize my iPhone apps? This is so needed…
816
9 Jul 2025
I’ve seen the future and it is bad. Real experts will spend all of their time explaining to people why the AI is wrong/hallucinating.
4
1,693
16 Sep 2024
Awesome work!! Looking forward to testing it out! @lukasarnld is the source going to be released?
Replying to @lukasarnld
We’re launching the public beta phase of our CellGuard iOS app. It supports all iPhones running iOS 14 or newer. You can contribute to an optional study that helps us to improve detection algorithms. Read more & download CellGuard at cellguard.seemoo.de
1
1
4
3,174
23 Aug 2024
Congrats to the @cursor_ai teams! 100% deserved. Truly the most usefully AI based tool I use. Game changer!
22 Aug 2024
We've raised $60M from Andreessen Horowitz, Jeff Dean, John Schulman, Noam Brown, and the founders of Stripe and Github. Cursor has become recognized as the best way to code with AI, powered by an ensemble of custom and frontier models, delightful editing, and petabyte-scale infrastructure. Our mission is to create a magical tool that will one day write all the world's software. Join us!
2
1,269
Mathew Solnik retweeted
In light of the OpenSSH RCE advisory published today by Qualys: blog.qualys.com/vulnerabilit…, where it references our March blog while discussing ASLR weaknesses being key to feasible modern i386 exploitation, here it is again in case you missed it:
A weakness 23 years in the making: binaries and libraries built with an older toolchain act as timebombs against ASLR under "recent" Linux kernel and glibc changes. Users: Check your exposure! Developers: Rebuild binaries to achieve full ASLR benefit! grsecurity.net/toolchain_nec…
8
27
5,193
Mathew Solnik retweeted
CVE-2024-6387 - Signal Handling Race condition results in remote root exploit of OpenSSH w/glibc. Found by @qualys - tagging @mdowd as this looks familiar to his prior SSH work and is referenced. qualys.com/2024/07/01/cve-20…

16
37
12,787
12 Jun 2024
Any recommendations on improving @cursor_ai for use with large and complex rust projects? It unfortunately isn’t able to follow along nearly as well as other languages.
657
11 Jun 2024
It’s only taken *8* years since I suggested it but Apple has finally added a “firewall”/blastdoor around Telephony (aka CommCenter etc). /System/Library/PrivateFrameworks/TelephonyBlastDoorSupport.framework/XPCServices/TelephonyBlastDoorService.xpc/TelephonyBlastDoorService
3
6
30
9,780
11 Jun 2024
Thanks @blacktop__ for the awesome diffs
2
813
7 Jun 2024
One of if not *the best* presentation on the 0day market and how it works. All you cellular folks - pay attention to the comments on dealing with sending over cellular carriers. I mentioned this back in the OMADM days. Pain the in ass but not impossible.
7 Jun 2024
Hey, for anyone who wanted to see this slide deck, it was a keynote about the 0day market, but it commented on public research vs saleable products. I have put it here: github.com/mdowd79/presentat… // cc @chompie1337 @bsdaemon
1
2
10
3,546
3 Apr 2024
What are everyone’s thoughts on sandboxing vs VMs? Especially in mobile. Would a Qubes like OS be better than current sandboxing? Especially if the kernels weren’t *nix based?
4
7
4,523
11 Mar 2024
Any recommendations on what to use to monitor/log 3rd party software/library versions in their dev stacks and environments? Ideally something that will alert for new CVEs?
2
1,417
15 Sep 2023
People will disagree with me - but if you want to start putting pressure on both the spyware devs and the OEMS… start publicly releasing the full exploit chains and implants. It will wreak havoc on all sides. Sorry but IOCs/hashes don’t slow down offensive tool usage.
1
1
7
3,186
24 Aug 2023
LTE/5G IMO is LESS secure than 2G when it comes to true RCE (no fake basestation) part 2: @natashenka’s presentation on Shannon hacking is one of the best overviews on true remote baseband hacking I have seen in a long time! Amazing work Natalie! Dealing with carrier filtering/packet modification has been a bane of my existence since 2014. I mentioned it in my slides back then too! hardwear.io/usa-2023/present… m.youtube.com/watch?v=NnmAik… Link to my old talk: 2014.ruxconbreakpoint.com/as… P.S. If you made it this far down - my next tweet will talk about why nation state (or even just well funded private entities) have less issues with carrier filters than standard researchers. P.P.S. Accidentally deleted the original part 1 tweet. Has to repost it.

14
49
7,877
24 Aug 2023
LTE/5G IMO is LESS secure than 2G when it comes to true RCE (no fake basestation). The IMS/VoLTE stacks can be hit from anywhere in the world with just a phone number. Media parsing, XML, etc... Android in baseband, iOS in userland. Plenty of 0days to be found. Have fun! P.S. Project Zero has dropped some fun bugs @natashenka P.P.S. I can confirm this area has been a heavily hit target by offensive companies for years. I'm taking a break from cellular so I figured I would drop some fun info.
9
1,616
16 Aug 2023
I wipe all my tweets every so often.
1
6
7,860
24 Aug 2023
Sometimes by accident… accidentally deleted one today.
625