@Dartmouth ISTS Fellow & @SAISHopkins Adjunct Prof., inter alia. Former @DARPA, @DEFCON CTF, etc. @DistrictCon, @hexacon_fr, @LABScon_io CFP Review Boards

Joined May 2011
93 Photos and videos
Pinned Tweet
20 May 2025
Back in 2023, the assessment of the pre-authentication vulnerability in SSH was that it wasn't exploitable on Linux. For my OffensiveCon 2025 keynote, I wrote enough of an exploit to show, with the right heap groom and stabilization, it's likely exploitable. Then I tried to have AI do it. Up to @taviso whether that merits switching to Windows 98 :) youtube.com/watch?v=Y1naY3gu…

14 Feb 2023
Replying to @taviso
If someone get a working OpenSSH exploit from this bug, I'm switching my main desktop to Windows 98 😂 (this bug was discovered by a Windows 98 user who noticed sshd was crashing when trying to login to a Linux server!)
4
34
243
52,268
Perri Adams retweeted
We won't stop until getting a fix into production is no longer the bottleneck in defending society's critical systems. deepmind.google/blog/introdu…
3
10
22
2,814
Perri Adams retweeted
Feb 20
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
1,911
5,643
49,442
26,190,768
Perri Adams retweeted
What mathematicians call "literature review" should be familiar to you as "vulnerability research". Or, put another way: erdosproblems.com is currently the best benchmark for LLM capabilities in finding 0days.
Recently I gave a talk on LLMs for Math Research (mostly to an audience of pure and applied mathematicians) I tried to compile the latest progress in one presentation pdf and video recording: drive.google.com/drive/folde…
6
19
168
30,310
Perri Adams retweeted
Hello security researchers! Like it or not, agentic AI is here. It’s time to explore its impact on novel, academic research in cybersecurity. To this end, we’re launching the Conference for Synthetic Security Research (synsec.org). Researchers, start your agents!

14
68
403
37,190
Perri Adams retweeted
Literally the other half of AIxCC that no one paid any attention to
1 Nov 2025
So the missing step here is AI writing patches
3
7
55
13,229
18 Oct 2025
Great example of what a game changer AI is for lit review (in and of itself a critical capability but should not be conflated with creating novel solutions)
Update: Mehtaab and I pushed further on this. Using thousands of GPT5 queries, we found solutions to 10 Erdős problems that were listed as open: 223, 339, 494, 515, 621, 822, 883 (part 2/2), 903, 1043, 1079. Additionally for 11 other problems, GPT5 found significant partial progress that we added to the official website: 32, 167, 188, 750, 788, 811, 827, 829, 1017, 1011, 1041. For 827, Erdős's original paper actually contained an error, and the work of Martínez and Roldán-Pensado explains this and fixes the argument. The future of scientific research is going to be fun.
Community note
GPT-5 did not solve those Erdos problems. It only "found" solutions in the sense of finding existing published literature that solved the problems. Here is an explanation from the maintainer of erdosproblems.com: x.com/thomasfbloom/s…
1
5
1,905
Perri Adams retweeted
This is not that much different than server-driven UI for mobile apps, where server-side logic controls layout, actions, and flow in mobile app UI. It was created to allow changes faster than a client code release could support. Software is software and good patterns re-appear.
14 Oct 2025
Can we eliminate the C2 server entirely and create truly autonomous malware? On the Dreadnode blog, Principal Security Researcher @0xdab0 details how we developed an entirely local, C2-less malware that can autonomously discover and exploit one type of privilege escalation vulnerability. A future where fully autonomous red team assessments are powered by nothing more than a pre-installed local model and a Lua interpreter may be closer than you’d imagine. Read about it here: dreadnode.io/blog/lolmil-liv…
1
4
2,013
15 Oct 2025
Have a Furby 0-day? A Juicero exploit? A bewitched 🪄PoC for some cursed, End-of-Life 👻 product that your friends keep begging you to stop reverse engineering & touch grass? We see you: your real friends are at @DistrictCon Junkyard. 9 days to submit your most unhinged bugs!
2
14
54
12,041
15 Oct 2025

15 Oct 2025
We believe in paying responsible security researchers for their hard work! 🤑
1
3
891
15 Oct 2025
We believe in paying responsible security researchers for their hard work! 🤑
11 Oct 2025
We still have some spots open for DistrictCon junkyard speakers! Not only do you have a chance to show off your awesome work on an end of life target that needs attention – or laughs – but also we are giving out cash prizes to winners!!!
7
33
8,133
Perri Adams retweeted
14 Oct 2025
bring your eol exploits to @districtcon junkyard! now’s the time to flex yr cute demo
1
18
99
15,677
Perri Adams retweeted
9 Oct 2025
RE//verse 2026 CFP is open! Got research? Prove it: sessionize.com/reverse-2026
7
19
5,972
Perri Adams retweeted
7 Oct 2025
This might actually be one of the best panel talks I've ever attended. @OffensiveAIcon
4
12
2,801
7 Oct 2025
Had a great time doing a keynote panel with Rob Joyce and Dave Aitel at @OffensiveAIcon… and love the creative engagement from the audience Photo credit to @caseyjohnellis
3
4
26
3,357
Perri Adams retweeted
Watching @daveaitel @RGB_Lights and @perribus trade friendly blows during the Keynote Panel at Offensive AI Con is too good!

ALT Gregzaj1 Banter GIF

2
13
2,042
Perri Adams retweeted
OAIC Day 1: Complete ✅ The conversation and idea sharing from yesterday's sessions have been bar-none. Plus, a full moon for last night's rooftop party! On deck this morning: --> Breakfast from 7-8:45 AM --> Kickoff at 9 AM with our keynote panel, featuring @RGB_Lights, @perribus, and @daveaitel. #OAIC2025 #OffensiveAICon
6
24
2,471
Perri Adams retweeted
🚀 From DARPA #AIxCC to SWE-bench! Team 42-b3yond-6ug’s small coder model is now: 🏆 #1 on SWE-bench (lite) 💡 #6 on SWE-bench (verified) All while using far less compute than the giants ahead. Big thanks to #AIxCC for fueling this journey!
2
4
30
3,538
Perri Adams retweeted
6 Oct 2025
Excited to be here at #OffensiveAICon for the next two days. 200 people focusing on offensive capabilities surrounding AI in the cybersecurity world. This team is top-notch and couldn't have brought together a more spectacular bunch of people to speak and to be able to participate in the event. I’m hoping to learn a lot. Interact with all the wonderful offensive AI minds. @RGB_Lights @daveaitel @mbazaliy @joshua_saxe @perribus @cyberphor and many more Shoutout to @dreadnode and RemoteThreat for putting the event together. @OffensiveAIcon @SANSInstitute @SANSOffensive
1
2
5
1,228
Perri Adams retweeted
I've spent a lot of time thinking about the best way to teach API security from the ground up for beginners. Today, I'm excited to launch the result: My brand new API Hacking course on JHT. It's built to give you a deep, foundational understanding of how to test modern APIs. 🧵
12
64
464
50,516