Security researcher 🇦🇺 Good-faith hacking 🤡 Weaponizing source code 🧬 github.com/sickcodes

Joined June 2020
1,099 Photos and videos
Pinned Tweet
14 Aug 2022
Playing Doom on a John Deere tractor display (jailbroken/rooted) at @defcon
56
788
3,217
Sick.Codes retweeted
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…
12,316
25,565
86,999
86,727,458
Sick.Codes retweeted
Much guardrail, amaze amaze amaze
37
51
756
42,879
Sick.Codes retweeted
Claude helped me with this bug too but in a different way... Tried to gaslight me saying it wasn’t ~exploitable in practice~ and I got obsessed with proving it wrong 😩
Confirmed! @chompie1337 of IBM X-Force Offensive Research (XOR) used a race condition to escalate privileges on Red Hat Enterprise Linux for Workstations, earning $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin
42
100
1,345
79,052
Sick.Codes retweeted
THE MAYOR WAS A CHINESE SPY
May 11
NEW: Eileen Wang, the mayor of Arcadia, California, has been charged with acting as an illegal foreign agent for China, the Justice Department announced on Monday. Wang agreed to plead guilty, the Justice Department said. abcnews.link/IntbpBy
190
3,602
62,598
1,817,634
Sick.Codes retweeted
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3 weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150 researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
31
379
1,505
413,786
Sick.Codes retweeted
May 11
I was hoping to compete in Pwn2Own with a Firefox full-chain entry, but unfortunately it was rejected. I’ve reported the vulnerability to the Mozilla team.
31
95
720
110,991
Sick.Codes retweeted
Apr 30
Apple accidentally left Claude.md files in today's Apple Support app update (v5.13)
283
1,029
13,547
2,599,928
Sick.Codes retweeted
yeah you wrote it dumbass
55
224
12,126
295,320
Sick.Codes retweeted
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server self-replicate. link below
307
2,241
9,329
5,850,138
Sick.Codes retweeted
vibe coded a fuzzing ai agent last month and let it run for a week using my $200 claude max. it then found 21 high/critical vulnerabilities in Chrome.
98
260
3,048
572,826
Sick.Codes retweeted
Mar 20
🚨BREAKING: SUPER MICRO CO-FOUNDER ARRESTED FOR SMUGGLING $2.5B IN NVIDIA GPUs TO CHINA >SMCI co-founder Yih-Shyan "Wally" Liaw arrested today >personally holds $464 MILLION in SMCI stock >charged with smuggling BILLIONS in Nvidia servers to china >used a southeast asian shell company to funnel $2.5B in servers to chinese buyers >$510 million worth shipped in just THREE WEEKS in spring 2025 >built thousands of fake dummy servers to fool U.S compliance auditors >caught on surveillance camera using a HAIR DRYER to swap serial number stickers >coordinated the whole thing over encrypted group chats >SMCI down 12% after hours >faces up to 30 years in federal prison ITS SO OVER…
Three Charged with Conspiring to Unlawfully Divert Cutting Edge U.S. Artificial Intelligence Technology to China “The indictment unsealed today details alleged efforts to evade U.S. export laws through false documents, staged dummy servers to mislead inspectors, and convoluted transshipment schemes, in order to obfuscate the true destination of restricted AI technology—China,” said John A. Eisenberg, Assistant Attorney General for National Security. “These chips are the product of American ingenuity, and NSD will continue to enforce our export-control laws to protect that advantage.” 🔗: justice.gov/opa/pr/three-cha…
1,539
8,377
33,985
10,247,879
Sick.Codes retweeted
Jan 29
oh my god
211
162
7,399
573,207
Last year, a human trafficking victim trapped in a crypto scam compound in the Golden Triangle region of Laos contacted me. He proceeded to leak a huge trove of the compound's internal materials. Then he had to get out alive. This is his story. 🧵👇 wired.com/story/he-leaked-th…
45
807
2,680
499,627
Sick.Codes retweeted
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
65
717
8,506
301,483
Sick.Codes retweeted
So Sony just sold the majority of its TV business to TCL. Truly the end of an era. I don’t think younger generations today (can) understand what it meant to walk into someone’s house and see a Sony TV.
880
2,790
27,004
1,583,857
Sick.Codes retweeted
I just found this in my son’s room is he doing drugs?
4,033
1,045
31,804
18,112,894
27 Dec 2025
AI-powered pre-workout powder…
2
1
14
1,146
Sick.Codes retweeted
Biggest web scraping company in the world is suing a web scraping company for web scraping its content obtained through web scraping.
159
1,100
14,954
635,608
Sick.Codes retweeted
13 Dec 2025
i have never failed a phishing test because i always raise a ticket directly with the cyber team pointing out that an email signed passing DMARC & SPF from our domain AND bot addy with 0 mailtrace results means that the attacker already pwnd our exchange server n its too late
22
177
6,710
171,012
Sick.Codes retweeted
found the redhat exec
10 Nov 2025
Linux shouldn’t be free.
12
102
3,552
78,837