Is “Robofuzzing” taken? If not this new bug hunting should now be called robofuzzing.
Posts by Nad
Unless yall mean dollarydoos, that is a seperate and failed currency.
Australian here, yes we do just turn the USD upside down.
I need a Covfefe, a Big Mac and an Amphetameme.
Just got access to Mythos.. here’s a rare glimpse into its inner workings..
They got a Claude that isn’t Autistic? Like Gemini type Claude?
I been using Gemini as a normy to Autism translator but me n Claude be gaslighting each other 🤣.
I see people trying to evade Defender.. I got some weird flavour of Autism where I’m having the opposite problem. I’m trying to trigger defender but can’t work out how to make malware that actually sets this heap of shit off 🤣🤣
I could go and look but that’s no fun.
ADHD is defined by having people constantly tell you you can’t do this and you can’t do that.
But your just standing there thinking to yourself “This person clearly hasn’t realised that I’ve already done all of the things they’re telling me I can’t do”
Like bruh I’m sorry its it’s already too late
🤣
Wordpress just needs to be set on fire
👀
You pay the robot to introduce the vulnerability, Then you pay the same robot to ‘find’ and ‘fix’ the vulnerability.
The cooling loops need more elctrolytes, it’s what the GPU’s crave!
Gods work. Thanks legends :)
CVE-2026-31413 - Linux Kernel Local Priv Esc
One extra + 1. That's the whole bug.
BPF verifier: insn_idx + 1 instead of insn_idx. Skips an instruction. For BPF_OR, verifier sees zero, CPU has your constant. Arbitrary kernel R/W.
Full container escape. Just CAP_BPF.
www.nadsec.online/blog/bpf-con...
CVE-2026-31413
Found a 1-char bug in the Linux BPF verifier. A + 1 that should've been + 0 in maybe_fork_scalars() gives you OOB map access and full container escape from any pod with CAP_BPF. Fix in 7.0-rc5.
-Technical writeup with POC dropping soon.
-Patched by me =-]
www.cve.org/CVERecord?id...
They just weren't paying the guy enough to not steal 100 mil worth of exploits and get absolutely bent over by the Russians...
If I was earning half what that guy would have been I wouldn't be having money troubles lmao.
One day they’re gonna put “no long boi dashes” in the system prompt and it will be all over.
So Anthropic Mythos only available to certain people and orgs as part of a gated rollout.
Thank god it won’t be possible to phish any of those certain peoples accounts and thank god none of them have an info stealer installed! Otherwise criminals would be able to use it!
It does exist (kinda) I setup my own similar setups. The backend that powers and enables all this stuff is nuts
Hmu
@d3ada55.bsky.social
At the end of the episode you guys were talking about a non-malicious super box and how it would be crazy if that existed.
@jackrhysider.bsky.social
-leekhoarder@onlineupdate.zip
The Robot has began writing its monthly reports.
I swear they’re funny..
Here’s the March ssh/telnet report, more can be found on my site, Robert is finishing the remainder up now:
www.nadsec.online/ssh-telnet
-written by Robert, the self-proclaimed Senior Threat Intelligence Goblin
Yup
March update:
Still no hoverboards, cigarettes are still bad for you..
🤣🤣💯💯
But Claude says I’m a big boy and I did it myself :(
I can already do this
When are people going to get realistic and accept that these AI agents effectively are holding zero days for every single piece of technology on Earth RN.
So many people in denial..
yall gonna find out over the next couple of month or so… (more likely the next couple of week)