dmnk's Avatar

dmnk

@dmnk.bsky.social

【DΞCOMPILΞ NΣVΞR】 Android Red Team @google Fuzzing @aflplusplus.bsky.social CTF @enoflag (opinions my own)

1,429 Followers  |  264 Following  |  191 Posts  |  Joined: 24.05.2023  |  2.1555

Latest posts by dmnk.bsky.social on Bluesky

Preview
Signal calls on Germany to vote against ‘Chat Control,’ saying it would leave EU market The head of the Signal Foundation raised concerns around Germany now refusing to say whether it will support Chat Control in an upcoming vote.

Signal to leave EU rather than comply w/ Chat Control, which would scan all messages sent over end-to-end encrypted platforms. Vote on Chat Control's future Oct 14. Germany is the swing vote. Officials there opposed the measure in past but new govt silent re position
therecord.media/signal-calls...

06.10.2025 15:37 — 👍 19    🔁 13    💬 0    📌 0

We ported Rust to the Sega Megadrive for the finals 🦀🦀🦀
(Times are off by one)

04.10.2025 18:29 — 👍 7    🔁 0    💬 0    📌 0

Ah times are in Mexican time, do off by one

04.10.2025 13:34 — 👍 0    🔁 0    💬 0    📌 0

My "friend"/coworker

04.10.2025 13:33 — 👍 1    🔁 0    💬 0    📌 0

I got volunteered to be a commentator on semifinal 1 and the final 😅

04.10.2025 07:22 — 👍 1    🔁 0    💬 1    📌 0
Hackceler8 2025
YouTube video by Hackceler8 Hackceler8 2025

Hackceler8 live stream will start on 2025-10-04 21:15 UTC / 14:15 PST

Schedule (PST)
14:15 - Live stream start
14:30 - Semifinals #1
16:30 - Semifinals #2
18:30 - Finals

www.youtube.com/watch?v=xN1W...

04.10.2025 07:15 — 👍 2    🔁 1    💬 2    📌 1

A beer leak?

30.09.2025 23:20 — 👍 0    🔁 0    💬 0    📌 0
Preview
Japan's beer-making giant Asahi stops production after cyberattack  | TechCrunch A day after one of Japan's biggest brewers, Asahi Group, announced it suspended production due to a cyberattack, the company said it has no timeline for its recovery.

NEW: A cyberattack has forced Japan's beer maker Asahi to suspend operations at its plants in the country since Monday.

For now, the company said it's experiencing a "system failure" but did not confirm "leakage of personal information or customer data to external parties."

30.09.2025 16:13 — 👍 13    🔁 9    💬 1    📌 2
Post image

Today, my research group @ Georgia Tech released a paper on vulnerabilities in Tile --- the second largest device finding network after Apple's AirTags.

You can read about it in Wired, reporting by @kimzetter.bsky.social!
www.wired.com/story/tile-t...

29.09.2025 13:45 — 👍 60    🔁 34    💬 1    📌 2

We still have strong guardrails for the model (i.e., the agent has to prove it found a valid bug, it's not allowed to change the harness (yet), ...) else we had to deal with false positives left and right.
However, it finds complex bugs that a fuzzer would never find, so I would say it's a net win..

28.09.2025 17:08 — 👍 2    🔁 0    💬 0    📌 0
Pointer leaks through pointer-keyed data structures Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...

Super cool potential ASLR leak involving dictionary hashes! googleprojectzero.blogspot.com/2025/09/poin...

26.09.2025 17:07 — 👍 10    🔁 6    💬 0    📌 0
Post image

GUIFuzz++ is the first general-purpose fuzzer for desktop GUI software! Fuzzing by translating AFL++ random input into user interaction with GUIs, leading to the discovery of 23 new bugs!

Paper: futures.cs.utah.edu/papers/25ASE.pdf
Source: github.com/FuturesLab/GUIFuzzPlusPlus

Go test some GUIs!

24.09.2025 20:52 — 👍 16    🔁 11    💬 1    📌 0

Adobe premiere - davinci resolve, it's what professionals use, contains features Adobe holds back for after effects, and for everyday tasks the **free** version is enough!

Photoshop, I've been using affinity photo and it gets the job done

Light room: capture one

13.09.2025 15:59 — 👍 0    🔁 0    💬 0    📌 0
Preview
Scientists Are Flocking to Bluesky Academics once loved Twitter—but in the age of X they’ve abandoned it in droves.

Academics once loved Twitter—but in the age of X they’ve abandoned it in droves. www.wired.com/story/bluesk...

28.08.2025 15:33 — 👍 2315    🔁 603    💬 67    📌 62
Preview
Meta forges ahead with facial recognition for its AI glasses Are big tech companies embracing surveillance over privacy?

"Meta originally scrapped the facial recognition feature for the first generation of the Ray-Ban Meta AI glasses over ethical concerns."

mashable.com/article/meta...

28.08.2025 22:25 — 👍 90    🔁 36    💬 9    📌 20
Post image

Yesterday my life changed forever. I discovered that the deli on the corner of my apartment sells these.

20.08.2025 20:54 — 👍 28    🔁 2    💬 2    📌 0
Preview
Introducing Rusted Firmware-A (RF-A) - A Rust-Based reimagination of Trusted Firmware-A Why Rusted Firmware-A?

Very excited to see this

www.trustedfirmware.org/blog/rf-a-blog

#rust #memory-safety

19.08.2025 16:51 — 👍 2    🔁 1    💬 0    📌 0
Preview
USB: the most successful interface that also brings power We use it every day, but how does it really work? USB has been around for almost 30 years and it evolved into really universal interface ...

I use USB daily but I have no idea how it works 🤔

USB 2 vs USB 3, USB-A vs USB-C, the PD standard… this talk is full of interesting details 💎

And now I even understand why my USB-C power bank doesn’t work with *this* cable unless flipped 🙃

media.ccc.de/v/why2025-25...

19.08.2025 20:04 — 👍 32    🔁 9    💬 0    📌 0

Today I have a more serious topic than usual, please consider reposting for reach:

My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder [1/4]

19.08.2025 08:34 — 👍 4    🔁 23    💬 1    📌 0
Preview
GitHub - sensepost/bloatware-pwn: LPE / RCE Exploits for various vulnerable "Bloatware" products LPE / RCE Exploits for various vulnerable "Bloatware" products - sensepost/bloatware-pwn

This repo is hype moments and aura honestly github.com/sensepost/bl...

19.08.2025 05:39 — 👍 58    🔁 10    💬 3    📌 2
The table of contents for Phrack 72 from phrack.org

The table of contents for Phrack 72 from phrack.org

At long last - Phrack 72 has been released online for your reading pleasure!

Check it out: phrack.org

18.08.2025 21:33 — 👍 122    🔁 61    💬 0    📌 4

[RSS] A Fuzzy Escape - A tale of vulnerability research on hypervisors


bughunters.google.com ->


Original->

18.08.2025 10:53 — 👍 1    🔁 1    💬 0    📌 0
Post image Post image Post image

Started working on my Nintendo DS Lite video capture to HDMI project today after weeks of zero motivation. Huzzah!

Fun fact, the fastest signals here are about 10 times slower than on the N64 (~5.5 MHz vs ~50 IIRC), which reduces the risk for signal integrity problems.

08.08.2025 22:55 — 👍 38    🔁 4    💬 1    📌 0
Preview
laf-intel

So does anyone actually know who laf-intel (lafintel.wordpress.com) is? Having a citation of just some blog name doesn't feel right to me

17.08.2025 06:13 — 👍 1    🔁 1    💬 0    📌 0
From Chrome renderer code exec to kernel with MSG_OOB Posted by Jann Horn, Google Project Zero Introduction In early June, I was reviewing a new Linux kernel feature when I learned about the...

Exploiting Linux kernel from Chrome renderer with MSG_OOB (Google Project Zero)

googleprojectzero.blogspot.com/2025/08/from...

#infosec #chrome

16.08.2025 09:47 — 👍 5    🔁 3    💬 0    📌 0
Post image

@blackhoodie.bsky.social will be at @sec-t.bsky.social on September 10th with a training on Linux Malware Reverse Engineering, for women by women! We have very few seats left 😁 blackhoodie.re/SecT2025/

14.08.2025 14:02 — 👍 12    🔁 9    💬 0    📌 0

CV Enhancers

14.08.2025 09:29 — 👍 9    🔁 1    💬 0    📌 0
Post image Post image

At USENIX Security? Then check out:

Studying the Use of CVEs in Academia, won distinguished paper award www.usenix.org/conference/u...

Discovering and Exploiting Vulnerable Tunnelling Hosts, won most innovative research Pwnie @ DEFCON www.usenix.org/conference/u...

Big thanks to all co-authors!!

13.08.2025 22:30 — 👍 14    🔁 6    💬 0    📌 1
Preview
GitHub - R9295/autarkie: Autarkie - Instant Grammar Fuzzing Using Rust Macros Autarkie - Instant Grammar Fuzzing Using Rust Macros - R9295/autarkie

Repo is here:
github.com/r9295/autarkie
#Fuzzing #LibAFL #AFLplusplus

12.08.2025 11:35 — 👍 0    🔁 0    💬 0    📌 0

@dmnk is following 20 prominent accounts