Cover art from the DEF CON special hardcopy release of Phrack issue #72.
The #defcon hardcopy of @phrack.org is a thing of beauty!
As usual, the content has excellent technical depth & spirit... I really felt a connection reading Orange Tsai's musings on CTF and his role as a "bug archeologist."
Hats off to everyone involved; it will always have a spot on my bookshelf.
12.08.2025 21:18 β π 3 π 0 π¬ 0 π 1
Logo for LiveCTF (livectf.com)
If you're not at #defcon right now and feeling some CTF FOMO, you can still tune in and watch the semifinal and final matches of LiveCTF at livectf.com
Scroll down for a bracket with matches in your local time, and tune in!
10.08.2025 15:12 β π 2 π 1 π¬ 0 π 0
Live-streamed head-to-head speed CTF sidecar to the DEF CON CTF... it's gonna be awesome!
08.08.2025 16:54 β π 0 π 0 π¬ 0 π 0
If youβre headed to DEF CON, donβt miss the AIxCC exhibit.
Not just to see me; though Iβll be there and at LiveCTF...
But to meet with some great minds in AI/cybersecurity space, and hear how the data from the competition will might drive a lot of future research.
But yes, also come by to see me!
04.08.2025 18:30 β π 0 π 1 π¬ 0 π 0
Just got back from speaking at @summerc0n.bsky.social which was great fun!
They really have a unique vibe that's only possible from a small conference with a loyal following.
Personally I appreciate the conference's sense of style and personality, and their meme game is impeccable! π
15.07.2025 16:08 β π 0 π 0 π¬ 0 π 0
Extremely interesting comparisons in cybersecurity...
The 1οΈβ£ thing to focus on? Talent.
Talented people have outsize impacts in software and cybersecurity. And expertise drives better policy (eventually)!
Pipelines to build more experts pay compounding returns.
25.06.2025 15:24 β π 3 π 1 π¬ 0 π 0
YouTube video by pwn.college
seeinglogic and zardus talk about getting into the cybersecurity industry
Had a great time talking with @zardus.bsky.social about getting started in cybersecurity: www.youtube.com/watch?v=n9QW...
Primary thrust: Try something that interests you, then keep trying things.
Every time, you'll either succeed, learn something, or meet new people, and this builds over time.
20.06.2025 14:55 β π 1 π 1 π¬ 0 π 0
Dear Bluesky friends: where do you buy hacker shirts?
Looking for something fresh, and there's definitely a line between cool and trying too hard.
06.06.2025 14:43 β π 0 π 0 π¬ 0 π 0
π¨ CALLING ALL VULNERABILITY RESEARCHERS π¨
The Junkyard is officially open!
This is our live, on-stage pwnathon dedicated to end-of-life systems. Submit your bugs!
Prizes range from $100 to $5,000 for categories like:
βοΈ Most Impactful System
πΎ Best Meme Target
π Most Engaging Presentation
28.05.2025 14:14 β π 19 π 18 π¬ 1 π 0
DistrictCon
We're thrilled to announce we're coming back for DistrictCon Year 1!
ποΈ Jan 24-25, 2026
πCapitol Hilton
Early bird tickets will be sold in September, and GA tickets in November! Call for Talks, Policy roundtables, and Bugs coming soon π
www.districtcon.org
06.05.2025 16:00 β π 23 π 12 π¬ 0 π 4
Pattern in the Noise: Structured Fuzzing with Python
βWhat happens if I need to fuzz something that doesnβt take strings or buffers as inputsβ is the question Iβve come to dislike most when talking to people about fuzzing.
Wrapping up my posts on Python #fuzzing by going through different ways to generate structured/complex inputs: seeinglogic.com/posts/struct...
I focused on Python because there isn't as much written on it, but the concepts apply to any language and across tools!
28.04.2025 17:13 β π 0 π 0 π¬ 0 π 0
Skip the hype, watch top CTF players for whether LLMs are changing the game (or not).
@hgarrereyn.bsky.social tells it like it is and shares his code to boot π
23.04.2025 20:57 β π 0 π 0 π¬ 0 π 0
GitHub - Live-CTF/LiveCTF-DEFCON33
Contribute to Live-CTF/LiveCTF-DEFCON33 development by creating an account on GitHub.
@livectf.bsky.social just posted their challenges and the solutions from the DEF CON quals: github.com/Live-CTF/Liv...
This means 6β£ challenges to replay, with solutions from some of the best CTF teams in the world.
Challenge-4 (sokobin) lets you push bits around on the stack to get the flag π€―
16.04.2025 14:46 β π 2 π 1 π¬ 0 π 0
LiveCTF
Past events:
*tap*, *tap* This thing on?
It's that time again! Prepare yourself for another DEF CON CTF qualifiers with a LiveCTF component this weekend! Thanks to @Nautilus_CTF for having us back and running another year! Keep an eye out here and at livectf.com for more details.
10.04.2025 21:47 β π 3 π 3 π¬ 0 π 0
Exploitation of AIxCC Nginx bugs: Part I
This blog post will analyse the exploitability of the temporal safety vulnerabilities in Nginx AIxCC.
AIxCC is a DARPA competition to find vulnerabilities in codebases using AI. The competitors are no...
Enjoyed this deep-dive on attempting to exploit AIxCC's NGINX heap bugs: roundofthree.github.io/posts/nginx-...
Dense material, but enjoyed that they:
- Gave detailed allocator comparison
- Tried application-specific approaches
- Combined bug primitives
- Used a now-public vulnerability dataset!
30.03.2025 21:25 β π 0 π 0 π¬ 0 π 0
Thanks for kind words, and thank you for reading!
It has been a minute since I wrote this, and you bring up a good point with LLMs being much more present in the coding environment now than when I wrote it. Maybe worth revisiting!
11.03.2025 20:10 β π 0 π 0 π¬ 0 π 0
Heard a lot of people wondering how good RE//Verse
would be, and I can say...
It's been awesome.
Similar in vibe to Infiltrate and OffensiveCon, plus a super positive hosting crew.
Great talks so far, I'm biased but really liked @mahal0z.bsky.social 's on improving decompilation β΅
28.02.2025 22:48 β π 5 π 1 π¬ 0 π 0
What an amazing crew, everyone was great and a pleasure to work with.
Unbelievable resolve and effort... to run a con with the lights out!
23.02.2025 14:43 β π 1 π 0 π¬ 0 π 0
Reaching out to you both!
14.02.2025 16:19 β π 1 π 0 π¬ 0 π 0
Report from CISA & friends on the Software Understanding Gap leading to national security-level issues: media.defense.gov/2025/Jan/16/...
This is what I'm working on improving, right in the IDE.
Reach out if you or your team wants to understand code better, I'd like to hear about your problems.
13.02.2025 15:02 β π 2 π 0 π¬ 1 π 0
Data art of a stacked area chart arranged to look like a mountain scene. Annotations added to show categorization of author's talks in 2020 and 2024. Original source: https://www.kopidion.com/projects.html
Looking back, what made ShmooCon so awesome?
My two cents: 1) community 2) high quality talks on a wide variety of topics.
Greg Conti & co made this to depict the 801 talks over the last 20 years... and I added arrows to show where my two snowflakes are on the mountain.
We'll miss you, ShmooCon.
16.01.2025 01:26 β π 1 π 0 π¬ 0 π 0
YouTube video by EuropeVEVO
Europe - The Final Countdown (Official Video)
See you at Shmoo!
A huge thanks to the Shmoo crew... it has been one of my favorite cons and has a special place in my heart as my first big con to speak at.
To commemorate the Final ShmooCon, please give this a listen and substitute "Countdown" with #shmoocon in your head: youtu.be/9jK-NcRmVcw π
09.01.2025 14:35 β π 2 π 0 π¬ 0 π 0
YouTube video by Napalm Records
NANOWAR OF STEEL - HelloWorld.java (Source Code Video) | Napalm Records
For the coders who just need a laugh right now... This was even better than I expected π
Also, I love "pippo" even though I don't think I've ever seen it used before...
www.youtube.com/watch?v=yup8...
18.12.2024 16:58 β π 0 π 0 π¬ 0 π 0
P.S. For any #LLM wizards out there: can you get a model to produce a version of my target that doesn't crash when dropped in to the harness?
Arithmetic expression evaluation seems to be just difficult enough to give LLMs trouble.
So if you can crack it, I'm interested to learn from your wisdomπ§
13.12.2024 23:13 β π 0 π 0 π¬ 0 π 0
GitHub - seeinglogic/python-fuzzing
Contribute to seeinglogic/python-fuzzing development by creating an account on GitHub.
Just pushed some #Python fuzzing example code to go along with the tutorial posts from my blog.
Check it out to see:
- A basic template you can reuse and adapt
- How to build basic valid inputs from fuzz data
- Demo of property testing & differential fuzzing
Repo: github.com/seeinglogic/...
13.12.2024 23:13 β π 2 π 0 π¬ 1 π 0
Advent of Code 2024
Best time of year is here, adventofcode.com time π
Fantastic refresher, speed challenge, or for trying new languages/ideas.
The problems are fun, and start easy but get harder.
Plus they aren't linked, so don't worry about starting late or skipping a day. Let me know if you give it a try!
06.12.2024 15:59 β π 0 π 0 π¬ 0 π 0
Fuzzing Python for Correctness: Checking on ChatGPT
One of the biggest issues with LLM-generated code is a lack of trust, mostly stemming from a lack of understanding from not having written it personally, and reduced confidence that the code handles e...
Curious about property-based testing or differential fuzzing for #Python?
How about a method to help catch hidden assumptions in AI-generated code?
Check out how to apply expert testing methods to find unexpected correctness bugs in non-trivial code: seeinglogic.com/posts/checki...
06.11.2024 21:34 β π 0 π 0 π¬ 0 π 0
@DistrictCon Founder. Harvard & Georgetown MPP/JD candidate. @CyberStatecraft / @BelferCenter fellow, ex-Google threat research. Dog mom. Opinions=my own π©π»βπ»
The Workshop on Software Understanding and Reverse Engineering (SURE). Co-located at ACM CCS 2025 in Taiwan. https://sure-workshop.org/
Native Hawaiian Hacker | Prev Co-captain of @Shellphish | PhD Student in Comp Sci @ASU l Decompiler Research | https://mahaloz.re
A new DC hacker conference: Bringing together builders, breakers, and fixers to do cool shit.
Jan. 24-25, 2026
districtcon.org
Identity and identity security geek with trimmings of scout-dad and board-game and computer-game aficionado. My profile picture may be AI generated (it is) but I'm not.
Geopolitics, Russia, China, Cyber
Chairman @silverado.org
Author of WorldOnTheBrink.com
Host GeopoliticsDecanted.com podcast
Founder Alperovitch Institute for Cybersecurity Studies at Johns Hopkins SAIS
Co-Founder CrowdStrike
@DAlperovitch elsewhere
Security, diversity, housing, Canadian stuff π¨π¦. Cofounder and CEO of @tallpoppy.bsky.social; more at leighhoneywell.com
Security Geek. We build Thinkst Canary - https://canary.tools
ποΈ Enterprise Security Weekly Podcast Host,
π€ BSides Knoxville Founder,
π£οΈ IANS Research Faculty,
π³ Cooking,
ποΈ F1,
β°οΈ Hiking
Hacker -> DARPA -> Founder -> Investor. Currently CEO of SportsVisio.com, GP at 10X Venture Partners (10xvp.com) Love to connect to new people!
Ex-fed hacker turned startup guy. Co-founder & CEO at Sevco Security, previously CTO @ JASK, founding team @ Carbon Black, 12 year US intelligence officer.
Founder/CEO at Opnova. Formerly Founder/CEO Fyde & Remotium.
https://opnova.ai
Founder of The Vertex Project (@vtxproject)
Father of the #APT1 Report @Mandiant.
Inventor of #synapse, #vivisect, UNCs, imphash, ...
DEFCON CTF Champion, Founder of Kenshoto
Founder & CEO at Tenzir β security data pipelines Β» docs.tenzir.com
β https://github.com/tenzir/tenzir
β https://github.com/tenzir/library
#SecDataOps #SecOps #DataOps #SOC #SIEM #ThreatHunting #DetectionEngineering #IncidentResponse #ThreatIntel #COSS
Hardening for food. Open Source, Cloud and Security. Giving π€ to Prowler since 2016. Linux, DFIR, CISSP, Heavy Metal. Del Atleti. http://prowler.com
Cybersecurity Executive and Thought Leader
Cofounder & CEO @northpolesec.bsky.social
Prev: @google working on Security Agents including Santa. Cofounder and Chief Architect @capsule8 (tweets are my own.)
Personal Blog: https://blog.markowsky.us
Company Website: https://northpole.security
Co-founder | Leen (Unified API & Data Fabric for Security)