@ivMobAppSeci
iAccount based inCanada
About this account
- Account based in
- Canada
- Connected via
- Canada App Store
Account-level information from X, not a live location or the device used for a specific post.
GenAI, Mobile AppSec, Android & iOS Reverse Engineering & Crypto(graphy). opinions = own
/usr/local/bin
Joined May 2010
- Tweets22.2K
- Following971
- Followers4.3K
- Likes16.9K
Hiring: iOS Reverse Engineer on my team at Corellium. Bring up iPhones/iPads and new iOS releases on our hypervisor, reverse binaries, build virtual peripherals and tools. US remote.
You won't be bored, I promise!
cellebrite.com/en/about/care…
I'd be interested to see how are things going inside companies in the travel industry right now.
There are billions of $ funding teams to solve one specific problem: "booking with AI". Finding the cheapest tickets or better options.
Ivn 🖤🖤🖤 retweeted
we're building a (PQ) CA 🔥 blog.cloudflare.com/cloudfla…
Ivn 🖤🖤🖤 retweeted
CVE-2026-100754: ChatGPT's code-signing checks on macOS/Windows can be bypassed by (local, unprivileged) attackers, who then inherits the agent's trust:
💉 Inject prompts
👀 Read private chats
🔓 Access TCC-protected files
🍪 Steal cookies/auth tokens/browsing sessions
Security & privacy used to mean fighting malware and hackers
...now, we have to add "AI agents" to that threat model 🤖 😅
Mahalo to the @nytimes for spotlighting some of our recent ChatGPT research & bugs!
nytimes.com/2026/09/29/techn…
Ivn 🖤🖤🖤 retweeted
si no sabes en qué gastar tus créditos de opus 5.5 tengo 2 proyectos en abierto, la web de helpmiriam y Polaris el sistema agentico que ayuda con mi enfermedad. Todo necesita mejorar
github.com/orgs/BeyondThePro…
Ivn 🖤🖤🖤 retweeted
Hello, Little People Living Inside My Computer,
I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous.
youtube.com/@MalwareForFun
An excellent new resource by @claucece: a practical cryptography course covering PIR in practice, TLS 1.3, post-quantum integration, and TLS attestation.
github.com/claucece/Practica…
Ivn 🖤🖤🖤 retweeted
I’m hiring a Mobile AppSec engineer at Shopify, based in Canada or the US. Small team, apps used by millions, lots of code shipping every week. You’ll have access to frontier models and build tools to find and fix vulnerabilities before they ship. If that sounds like your kind of work, DM me.
When Patrick speaks, you listen. Period.
Great job, Patrick. And +1 on the Kudos to the Muse team.
Hooray, hot-fixed! 😍 Kudos on the quick patch (& full disclosure FTW) 🙏🏽
But there was a 'remote' exploit vector: a simple ClickFix attack could deliver the hijack giving a *remote* attacker complete access then to every victim device running Muse
See: arstechnica.com/security/202…
Ivn 🖤🖤🖤 retweeted
A lot of people have asked... and yes, we’re hiring mobile engineers at Shopify. We’re completely rethinking how mobile apps get built with AI, and there’s a lot to build. Come join us.
shopify.com/careers/software…
Ivn 🖤🖤🖤 retweeted
And once a Mac is exploited, you can interact with any of the users "connected" devices also running Muse.
...meaning you remotely task their mobile (iOS) Muse client ...invisibly 📲🔓👀
What can you do? Welll, some very neat iOS stuff!
Ivn 🖤🖤🖤 retweeted
First, one of 0day PoCs: github.com/pwardle/not-a-mus…
Run with `-h` for some fun options from the 50+ commands Muse exposes.
Then click Muse’s 🎙️ and dictate a prompt. That’s the trigger. 👀
`endo_voyager_dictation_endpoint`-gate?
Nice one, Patrick🔥
👇🏼
Used it to hack itself? 💀
But please fix, its trivial to exploit and (locally) take over the agent 😭
github.com/pwardle/not-a-mus…
Ivn 🖤🖤🖤 retweeted
TIL macOS 27 now comes with new fm cli 🤯
We can now use Apple's Foundation Models (on device) from CLI!
Xcode 27.2 replaces project.pbxproj with a JSON file. Two parts on what that means for security: a real canonical byte form, 4 ways your tooling reads a different file than Xcode does, and the .gitattributes line that switches the whole benefit off.
ivrodriguez.com/what-xcodes-…