@ivMobAppSec

GenAI, Mobile AppSec, Android & iOS Reverse Engineering & Crypto(graphy). opinions = own

/usr/local/bin
Joined May 2010
Are you recruiting them *this* young, @steipete ? 😂
1
142
Ivn 🖤🖤🖤 retweeted
Hiring: iOS Reverse Engineer on my team at Corellium. Bring up iPhones/iPads and new iOS releases on our hypervisor, reverse binaries, build virtual peripherals and tools. US remote. You won't be bored, I promise! cellebrite.com/en/about/care…
1
1
4
635
I'd be interested to see how are things going inside companies in the travel industry right now. There are billions of $ funding teams to solve one specific problem: "booking with AI". Finding the cheapest tickets or better options.
225
Ivn 🖤🖤🖤 retweeted
CVE-2026-100754: ChatGPT's code-signing checks on macOS/Windows can be bypassed by (local, unprivileged) attackers, who then inherits the agent's trust: 💉 Inject prompts 👀 Read private chats 🔓 Access TCC-protected files 🍪 Steal cookies/auth tokens/browsing sessions
Security & privacy used to mean fighting malware and hackers ...now, we have to add "AI agents" to that threat model 🤖 😅 Mahalo to the @nytimes for spotlighting some of our recent ChatGPT research & bugs! nytimes.com/2026/09/29/techn…
5
24
116
9,825
Ivn 🖤🖤🖤 retweeted
si no sabes en qué gastar tus créditos de opus 5.5 tengo 2 proyectos en abierto, la web de helpmiriam y Polaris el sistema agentico que ayuda con mi enfermedad. Todo necesita mejorar github.com/orgs/BeyondThePro…
10
87
4
215
8,779
Ivn 🖤🖤🖤 retweeted
Hello, Little People Living Inside My Computer, I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous. youtube.com/@MalwareForFun
129
381
8
5,116
147,761
Ivn 🖤🖤🖤 retweeted
An excellent new resource by @claucece: a practical cryptography course covering PIR in practice, TLS 1.3, post-quantum integration, and TLS attestation. github.com/claucece/Practica…
1
19
138
6,582
Ivn 🖤🖤🖤 retweeted
I’m hiring a Mobile AppSec engineer at Shopify, based in Canada or the US. Small team, apps used by millions, lots of code shipping every week. You’ll have access to frontier models and build tools to find and fix vulnerabilities before they ship. If that sounds like your kind of work, DM me.
3
7
1
73
6,811
When Patrick speaks, you listen. Period. Great job, Patrick. And +1 on the Kudos to the Muse team.
Hooray, hot-fixed! 😍 Kudos on the quick patch (& full disclosure FTW) 🙏🏽 But there was a 'remote' exploit vector: a simple ClickFix attack could deliver the hijack giving a *remote* attacker complete access then to every victim device running Muse See: arstechnica.com/security/202…
5
878
Ivn 🖤🖤🖤 retweeted
A lot of people have asked... and yes, we’re hiring mobile engineers at Shopify. We’re completely rethinking how mobile apps get built with AI, and there’s a lot to build. Come join us. shopify.com/careers/software…
12
14
192
12,377
Ivn 🖤🖤🖤 retweeted
Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family. It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
3,342
9,030
6,513
97,097
28,130,499
Ivn 🖤🖤🖤 retweeted
And once a Mac is exploited, you can interact with any of the users "connected" devices also running Muse. ...meaning you remotely task their mobile (iOS) Muse client ...invisibly 📲🔓👀 What can you do? Welll, some very neat iOS stuff!
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
12
51
15
332
283,973
Ivn 🖤🖤🖤 retweeted
First, one of 0day PoCs: github.com/pwardle/not-a-mus… Run with `-h` for some fun options from the 50+ commands Muse exposes. Then click Muse’s 🎙️ and dictate a prompt. That’s the trigger. 👀
4
5
3
93
28,557
`endo_voyager_dictation_endpoint`-gate? Nice one, Patrick🔥 👇🏼
Used it to hack itself? 💀 But please fix, its trivial to exploit and (locally) take over the agent 😭 github.com/pwardle/not-a-mus…
2
516
Ivn 🖤🖤🖤 retweeted
TIL macOS 27 now comes with new fm cli 🤯 We can now use Apple's Foundation Models (on device) from CLI!
38
72
21
1,233
282,381
Xcode 27.2 replaces project.pbxproj with a JSON file. Two parts on what that means for security: a real canonical byte form, 4 ways your tooling reads a different file than Xcode does, and the .gitattributes line that switches the whole benefit off. ivrodriguez.com/what-xcodes-…
1
1
5
615
Let's both of us get 1B Muse tokens. Code: ETS6Z0
186
Oh! @Muse is ready in 🇨🇦
176
Oh this is great!
We're adding support for AGENTS.md to Claude Code. Starting today in version 2.1.277, if there is no CLAUDE.md in a folder, Claude will check for and use AGENTS.md. You can toggle this behavior in /config.
1
449