AI x Infosec Researcher @RevEng_AI • Binary Program Analysis • PhD Candidate @TUBerlin • prev. built @VulHuntRE at Binarly • Capturing Flags for @ENOFLAG

Germany
Our work on exploring new ways for efficient firmware fuzzing will be published at @USENIXSecurity 2023! With SAFIREFUZZ, we introduce near-native rehosting, drastically improving the performance of fuzzing embedded targets. Super happy about this work w @domenuk @nSinusR
3
57
204
42,130
>let Astra churn through 60% of weekly limit on an 8 hour goal >@thsottiaux hits the limit reset button blessed morning
3
262
LLMs can produce increasingly pleasant-looking C, but whether that code still describes the binary remains tough to answer. CHISEL is the newest paper in a line of iterative approaches: it augments compiler-guided syntax repair with differential fuzzing to catch semantic drift.
5
8
118
5,203
CHISEL reaches 96.1% recompilability and 79.8% re-executability on a small dataset but also discusses incorrect acceptance as a problem. false positives are an inherent challenge in dynamic approaches, where your signal is only as good as your observability and coverage.
1
1
377
today, we @RevEng_AI released the next generation of our decompiler: Ventris the new model comes with improved struct layout recovery, better PE support, and more. on decbench, we beat all other available decompilers in structure recovery, and achieve #2 rank overall
3
19
107
18,288
we submitted and verified our results via the public site: decbench.com/leaderboard/?da… (`normalize` as there is no arch-specific view right now) it's cool to see that our {static context collection -> one-shot decompilation} approach can compete with fully agentic frontier LLMs
1
1
9
1,400
it's great that with decbench, we have a high-quality public benchmark. yet, decompiler evaluation remains hard, and I see two primary challenges right now: 1. high-quality, real-world-like, fully private data. Frontier LLMs have seen virtually every open source function in existence and leakage is not fully avoidable, something we also cannot rule out for our model. 2. finding a better proxy for semantic fidelity. A program can recompile, but do something entirely different. A program can also recompile, have a totally different byte-level structure from the groundtruth, and still do the same job. Dynamic-execution based attestation is tough to get correct at scale, but might be a better signal in the long run.
1
7
959
> rehosting [the Tesla Wall connector] gives you basic block coverage and >1,000 inputs per second, making the difference between "unfuzzable" and finding the bug heck yeah! awesome talk on firmware fuzzing and a wormable charger bug
Our @BlackHatEvents USA slides and demo video are now available! We plugged into a Tesla Universal Wall Connector and showed how an attacker could walk out with a worm that crosses four vendors, with no human in the loop after launch. Links and more info in comment
8
609
authors of SIMurai [1] dropping some new cellular security research: CATana meticulous naming scheme for a super intriguing line of research [1] usenix.org/system/files/usen…
Our @wootsecurity'26 paper "CATana" is now available: usenix.org/system/files/woot…! In the paper, we find that some phones and many IoT devices execute AT commands sent by the SIM, leading to a wide range of consequences from DoS over 2G downgrade to device compromise.
7
648
happy birthday, Binji! @vector35
1
5
765
interesting experiment in automated decompiler research: take a baseline impl and some well-defined metrics and let an LLM improve it! extracting the core insights from and looking for real innovations in such a self-refinement loop presents another challenge we need to solve to truly advance decompiler engineering. but it's definitely neat to see this make progress, and important to have good benchmarks for decompiler development!
I'd like to introduce Kuna, a new Rust-based decompiler that explores a highly experimental direction: self-refining decompiler development and usage. Or: a decompiler constantly improved by agents, made for agents. Kuna rivals the best in structuring now. Let's talk about it.1/
2
12
787
really didn't feel like paying $300 for the codex micro but I liked the idea of agent state indicators. so I ordered some frosted keycaps and had a sweet weekend project: a daemon normalizes codex/claude/omp events, tracks sessions, and updates LEDs via custom VIA/QMK channel
2
17
4,111
to me, it seems like a truthful adaptation. the problem is that while Neuromancer described never-before-seen things when it came out, since then the themes have been used over and over, so people might think this does not look exciting. I am excited.
I dunno man I think cyberpunk is gonna have to get more cyber and more punk to seem different from everyday life at this point Also, Pantheon
4
516
this is huge for decompiler evaluation and development! when people started using LLMs for decomp, hallucinations and subtle cfg differences prevailed, now, LLMs top the leaderboards. the field has made rapid progress recently and measuring it is crucial for future progression.
We are approaching perfect binary decompilation, and, crazier still, LLMs may soon be the best decompilers on the planet. I'd like to introduce DecBench, an evaluation site to determine how close we are to completing the field of perfect decompilation. Links and more in 🧵
1
17
1,640
the soundtrack remains undefeated
The Ghost in the Shell (2026) and Ghost in the Shell (1995)
5
623
perks of doing research at the intersection of AI and infosec: no one is getting blocked/downgraded faster than you
I'm so glad Fable is back. Over the last couple weeks I really missed typing one message and then getting immediately bounced to Opus
6
495
interesting new paper on LLM-based decompilation: AutoDecompiler is an RL-optimized model for feedback-driven, multi-turn decompilation. although previous one-shot approaches might have optimized for recompilation or even executability, they did not utilize feedback directly.
2
14
70
4,341
the paper has quite a few interesting ideas, including their RL goals: the authors not only use recompilability and re-executability but also a syntactic reward based on AST-similarity and a dataflow reward comparing normalized relations between reference and generated code
1
1
7
497
for their multi-turn refinement, they introduce trajectory goals, e.g., rewarding progression and final quality while not conclusive, I think this research is an insightful step towards behaviorally equivalent decompilation paper by Liu et al.: arxiv.org/pdf/2606.16162
1
6
427