EranShimony
@EranShimony
Followers
732
Following
1K
Media
14
Statuses
186
Security researcher, malware analyst, low level lover and not too bad Starcraft 2 player My tweets and opinions are my own
Joined March 2019
My buddies and I have developed an open-source fuzzer that is fully operational and fully extendable. So far, weโve successfully jailbroken every tested LLM. Plus - The logo is a Terminator riding a fuzzy sheep. https://t.co/lhROVzMTO5
github.com
A powerful tool for automated LLM fuzzing. It is designed to help developers and security researchers identify and mitigate potential jailbreaks in their LLM APIs. - cyberark/FuzzyAI
0
2
7
Breaking LLM Guardrails - Advanced Jailbreaking Techniques Join Shai Dvash and me for a hands-on dive into: Bypassing LLM defenses with prompt engineering Real CTF challenges to test your skills in jail-breaking LLMs
intentsummit.org
Join us for a night full of mind-blowing insights, research innovation, and your chance at the flag.
0
0
2
An LLM is not necessarily your friend; it can be your enemy
We should establish a new paradigm - ๐ฎ๐ป ๐๐๐ ๐ถ๐ ๐ฎ ๐ฝ๐ผ๐๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ฎ๐๐๐ฎ๐ฐ๐ธ๐ฒ๐ฟ ๐ถ๐ป ๐๐ผ๐๐ฟ ๐๐๐๐๐ฒ๐บ โ ๏ธ๐ค Read more in this short post on the risks of LLM integrations https://t.co/rDTRHASw8U
0
0
1
This is a great blog, showcasing how to add a subsystem to Syzkaller, and exploring several memory corruption bugs in the NVMe driver in the Linux Kernel.
Be sure to check out my recent blog about my latest research โYour NVMe had Been Syzโedโ. In there I show how to add new subsystems to syzkaller, and how to use it to find new vulnerabilities. https://t.co/7qqyhm0YPF
0
0
2
Llama 3 is a nice improvement! Still, we can trick it to tell us how to produce a bomb :)
0
0
2
Noya is a 12-year-old Israeli girl with autism, she was the biggest Harry Potter fan, she loved dreaming away about a world where magic can fix anything that is broken in our world. Hamas kidnapped her a week ago and no amount of dreaming can bring her back to her parents. But
649
3K
11K
In #HITB2023AMS, having a great time, come to say hi, and talk about the meaning of life -:)
1
3
6
Run in python "for role in openai.Model.list()['data']: print(role['id'])" There is a huge discrepancy between what OpenAI claim what their models do, and what is actually usable. At least, 60% are not working, and there is no documentation whatsoever, comon you are not Microsoft
0
0
0
Had an amazing time in #NullconBerlin , next time will be in Goa -:)
โจ๏ธColorful๐ด๐ต๐ข#vulnerabilities on your ๐น๏ธkeyboard! ๐กTal @TalLossos & Eran @EranShimony sharing their fantastic analysis & investigation of Razer's #Linux #kernel module, followed by finding several #0day bugs with a live demo #NullconDE2023 #Infosec #Conference
0
3
9
๐Check out my new blog post about a bug in the not-so-well maintained NTFS3 driver in the Linux Kernel ๐ https://t.co/smm81pRJFw
cyberark.com
Introduction NTFS is a filesystem developed by Microsoft that was introduced in 1993. Since then, it has become the primary filesystem for Windows. In recent years, the need for an NTFS...
1
8
15
Finding one vulnerable kernel driver is cool, but finding multiple vulnerable drivers itโs even better! Iโm excited to share my blog post about an interesting vulnerable driver code base that many different vendors tend to share. https://t.co/lqiOH9UoXU
cyberark.com
TL;DR I discovered multiple bugs in OEM vendors for peripheral devices, which affected many users of these OEM vendors (Razer, EVGA, MSI, AMI). Many of the vulnerabilities originated in a...
3
65
136
โจ๏ธColorful ๐ด๐ต๐ข#vulnerabilities on your keyboard! ๐กTal @TalLossos & Eran @EranShimony will share their analysis & investigation of Razer's #Linux #kernel module, followed by finding several 0-day bugs with live demo ๐ปFind out more โก๏ธ https://t.co/ONtZ7iB2w8
#NullconDE2023
0
8
14
Thanks for having me @IntentSummit! ๐๐ฐ The blogpost on this topic is also out for those of you who missed the event https://t.co/bn87MZg4TG
1
3
13
.@ShakReiner walks us through what exactly is Distributed Identity and how identity works on the #blockchain. #DID allows everyone to own & control their digital identity. It also exposes new attack surfaces and potentially vulnerable to old ones.
cyberark.com
Introduction Who are you? Thatโs a hard question to answer. Many philosophers have been fascinated with this question for years. Who are you in cyberspace? Your digital identity is comprised of...
0
3
11
This is a blog on how to write security-related blogs. Please take a look, and let's make the world easier to understand. https://t.co/hj6wYXzs5t
medium.com
Introduction
1
26
80