Dave Aitel
@daveaitel
Followers
28K
Following
14K
Media
3K
Statuses
93K
Cyber Security Researcher | Policy Analyst | Technical Team Member at OpenAI | @[email protected]
Joined August 2007
woot nice vuln find from @joernchen .. Anyone using LangGraph better upgrade. RCE via json deserialization in graph.invoke() which is the main api https://t.co/KrKrOsZv1z
github.com
# Summary Prior to `langgraph-checkpoint` version `3.0` , LangGraph’s `JsonPlusSerializer` (used as the default serialization protocol for all checkpointing) contains a remote code execution (RC...
0
25
86
#Django: Critical SQL Injection Vulnerability in Django (CVE-2025-64459): https://t.co/aYK8gTJVXY
endorlabs.com
Critical SQL Injection Vulnerability in Django (CVE-2025-64459). Learn what happened, root cause, impact, and how to mitigate.
1
73
311
@ryanaraine always bring the 💨 This is one of the best security podcasts period! Make sure you all subscribe! @daveaitel discuss @OpenAI’s #aardvark
The podcast is going live this morning, with Dave Aitel going deeper on OpenAI Aardvark Tap in: https://t.co/sGPF4b71Dh
2
4
9
Automated vulnerability scanning at scale. It's amazing the depth of security issues GPT-5 can find.
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
4
14
191
Aside from how obviously great this release is, the name Aardvark itself feels very @daveaitel inspired and now I want to know the backstory.
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
1
1
25
the experience of using openai aardvark has been at times viscerally strange. the bugs it produces are sometimes those a human would find, and sometimes they leverage a meticulousness and deep and broad understanding that feels totally alien. it’s a new day.
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
5
2
19
This looks *fascinating* and it could be utterly industry-changing:
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
2
7
84
Aardvark is changing how we discover and fix vulnerabilities at scale. It's truly a glimpse into the future of cybersecurity. Congrats on the launch @embeddedsec!!
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
3
14
161
Proud to introduce Aardvark, our agentic security researcher powered by GPT-5. Aardvark hunts for vulnerabilities the way a security engineer would: by reading and analyzing code, writing and running tests, and proposing patches. Now in private beta.
openai.com
Now in private beta: an AI agent that thinks like a security researcher and scales to meet the demands of modern software.
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
8
20
82
Introducing Aardvark, our agentic security researcher:
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
98
160
2K
Aardvark is a labor of love and mission for the whole team. We are super excited to bring it to you. Sign up for the beta immediately!!!
Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. https://t.co/xwtJhfDM3X
9
34
269
Excited to share two new #fuzzing technical reports from my group! 🔹 InsightQL: Advancing Human-Assisted Fuzzing with a Unified Code Database and Parameterized Query Interface 🔹 DynamiQ: Unlocking the Potential of Dynamic Task Allocation in Parallel Fuzzing (tool released!) 1/n
1
5
18
Really remarkable UNGA moment in New York: Syria’s President Ahmed al-Sharaa — once a rebel leader with a $10M U.S. bounty on his head — is now being interviewed by ex-CIA Director and US Army general in Iraq David Petraeus at the Concordia Summit. -Petraeus: We were on
87
241
733
congrats to @FakePsyho for claiming the top spot on the @atcoder World Finals programming competition (followed by OpenAI at #2)!
Humanity has prevailed (for now!) I'm completely exhausted. I figured, I had 10h of sleep in the last 3 days and I'm barely alive. I'll post more about the contest when I get some rest. (To be clear, those are provisional results, but my lead should be big enough)
37
104
1K
Disruptive cyberattack against Russian drone manufacturer claimed by Ukrainian hacktivists
scworld.com
TechCrunch reports that Russian drone manufacturer Gaskar Group had its operations severely disrupted following an attack against its network and server infrastructure claimed by Ukrainian hacktivist...
0
2
3
Firmware Binary Analysis in Azure is in public preview!! New blog on its capabilities and how to get access. Drag and drop your firmware to browser and find issues https://t.co/ikmpGQnaQm
3
51
147
We’re sharing more about how we report vulnerabilities we discover in third-party software—through research or automated means. Our new disclosure policy is designed for cooperation, transparency, and ecosystem-wide security.
openai.com
OpenAI introduces its Outbound Coordinated Disclosure Policy to guide how it responsibly reports vulnerabilities in third-party software—emphasizing integrity, collaboration, and proactive security...
24
52
666