Caleb Gross
@noperator
Followers
2K
Following
4K
Media
219
Statuses
1K
ai for security
Joined October 2009
A new tool: Slice 🔪 With the help of build-free CodeQL and Tree-Sitter, Slice can help GPT-5 can reliably reproduce discovery of CVE-2025-37778: use-after-free vulnerability in the Linux kernel! https://t.co/J2na8iX4hv
4
52
169
It's interesting to note the listing of critical Taiwanese edge devices. Reports confirm nation-state actors are attacking these devices.
4
31
131
burp suite just joined the rank-maxxing train https://t.co/xvTVkAOeks
video + transcript for my recent talk at inaugural @OffensiveAIcon: https://t.co/O0fsqNGL2K kudos @sweepthatleg for recording 🤙
2
0
5
The @offby1security stream with @noperator is now available on YouTube below. It's definitely worth the view and provides actionable techniques for those interested in n-day and 0-day vulnerability research! https://t.co/g7M3hoBwDZ
0
22
88
in some initial testing, Slice can successfully use gpt-oss-120b (via openrouter) to find the same UAF, while 3X faster (2.5 min) and 56X cheaper ($0.06) than using GPT-5 :)
A new tool: Slice 🔪 With the help of build-free CodeQL and Tree-Sitter, Slice can help GPT-5 can reliably reproduce discovery of CVE-2025-37778: use-after-free vulnerability in the Linux kernel! https://t.co/J2na8iX4hv
0
3
50
“One day the toys will all be put away, the house still and quiet.” These words—from a video my friend @isaacfrench_ made for his wife—hit me hard this morning. 📢Parents of young kids, take it from me—a recent empty nester: The Good Old Days don’t feel like it at the time.
163
337
5K
starting in 45 min :)
Join me for the next @offby1security stream on Tue, November 4th @ 9:30AM PT with Caleb Gross (@noperator) on "Scaling LLM-Based Vulnerability Research via Static Analysis & Document Ranking!" A cool new way to diff binaries to find vulnerabilities! https://t.co/0UfXouoNRr
0
2
13
gonna be fun 🙂
Join me for the next @offby1security stream on Tue, November 4th @ 9:30AM PT with Caleb Gross (@noperator) on "Scaling LLM-Based Vulnerability Research via Static Analysis & Document Ranking!" A cool new way to diff binaries to find vulnerabilities! https://t.co/0UfXouoNRr
1
0
12
thanks for the s/o @exploitsclub @_stigward 🤙
ICYMI Halloween https://t.co/t7k0vTEBaV dropped yesterday ! Patch gapping browsers w/ @seal9055 and @InterruptLabs
@ky1ebot's winning Ubuntu UAF @noperator talks LLMs for VR and @addisoncrump_vr talks fuzzing research stagnation + Jobs and MORE 👇 https://t.co/boA3WDFiWS
0
1
5
here's how I'm approaching a solution to the "growing backlog of bugs" problem: https://t.co/73NpVC1QSH. i.e., don't try to score them—just rank them directly against one another.
This. Alert & CVE fatigue are real. Perpetually growing backlogs of bugs means no one gives a shit anymore. We need clear writeups that consider exploitability, and include a patch. If you can automate finding bugs, you can automate submitting fixes.
0
1
10
A must read if you do security stuff with LLMs! Kind of an eye opener to me
video + transcript for my recent talk at inaugural @OffensiveAIcon: https://t.co/O0fsqNGL2K kudos @sweepthatleg for recording 🤙
0
1
3
I need to hear the story behind the "excessive amount of dog poop that affected the well-being of the robots"
0
0
0
Great post by @noperator: built a sast tool that uses codeql (which can now scan c++ without compiling) and tree sitter, and triage with an LLM to find vulns with a low false positive rate
noperator.dev
Earlier this summer, Sean Heelan published a great blog post detailing his use of o3 to find a use-after-free vulnerability in the Linux kernel. The internet lit up in response, and for good…
3
6
48
Utterly brilliant talk by Caleb. Love the framing of us all having a which problem.
video + transcript for my recent talk at inaugural @OffensiveAIcon: https://t.co/O0fsqNGL2K kudos @sweepthatleg for recording 🤙
0
1
3
updated with v important footnote 👀🚗🐟
video + transcript for my recent talk at inaugural @OffensiveAIcon: https://t.co/O0fsqNGL2K kudos @sweepthatleg for recording 🤙
0
0
3
AWS (Antifa Web Services) doing the #NoPings protest today
3
20
120