olivier_boschko Profile Banner
Boschko Profile
Boschko

@olivier_boschko

Followers
4K
Following
20K
Media
203
Statuses
2K

just a french canadien | ai red team @HiddenLayerSec | CISSP BSCP CRTL CRTO OSCP eWPTX eCPPT | goofing off @ https://t.co/aWC0YYEp9x

Oppinions are my own
Joined February 2017
Don't wanna be here? Send us removal request.
@olivier_boschko
Boschko
12 days
Chained 6 vulnerabilities to get RCE on @UnitreeRobotics days ago. They pushed V1.1.11 a day later "patching" (not really) the RCE. The @pwnoio boys are unstoppable, new RCE using the same primitive. Crazy blog dropping soon 🔥🔥🔥 @retr0reg
3
25
204
@olivier_boschko
Boschko
14 days
If you’ve got solid python skills, strong appsec background & you’re curious about applying your skills to AI/ML security, come join my team at HiddenLayer. Great pay, benefits, fully remote, working alongside amazing talent & awesome people
job-boards.greenhouse.io
Remote, US
3
14
107
@olivier_boschko
Boschko
18 days
It had to be done 💸
@retr0reg
Ruikai
18 days
fucking clanker
0
0
12
@olivier_boschko
Boschko
25 days
We've published the full transcript + additional technical details from our Offensive AI Con talk on Deductive Engine: Human-Inspired Taint Reasoning. If you missed it or want the under-the-hood details, check out the link below!
1
1
15
@retr0reg
Ruikai
1 month
I'll be presenting one of our most interesting work: Deductive Engine: Human-inspired Taint Reasoning, this Tuesday at @OffensiveAIcon. As a Teaser, Deductive Engine not only able to replicate the finding of UniPwn (CVE-2025-35027) - but surprisingly finding two stack-based
3
3
35
@olivier_boschko
Boschko
1 month
I'll be @OffensiveAIcon - come find me! Joining the incredibly talented researcher @retr0reg, founder of @pwnoio, on stage Tuesday discussing LLM-driven binary taint analysis using deductive reasoning & human heuristics
0
1
12
@olivier_boschko
Boschko
6 months
New blog just dropped 🤠 I've spent hours boiling down why adversarial examples fundamentally exist, distilled down to technical crystal-clear explanations anyone can grasp. This is what I wish someone had given me months ago. Give it a read ❤️ https://t.co/rVsC25b11v
Tweet card summary image
boschko.ca
Explore why adversarial examples fundamentally exist & why models are often wrong almost everywhere.
5
29
91
@olivier_boschko
Boschko
6 months
My old team is hiring! Its one of best internal Red Teams IYKYK. Lots of complex & challenging ops in an environment with $1B/yr cyber spend. Huge training budgets & all the toys/gadgets money can buy 😎 the team is seriously amazing. Check out the posting for more details
@ars3n11
Arsenii P
6 months
🇨🇦🚀 RBC Adversary Emulation is hiring! We're looking for a mid- to senior-level penetration tester / red team operator with a strong consulting background. 📍Toronto (preferred) or anywhere in Canada https://t.co/ioX9R4Qb1I
3
3
31
@olivier_boschko
Boschko
6 months
Great research 🔥 pretty insane level of risk to leave your users exposed to for months. Not implementing an immediate fix & waiting on protocol upgrade feels kinda shitty. The full article + triage timeline & conversation is worth the read.
@shabarkin
Pavel Shabarkin
7 months
On Feb 17 2025 I reported a critical vulnerability to @Scroll_ZKP. $100m+ in TVL was at risk for more than 2 months. Anyone could force Scroll L2 into an indefinite re-org, halting the chain so that no user transactions would be included in blocks and the chain would not move
0
1
10
@olivier_boschko
Boschko
7 months
Check out @hiddenlayersec newest transferable & universal prompt attack technique coined "Policy Puppetry". It's hot out of the oven & ready for you to use on your next red team 🔥 https://t.co/zXMjX1vOUW
Tweet card summary image
hiddenlayer.com
HiddenLayer’s latest research uncovers a universal prompt injection bypass impacting GPT-4, Claude, Gemini, and more, exposing major LLM security gaps.
0
6
28
@olivier_boschko
Boschko
8 months
Happy to announce that I've joined the world's best @HiddenLayerSec! 🔥 I'm absolutely pumped to be securing AI with this insanely stacked & talented team. Good times on the horizon 😎
12
0
66
@olivier_boschko
Boschko
9 months
So those vulnerabilities I found in that sex toy app 3 years ago... the ones where I could access 60,000+ accounts & all their super private data? They might FINALLY be fixing everything. Super weird experience. Heavily redacted blog post dropping soon if all goes well 👀
0
0
20
@olivier_boschko
Boschko
9 months
Finally finished reading 🤯 this is 100% a must read. I dont know of anyone else who's consistently finding insane vulns in AI/ML projects & posting writeups/sharing their thought process. Patrick doesn't miss 🎯
@retr0reg
Ruikai
9 months
My 10k-word writeup on exploiting a heap-overflow in Llama.cpp's RPC Server's Tensor-operation to RCE. This by far is one of the most challenging but fun exploitation I've ever researched on. https://t.co/aPLJyDF4Vq
1
1
34
@olivier_boschko
Boschko
9 months
Maybe its a mindset issue, but spending time reading AML ATK/DEF papers to midway realize its 99% useless in the real world feels... annoying? Especially when proven w/ unnecessary constraints + the fact that research clusters are so far detatched from "real" deployment clusters
3
0
9
@olivier_boschko
Boschko
10 months
👀👀👀🔥🔥🔥🔥
@h4kb4n
h4k
10 months
The entire Shambles product line has been updated with a new version of the SCA (Software Composition Analysis) feature and now includes SBOM export functionality. Accuracy and coverage have been further improved.
0
0
7
@olivier_boschko
Boschko
11 months
Happy holidays folks! Here's to happiness, love, success, and as always stylish shells 🐚 in the year ahead ❤️
0
0
29
@olivier_boschko
Boschko
11 months
It's a hard sell
0
1
7
@olivier_boschko
Boschko
1 year
Dopped a spicy 25-min read exploring adversarial ML 🤠 It's a mix of in-depth & light peppering of the broader field. So much I couldn’t fit (extraction, inversion, poisoning), but I hope it sparks curiosity. Made for learners no fancy background ❤️ https://t.co/QE1j0tu4Jl
Tweet card summary image
boschko.ca
Explore adversarial attacks on AI/ML models through hands-on challenges on Dreadnode’s Crucible CTF platform.
12
68
208