Johann Rehberger
@wunderwuzzi23
Followers
8K
Following
3K
Media
522
Statuses
2K
Hacking neural networks so that we donβt get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg
127.0.0.1
Joined February 2012
how many Antigravity vulns can we chain together for a cool exploit demo π₯ 1. Invisible Unicode Tags hidden in a Linear ticket 2. Lack of human in the loop for MCP tool calls 3. Gemini 3 hijacked by the hidden instructions! 4. Bypassing guardrails for RCE 5. Developer pwnd! π
3
18
113
Will write up a blog post about it also soon to help raise awareness also.
0
0
3
Full Self-Driving Supervised improves US road safety by over 80%, saving lives & preventing injuries
0
50
471
πͺ If you have a next.js app rotate NEXTAUTH_SECRET regularly. It's all that is needed to mint valid auth cookies!
1
1
2
Cool, Apple fixed some security issues in the Terminal app that I reported. π π https://t.co/XAHxDKR9Pr
1
0
18
Why do researchers keep finding so many prompt injection issues? Perhaps it is because many AI system designers and defenders are misunderstanding the risks.π¨ Find out moreβ¬οΈ https://t.co/j7eAFszNcl
ncsc.gov.uk
There are crucial differences between prompt and SQL injection which β if not considered β can undermine mitigations.
5
32
107
So, for instance, if used in CI/CD, attacker could call web fetch read IMDS info and leak it, etc.. scary stuff.
1
0
5
Another Gemini CLI issue from earlier this year fixed. π An adversary, via prompt injection, was able to invoke any tool when in non-interactive mode (eg automated workflows, CI/CD,...)
2
0
10
Normalization of Deviance in AI That's how I call the gradual and systemic over-reliance in LLM outputs, especially with agentic systems. Treating probabilistic and possibly adversarial model outputs as if they were reliable, predictable, and safe. The model will not
embracethered.com
The gradual and systemic over-reliance on LLM outputs, especially with agentic systems, leads to a normalization of deviance.
1
2
7
Antigravity IDE update available just now. No security fixes or CVEs mentioned yet...
2
1
15
Will also include some of the demos in my 39c3 talk! https://t.co/ys8AdYqLsC
how many Antigravity vulns can we chain together for a cool exploit demo π₯ 1. Invisible Unicode Tags hidden in a Linear ticket 2. Lack of human in the loop for MCP tool calls 3. Gemini 3 hijacked by the hidden instructions! 4. Bypassing guardrails for RCE 5. Developer pwnd! π
1
0
3