kernelpool's profile picture.

Tarjei Mandt

@kernelpool

Tarjei Mandt reposted

LLM Poisoning [1/3]: Local LLMs are vulnerable to supply chain attacks. Inject a trigger-activated Trojan in a LLM. First step, build a probe to read a transformer's pre-down MLP activations to detect your chosen trojan trigger. 🔗 Full article synacktiv.com/publications/l…


Unfortunately can't make it to either of these, but do say hi to my esteemed colleagues! :D x.com/mncoppola/stat…

On my way to an @OffensiveAIcon - @hexacon_fr double header. I’ll be manning the Catalyst booth at Hexacon. Come say hi!



Security industry is doomed 😔

I think 100% security is possible (outside of the LLM world) In regular apps a security flaw is present if a developer makes a mistake, and once found the developer can patch it and avoid making the same mistake in the future There's still no patch for a prompt injection



Come join us at @hexacon_fr ! 🦊

Last sponsor to join us for this edition of Hexacon: meet @catalystsec! 🦊 Catalyst Security is a growing team of highly experienced vulnerability  researchers, focused on solving the most challenging technical problems. Come and meet us!

hexacon_fr's tweet image. Last sponsor to join us for this edition of Hexacon: meet @catalystsec! 🦊

Catalyst  Security is a growing team of highly experienced vulnerability  researchers, focused on solving the most challenging technical problems.

Come and meet us!


Tarjei Mandt reposted

Sweet mother of GAWD! 😱 It's here, it's really really here... 🥺

blacktop__'s tweet image. Sweet mother of GAWD! 😱 It's here, it's really really here... 🥺

Tarjei Mandt reposted

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…


Some quick benchmarks of LongCat-Flash-Chat on M3 Ultra 80 core (support just added to MLX 🚀): Promp tokens: 512, Gen tokens: 1024 - 6-bit: pps=238.827, gen=20.623, peak=459.204GB - 4-bit: pps=253.909, gen=26.876, peak=319.071GB - 3-bit: pps=251.613, gen=29.519, peak=248.971GB

Latest mlx-lm has a bunch of new models thanks to @ActuallyIsaak pip install -U mlx-lm - LongCat Flash by Meituan - Nemotron-H by Nvidia - Apertus by Swiss AI - Granite MoE by IBM

awnihannun's tweet image. Latest mlx-lm has a bunch of new models thanks to @ActuallyIsaak 

pip install -U mlx-lm

- LongCat Flash by Meituan
- Nemotron-H by Nvidia
- Apertus by Swiss AI
- Granite MoE by IBM


After lots of more testing using GLM Air I've also found that the bf16 version actually performs much better for tool calling over long context (e.g. beyond 64k). There are way more issues with quantized models, even at 8-bit. Anyone seeing similar results?


So far GLM 4.5 (Air) is my favorite local model for code auditing tasks. It's really good at instruction following and handling long context prompts. gpt-oss 120b is good too, but reasoning effort has to be set to Medium (e.g. @lmstudio sets it to Low by default).


Tarjei Mandt reposted

I wrote-up how I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation. Link to the blog post below 👇


Tarjei Mandt reposted

We’re ready for round 2 of @offensive_con ! Come say hi and grab a pen and stickers at our booth :)

kernelpool's tweet image. We’re ready for round 2 of @offensive_con ! Come say hi and grab a pen and stickers at our booth :)

Wheels down Berlin 🛬😅


Tarjei Mandt reposted

Great news! The Pwnie awards nominations are now open! pwnies.com/nominations/


Spoiler alert: I’ll be at @offensive_con next week. Looking forward to seeing everyone there! :)

We're excited to be at OffensiveCon this year, come up to our booth and say hi!



Tarjei Mandt reposted

We're excited to be at OffensiveCon this year, come up to our booth and say hi!


Tarjei Mandt reposted

`ipsw` has a 🆕 AI powered DECOMPILER 🤯 Check it out! 🎉 github.com/blacktop/ipsw/…

blacktop__'s tweet image. `ipsw` has a 🆕 AI powered DECOMPILER 🤯

Check it out! 🎉

github.com/blacktop/ipsw/…

Loading...

Something went wrong.


Something went wrong.