tweetindex
IT

Johann Rehberger ✓

@wunderwuzzi23 · 127.0.0.1 · joined 20 Feb 2012

Hacking neural networks so that we don’t get stuck in the matrix. Builder and Breaker. Opinions are my own. https://t.co/ij8buvMaXg

10 513Followers
667Following
2 244Posts total
177.7KViews on collected posts

Ultimi post

someone is reading my blog?! 🤖 i wonder where the agents learned about https://t.co/6sWjyXDNcc and that openai allow-listed it? 😂 1.8K views · 16 likes · 3 reposts · 3 replies Open on X →
From SELECT to SYSADMIN 🔥 Something fun and new. I hacked the SQL Server AI database assistant in unexpected ways, using some old school T-SQL tricks along the way. See you at BlueHat Asia! 🚀 2.5K views · 34 likes · 2 reposts · 7 replies Open on X →
We're excited to announce our next BlueHat Asia speaker, Johann Rehberger (@wunderwuzzi23), independent security researcher. Johann has more than 18 years of experience in threat analysis, threat modeling, penetration testing, red teaming, and offensive security leadership. http 3.2K views · 16 likes · 0 reposts · 0 replies Open on X →
https://t.co/pIgskkAd7k 1.8K views · 10 likes · 0 reposts · 1 replies Open on X →
no but seriously stop letting agents use python. 1.9K views · 1 likes · 0 reposts · 1 replies Open on X →
oh cool. latest claude research made it on hackernews. 🚀 good reminder that security invariants are not optional. https://t.co/u0gcbPiyUZ 3.3K views · 34 likes · 1 reposts · 3 replies Open on X →
@wunderwuzzi23 The agent refusing the unknown binary, writing its own “safe” decoder, then getting owned through module shadowing is almost too perfect. The safety detour literally became the exploit path. 848 views · 2 likes · 0 reposts · 0 replies Open on X →
Breaking Claude Code Opus 5 Auto Mode 🔥 Full write-up with more details: https://t.co/KnLr9bZ75C 12.1K views · 87 likes · 14 reposts · 5 replies Open on X →
7/ Put your agents in sandbox and monitor them ℹ️ 5.1K views · 33 likes · 2 reposts · 3 replies Open on X →
6/ In some runs Claude noticed the compromise and tried to kill the malware later on. But Auto Mode blocked the cleanup command! 🤯 It allowed the malware to run, but denied stopping it. Another example where a safety feature can end up working against you. https://t.co/sF8Khs 7.2K views · 63 likes · 3 reposts · 2 replies Open on X →
5/ Boom 💥 The struct. py runs heavily obfuscated code (thanks GPT-5.6) avoiding Claude's "grep for scary strings" mitigation. It spawns a detached child, pulls a remote stage, drops a native payload, calls back to c2. Pops calculator too, for the classic visible proof. 😈 https 5.6K views · 44 likes · 0 reposts · 1 replies Open on X →
4/ That safety decision IS the exploit! 🔥 Claude writes code with "import base64" and runs it from the extracted folder The twist --> Module Shadowing Attack: 🤯 The zip contains a struct. py, and hence attacker's code runs instead (base64 uses struct) Quick explanation ht 8K views · 41 likes · 2 reposts · 2 replies Open on X →
3/ Curl works and the zip file with the encoded records gets extracted and it includes a binary to decode them. Claude doesn't want to run the unknown binary! 🚨 BUT it decides it can write a safe decoder in Python instead... 🧐 https://t.co/dn0jm0LGnl 6.8K views · 24 likes · 0 reposts · 1 replies Open on X →
2/ The web site hosts a zip file with "notebook records" in a weird encoding. Plausible & harmless-looking... Claude uses WebFetch. But we don't want that, it typically summarizes & stops So, server returns 415 Unsupported Media Type Claude decides "Let me try curl directly" 7.7K views · 26 likes · 0 reposts · 2 replies Open on X →
Breaking Claude Code Opus 5 Auto Mode 🔥 1/ Here is a somewhat hilarious attack chain that hijacks Claude Code Opus 5 for a full system compromise via a website Hint: Security invariants are not optional 🧵 91.8K views · 405 likes · 54 reposts · 22 replies Open on X →
@wunderwuzzi23 Interesting thing you might wanna know: Your domain is blocked by bitdefender https://t.co/uGqbtt0Pv6 82 views · 1 likes · 0 reposts · 1 replies Open on X →
@wunderwuzzi23 For agent stacks, "exploit yourself" probably has to start from tool permissions, not prompts. The useful test is: after the first bad instruction gets through, what can it touch, and who notices before damage? 80 views · 1 likes · 0 reposts · 1 replies Open on X →
@wunderwuzzi23 I try to convince people of this all the time. there's no better way to cut through the "theoretical risks" by just hacking yourself. It gives you something specific to mitigate instead of guessing. 221 views · 2 likes · 0 reposts · 0 replies Open on X →
Sometimes it seems security is drifting back towards a "Prevent Breach" mindset. Prevent breach was never enough. Patch faster, of course. But offensive AI is about a lot more than finding bugs! Invest in Assume Breach! Grow an internal Red Team. Automate offensive AI. Learn 17.4K views · 46 likes · 3 reposts · 8 replies Open on X →

Rispetto ad account della stessa dimensione

15 post degli ultimi 90 giorni, accanto alla fascia di 10K–100K follower. arriva a molti, ma pochi di loro reagiscono.

Visualizzazioni mediane5 103questo account924mediana per 10K–100K
Copertura, %48.54%questo account3.62%mediana per 10K–100K
Interazione, %0.60%questo account1.52%mediana per 10K–100K
MetricaQuesto accountMediana per 10K–100KRapporto
Visualizzazioni mediane per post5 1039245.52×
Copertura (visualizzazioni ÷ follower)48.54%3.62%13.4×
Tasso di interazione0.60%1.52%0.39×

Altri account di questa fascia →   Confronta con un altro account →   Come sono costruiti questi parametri →

Growth & engagement

How the posts we collected actually performed: views and reaction rate post by post, what the audience did with them, and where the follower count goes.

Views per post

7.7K27 Aug
6.8K
8K
5.6K
7.2K
5.1K
12.1K
848
3.3K31 Aug
1.9K
1.8K
3.2K2 Sep
2.5K
1.8K4 Sep

Last 14 collected posts, oldest on the left. The scale is logarithmic: one post can outrun the rest a hundred times over.

Engagement rate per post

0.36%27 Aug
0.37%
0.59%
0.80%
0.94%
0.74%
0.92%
0.24%
1.14%31 Aug
0.16%
0.60%
0.53%2 Sep
1.76%
1.20%4 Sep

Reactions — likes, reposts, replies and quotes — divided by views. Median for 10K–100K accounts is 1.52%.

What the audience does

Likes59.3%886 in total
Reposts5.6%84 in total
Replies4.2%63 in total
Quotes1.9%28 in total
Bookmarks28.9%432 in total

Share of every reaction we collected for this account. Replies mean argument, reposts mean endorsement, bookmarks mean the post was worth keeping.

The follower curve appears once this account has two daily snapshots — we take one a day, and this one is on its first.

Account simili