Piotr Bazydło

@chudypb.bsky.social

Principal Vulnerability Researcher at the watchTowr | Previously: @thezdi | https://chudypb.github.io

Research is fun. One month ago, I thought that I'll never again make a research as good as my .NET deserialization one. Here I am today, writing a new whitepaper. You never know the day 😅

Some serious question about a larg-scale usage of AI in Vuln Research. Aren't you afraid of missing some key datails by outsourcing huge tasks to AI? I am. If you rely on a tool, you're as good as your tool. If AI screws in a huge project, you probably won't even notice that.

Great news: I got invited to Microsoft Zero Day Quest onsite event. Bad news: It overlaps with my kid's estimated due date 😅 Happy hacking to all of you who's planning to go to Redmond 😎

Bild

I'm happy to be on the nominations list second year in the row! This time, it's with "Half Measures and Full Compromise: Exploiting Microsoft Exchange PowerShell Remoting" research and some nice RCE chains on Exchange:) chudypb.github.io/exchange-powershell.html

chudypb.github.io

James Kettle@jameskettle.com · 2y ago

Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...

After amazing (almost) 3 years, this is my last day at @thezdi.bsky.social. Huge thanks to the entire team, it was an honour to work with you folks! New challenges and adventures are starting in 2025 :) PS. Watch out for the ZDI blog, as several of my posts should appear there in 2025.