Took some time to improve a few things on WinDiff (added permalinks, filtered out empty results) and added a Claude skill to easily use WinDiff to produce quick security-oriented diff analyses between binary/OS versions. Feel free to try! github.com/ergrelet/win...
Erwan Grelet
@ergrelet.bsky.social
Fond of reverse engineering and software development. Doing security engineering at some company.
Agents need better tools for reversing! I'm releasing declib (previously libbs), with a new CLI today that gives agents CLI access to 4 decompilers (IDA, Ghidra, Binja, angr), parity feature support to most MCP (12 features), and the ability to sync those changes across decs!
libbs decompiler: cross-decompiler type sync (IDA -> Ghidra)
Recorded by mahaloz
asciinema.org
New #TinyTracer (4.0) is ready: github.com/hasherezade/... - refactored for compatibility with the latest PIN - and with some new features!
I'll be back at @reconmtl.bsky.social teaching a training with Keith Ramphal, we'll be bringing our combined malware reverse engineering experience to the masses! Whatever runs, wherever it runs, cause the days of your boring ol' Windows C bot are over. recon.cx/2026/en/trai...
Advanced Malware Reverse Engineering - REcon 2026 Training
4-day hands-on malware analysis training by Marion Marschalek and Keith Ramphal. Master Windows, Linux & macOS malware reverse engineering at REcon Montreal.
recon.cx
Offensivecon is coming to Tokyo! 🔗 www.offensivecon.jp Ticket shop, sponsorships and CFP are already open...
Seth Jenkins updated our 0-click exploit chain to work on a Pixel 10 with an eye-popping driver bug! We’ll be presenting this work Saturday @offensivecon.bsky.social projectzero.google/2026/05/pixe...
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible t...
projectzero.google
Deepfakes are everywhere, but digital forensics investigators are fighting back. Learn more: https://scim.ag/42dMPBg
@blackhoodie.bsky.social will be back at @reconmtl.bsky.social this year 😱😻✨ Jane Tangen and Amna K Moon will be teaching an Introduction to x86 Reverse Engineering! We're delighted to be hosted at the Montreal Google offices! blackhoodie.re/Recon2026/
Blackhoodie at Recon 2026
We are looking forward to hosting another Blackhoodie training at Recon for 2026! We will be hosting a free, one day training for women, by women.Join us for an introduction to Ghidra and static analy...
blackhoodie.re
Big changes to Android and Chrome VRP: - focus on high-impact, reproducible bugs with low/no reward for lower impact - big prizes for full chains with some annual limits - PoCs required It’s the end of an era, but the start of a new one. bughunters.google.com/blog/evolvin...
Blog: Evolving the Android & Chrome VRPs for the AI Era
We are announcing changes to the Chrome & Android Vulnerability Reward Programs (VRP) which take effect immediately and are focused on adjusting our reward amounts and bonuses to reflect the types of ...
bughunters.google.com
Join us at REcon 2026 for a deep dive into deobfuscation! @mrphrazer.bsky.social and I will share some insights on the evolving landscape. Stay tuned!
Talk w/ @nicolo.dev at @reconmtl.bsky.social : Deobfuscation in the Age of Agentic Reverse Engineering From control-flow cleanup to interprocedural analysis—and why human reasoning still matters. Details: cfp.recon.cx/recon-2026/t... Additional training on deobfuscation: recon.cx/2026/en/trai...
Major milestone forward for HyperDbg supporting #Linux. We've made a major progress on porting HyperDbg to Linux (still a long road ahead). Now the HyperDbg SDK can be compiled with GCC for both user/kernel modes on Linux. More updates coming soon...👀 github.com/HyperDbg/Hyp...
HyperDbg/hyperdbg/linux at dev · HyperDbg/HyperDbg
State-of-the-art native debugging tools. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.
github.com
We have started announcing Recon 2026 Presentations recon.cx/2026/en/spea... More talks to be announced soon once we have confirmations #REcon2026 #ReverseEngineering #InfoSec #cybersecurity
Trailmark: parse source code into a Claude queryable call graph Blog post: blog.trailofbits.com/2026/04/23/t... Repository: github.com/trailofbits/... #infosec #llm
Mozilla says Mythos helped identify 271 vulnerabilities in Firefox 150. I went through the commits, CVEs, and bug links to see what that number really means. My takeaway: relax folks. xark.es/b/mythos-fir...
A quick look at Mythos run on Firefox: too much hype?
A closer look at Mozilla's Firefox 150
xark.es
OffensiveCon'26 agenda is out www.offensivecon.org -> Original->
NEW: Apple fixed the bug that law enforcement, like the FBI, were taking advantage of to extract chat messages that had been deleted or disappeared automatically. Until now the iPhone stored deleted or disappered messages in a database, allowing authorities to access them with forensic tools.
Apple fixes bug that cops used to extract deleted chat messages from iPhones | TechCrunch
The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.
techcrunch.com
Binary Ninja 5.3 (Jotunheim) is released: binary.ninja/2026/04/13/b... Major updates: NDS32 support, AArch64 ILP32 ABI, new Universal MachO UI, way more containers, command palette upgrade, type library helpers, ghidra gzf export, updated IDB import, HW and conditional breakpoints, and much more!
Binary Ninja - Binary Ninja 5.3 (Jotunheim)
Binary Ninja is a modern reverse engineering platform with a scriptable and extensible decompiler.
binary.ninja
Binary Ninja 5.3 (Jotunheim) adds new architecture APIs for full function level lifting. We are already using them for upcoming TMS320C6x work, and plugin authors should be able to put them to good use too.
The fuzzer that found project-zero.issues.chromium.org/issues?q=com... (and a number of issues prior to that as well) is now open-source: crrev.com/c/7580844 It uses pkeys, trap-handling and single-stepping to intercept and mutate in-sandbox reads (see trap-fuzzer.h). Definitely had fun writing it!
Project Zero
project-zero.issues.chromium.org
2 years ago I did a PoC to run #rust 🦀 in the #pixel modem Today it shipped in millions of devices! They grow up to fast! 🥲 security.googleblog.com/2026/04/brin... #rust #security #smartphone #baseband
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been f...
security.googleblog.com
Tired of reversing the same libc for the 100th time? 👀 Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries. High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami. 🔗 blog.quarkslab.com/sighthouse-a...
SCOOP: Someone has found new samples of the iPhone spyware DarkSword and published them on GitHub, putting millions of iOS users at risk. A cybersecurity researcher told us that the leaked spyware is "way too easy to repurpose" and "we need to expect criminals and others to start deploying this."
Someone has publicly leaked an exploit kit that can hack millions of iPhones | TechCrunch
Leaked "DarkSword" exploits published to GitHub allow hackers and cybercriminals to target iPhone users running old versions of iOS with spyware, according to cybersecurity researchers.
techcrunch.com
The CEO of Krafton used ChatGPT to push out the head of the studio developing Subnautica 2 against the advice of his own legal team and failed miserably.
CEO Ignores Lawyers, Asks ChatGPT How to Void $250 Million Contract, Loses Terribly in Court
The CEO of Krafton used ChatGPT to push out the head of the studio developing Subnautica 2 against the advice of his own legal team and failed miserably.
404media.co
RE//verse 2026 talks are live on YouTube! Want to revisit a talk or catch the ones you missed? The full playlist is now available: youtube.com/playlist?lis...
The recording of my talk "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels" at @re-verse.io is now online! Recording: www.youtube.com/watch?v=ns5j... Slides: nicolo.dev/files/pdf/re... Binary Ninja plugin: github.com/seekbytes/pt...
GitHub - seekbytes/ptxNinja: Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs.
Binary Ninja plugin for reverse engineering PTX -- the virtual instruction set architecture of CUDA-based GPUs. - seekbytes/ptxNinja
github.com
RE//verse 2026 videos are online www.youtube.com -> Original->
The slides from my @re-verse.io talk, "Challenges in Decompilation and Reverse Engineering of CUDA-based Kernels", are now online! Slides: nicolo.dev/files/pdf/re... Plugin: github.com/seekbytes/pt...
Last day before prices go up for Deconstructing Rust Binaries at Ringzer0, March 23-26! If you've been thinking about this fully remote, 16-hour Rust reverse engineering training: now is the time to book! ringzer0.training/countermeasu... #infosec #ReverseEngineering #rustlang #MalwareAnalysis
Deconstructing Rust Binaries
Deconstructing Rust Binaries is the first comprehensive training course focused solely on reverse engineering Rust binaries. This course is for any reverse engineer who needs a rapid, practical…
ringzer0.training
In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...
projectzero.google
NEW: Def Con banned hackers Pablos Holmes and Vincenzo Iozzo, as well as former MIT Media Lab director Joichi Ito, from attending the conference based on their links to Jeffrey Epstein. Holmes and Iozzo exchanged emails with Epstein for several years.
Hacking conference Def Con bans three people linked to Epstein | TechCrunch
The Def Con hacking conference banned hackers Pablos Holman and Vincenzo Iozzo, as well as former MIT Media Lab director Joichi Ito, from attending the annual conference after their reported connectio...
techcrunch.com