Interviews

  • C4DT Observer 16: Anticipating the Agentic Era: Assessing the Disruptions by AI Agents

Articles

Blog posts

I wrote multiple blog posts for the Kudelski Security research blog

  • How We Exploited Qodo: From a PR Comment to RCE and an AWS Admin Key - Leaked Twice
  • How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories, HN discussion
  • Getting RCE on browser-use/web-ui AI Agent Instances
  • Careful Where You Code: Multiple Vulnerabilities in AI-Powered PR-Agent
  • Introducing Fuzzomatic: Using AI to Automatically Fuzz Rust Projects from Scratch
  • Polynonce: A Tale of a Novel ECDSA Attack and Bitcoin Tears
  • Automatically Fix Security Issues at the Source
  • Oramfs: Resizable ORAM, Remote Storage Agnostic, Written in Rust
  • Advancing Rust Support in Semgrep
  • Benchmarking privacy-preserving motion detection
  • A Solution to the Dangerous Delegated Responder Certificate Problem
  • Replacing passwords with FIDO2 updated slides and resources
  • Differential privacy: a comparison of libraries
  • FIDO2 Deep Dive: Attestations, Trust model and Security
  • FIDO2: Solving the Password Problem