Chris Thompson (@retbandit) 's Twitter Profile
Chris Thompson

@retbandit

Head of Red team @ IBM X-Force. Black Hat Review Board. Founder and co-organizer of Offensive AI Con. Co-Founder of RemoteThreat. inveni et usurpa

ID: 325116309

linkhttp://remotethreat.com calendar_today27-06-2011 19:22:57

1,1K Tweet

6,6K Followers

835 Following

Adam Chester 🏴‍☠️ (@_xpn_) 's Twitter Profile Photo

Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D youtu.be/C9J5okm6cA4

Chris Thompson (@retbandit) 's Twitter Profile Photo

There is a wild number of AI talks to review for Black Hat this year… the AI hype is real, but seeing a lot of really cool research the authors should be proud of!

bohops (@bohops) 's Twitter Profile Photo

A quick update to "The Ultimate WDAC Bypass List" - Added Bobby Cooke's excellent writeup and tradecraft for "Bypassing Windows Defender Application Control with Loki C2" (via Electron Apps) [ibm.com/think/x-force/…] github.com/bohops/Ultimat…

chompie (@chompie1337) 's Twitter Profile Photo

Me and the homies are dropping browser exploits on the red team engagement 😎. Find out how to bypass WDAC + execute native shellcode using this one weird trick -- exploiting the V8 engine of a vulnerable trusted application. ibm.com/think/x-force/…

Offensive AI Con (@offensiveaicon) 's Twitter Profile Photo

Offensive AI Con is excited to announce Joshua Saxe as our keynote speaker! Joshua leads AI security efforts at Meta and is an accomplished data scientist who recognizes that "the dam is about to break"—AI will fundamentally alter the security landscape.

Offensive AI Con is excited to announce <a href="/joshua_saxe/">Joshua Saxe</a> as our keynote speaker!

Joshua leads AI security efforts at <a href="/Meta/">Meta</a> and is an accomplished data scientist who recognizes that "the dam is about to break"—AI will fundamentally alter the security landscape.
Brett Hawkins (@h4wkst3r) 's Twitter Profile Photo

New research just dropped I'll be presenting at TROOPERS Conference next week - Attacking ML Training Infrastructure 💥 Model poisoning for code execution ⚠️ Abusing ML workflows ⚙️ MLOKit updates and new threat hunting rules ibm.com/think/x-force/…

dreadnode (@dreadnode) 's Twitter Profile Photo

Introducing AIRTBench, an AI red teaming benchmark for evaluating language models’ ability to autonomously discover and exploit AI/ML security vulnerabilities. Read the paper on arXiv: arxiv.org/abs/2506.14682 Open-source dataset and benchmark eval code repo:

Introducing AIRTBench, an AI red teaming benchmark for evaluating language models’ ability to autonomously discover and exploit AI/ML security vulnerabilities.

Read the paper on arXiv: arxiv.org/abs/2506.14682 

Open-source dataset and benchmark eval code repo:
Offensive X (@theoffensivex) 's Twitter Profile Photo

Returned from a coffee break, we join Ruben Boonen (b33f | 🇺🇦✊) to learn more about Type-2: Attacking AI-Enabled IDEs for Post-Exploitation. #OffensiveX2025 #AI #PostExploitation #CyberSecurity #RedTeam #OffensiveSecurity #VulnerabilityResearch

Returned from a coffee break, we join Ruben Boonen (<a href="/FuzzySec/">b33f | 🇺🇦✊</a>) to learn more about Type-2: Attacking AI-Enabled IDEs for Post-Exploitation.

#OffensiveX2025 #AI #PostExploitation #CyberSecurity #RedTeam #OffensiveSecurity #VulnerabilityResearch
b33f | 🇺🇦✊ (@fuzzysec) 's Twitter Profile Photo

You can find my slide deck for Offensive X on GitHub. I also included a minimalist extension that you can build on and will load in any of the VSCode forks on any platform 👨‍💻⚔️

You can find my slide deck for <a href="/TheOffensiveX/">Offensive X</a> on GitHub. I also included a minimalist extension that you can build on and will load in any of the VSCode forks on any platform 👨‍💻⚔️
b33f | 🇺🇦✊ (@fuzzysec) 's Twitter Profile Photo

I wrote a blogpost about Android on-device fuzzing -> Reproducing a million-dollar bug: WhatsApp CVE-2019-11932 (with AFL & Frida) ibm.com/think/x-force/…

I wrote a blogpost about Android on-device fuzzing -&gt; Reproducing a million-dollar bug: WhatsApp CVE-2019-11932 (with AFL &amp; Frida)

ibm.com/think/x-force/…
Dave Cossa (@g0ldengunsec) 's Twitter Profile Photo

Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can it be identified in an enterprise and misconfigurations that could allow it to be used for out-of-band execution and persistence. ibm.com/think/x-force/…

DistrictCon (@districtcon) 's Twitter Profile Photo

We’re proud to announce the Review Board for DistrictCon’s call for papers! Our CFP will open next month, and we're excited to receive all your submissions! districtcon.org/cfp Perri Adams Rodrigo Branco sergey bratus chompie Winnona 💾 Ryan Speers mdowd Jay Lagorio 🅅

We’re proud to announce the Review Board for DistrictCon’s call for papers! Our CFP will open next month, and we're excited to receive all your submissions! districtcon.org/cfp

<a href="/perribus/">Perri Adams</a> <a href="/bsdaemon/">Rodrigo Branco</a> <a href="/sergeybratus/">sergey bratus</a> <a href="/chompie1337/">chompie</a> <a href="/__winn/">Winnona 💾</a> <a href="/rmspeers/">Ryan Speers</a> <a href="/mdowd/">mdowd</a> <a href="/jaylagorio/">Jay Lagorio 🅅</a>
Chris Thompson (@retbandit) 's Twitter Profile Photo

Come join us and learn how to attack AI platforms, model registries, training infrastructure, and backdoor models (and how to defend against these new attacks). It’s been a really hot topic with various military commands I’ve met with recently!

Offensive AI Con (@offensiveaicon) 's Twitter Profile Photo

How are you leveraging AI to advance offensive security? We want to hear about it at OAIC in October. CFP open now... only ONE MORE WEEK left to submit your talk(s)! sessionize.com/offensive-ai-c…

Ryan Fedasiuk (@ryanfedasiuk) 's Twitter Profile Photo

Wow. Spotted on a walk and I can’t believe it: The office of the world’s first open-source intelligence agency — the Foreign Broadcast Information Service (FBIS) — is available for lease. This is the story of an unassuming town house that ushered 🇺🇸 into the Information Age. 🧵

Wow. Spotted on a walk and I can’t believe it:

The office of the world’s first open-source intelligence agency — the Foreign Broadcast Information Service (FBIS) — is available for lease.

This is the story of an unassuming town house that ushered 🇺🇸 into the Information Age. 🧵
Chris Thompson (@retbandit) 's Twitter Profile Photo

I recently interviewed with Politico on the risks and benefits of the offensive use of AI. “This isn’t just malicious threat actors using it,” ... “There’s also the security research community that is leveraging this work to do their jobs better and faster as well. So it’s kind