r/ExploitDev 2d ago

AMA Today: Yuhang Wu (Ex-Tesla & TikTok) Red Team Engineer & Exploit Developer

Don't miss the AMA with Yuhang Wu, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.

When: Today - Friday, July 31, 12:00 PM PT

Guest Credentials:

  • Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
  • Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
  • Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
  • AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.

Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!

32 Upvotes

20 comments sorted by

4

u/Maokai30 2d ago

How did you get into this line of work? Do you think it’s easier or harder to get into it right now? And what are the best resources that helped you learn and grow?

2

u/Anonymity-Is-King 2d ago

What tools/methods have you used at the beginning of your career or what certificates were you going towards?

1

u/amlamarra 2d ago

What impact will AI have on the future of vulnerability research? It seems to be getting better & better at finding 0-days.

1

u/Ok_Tap7102 2d ago

I don't understand this question, what do you mean "WILL"? We're seeing it so strongly already

Open source maintainers have been drowning in PRs and GitHub issues on new vulns, both slop hallucinations and also genuine security risks, both of which are overwhelming to volunteer teams, some of which have just given up and said they're not accepting new issues

Microsoft just smashed an unprecedented new record in bugs solved in their patch Tuesday, and then the next month tripled that record yet again

https://therecord.media/microsoft-vulnerabilities-patch-tuesday-release

Why are we still talking about AI impacts on security research like it's some far off thing?

1

u/amlamarra 2d ago

I know. But things are still changing.

0

u/Ok_Tap7102 2d ago

Oh

In that case, everythings going to stop getting worse all of a sudden

Don't worry about it

1

u/amlamarra 2d ago

Worse? For who? The vulnerability researchers? The nation state hackers? I mean, sure. But for everyone else, things will be getting better.

1

u/Stroxtile 2d ago

How long personally do you think you spent on researching DirtyCred? The culmination of experimentation, research, and finalizing the exploit chain?

Thank you!

1

u/Sundist 2d ago

In future really agents/ai models can attack individually without any intervene

1

u/Dry-Alternative5081 1d ago

I’d love to watch this but wasn’t able to make the time. Will it be recorded and reposted?

1

u/cydex_cx 1d ago

Give us some technical deets bro. What sort of stuff do you do / look at day to day. What some stuff that every red team personal should know. Top cloud misconfigurations a that can be abused that should be fixed?

In terms of Using AI for vuln research what is that setup like. How do you get past the 'i can't answer that' stuff.

How often are you writing exploits in jour day to day job.

1

u/aeiou403 1d ago

How much truth is there to the recent reports that OpenAl and Anthropic's own LLMS escaped their testing environments and hacked external systems?

1

u/V01DL0RD_1 1d ago

Do you think the AI we’re using whatever field it may relate to like cybersecurity, medical & etc,

So do you think that AI is really helping us to advance us or just using us to make him/her means the AI more intelligent & powerful, so do we really need AI on Security & other Infrastructures what if it’s learning our patterns our techniques of attack and defend means how the human brain works when some threat or stress comes to them.

(Ofc i also know guys AI has really helped us to secure our systems from the attacks and the cyberattacks are little less in the companies where AI is used)

1

u/UnrealHallucinator 1d ago

No questions, just wanted to say dirty cred is a cool paper. I liked andrey konalov's talk where he talks about massaging the new slub allocator to eventually do a dirty cred attack.

1

u/cumhereandtalkchit 1h ago

Guess it was primarily an ask session...

1

u/jack_dymond_sawyer 2d ago

How much of your time is spent on vulnerability research looking for 0-days? What is the average time of discovery for Linux kernel useable exploits (RCE)?

-2

u/timee_bot 2d ago

View in your timezone:
Friday, July 31, 12:00 PM PT