1. X
  2. Brian Pak
Log inSign up
Brian Pak
616 posts
user avatar
Brian Pak
@brian_pak
ai + security + alpha CEO @theori_io / @xint_official → building the world's best AI hacker 9x DEF CON CTF winner CMU CS '11 | founded PPP & MMM
Seoul / SF
theori.io
Joined April 2010
204
Following
3,624
Followers
RepliesRepliesMediaMedia
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

  • user avatar
    Brian Pak
    @brian_pak
    May 1
    Hey everyone. We’ve seen the discussions around Copy Fail (CVE-2026-31431) and the disclosure process. We appreciate the passion from distro maintainers, defenders, and the broader Linux community. This is a serious issue, and we want to share some context on our side in good
    108K
  • user avatar
    Brian Pak
    @brian_pak
    Apr 30
    and yes, RHEL 14.3 doesn't exist 😅 We meant to say RHEL 10.1. Sorry for the confusion! And also yes, the static webpage copy.fail -- even the logo -- is vibe-coded. Too busy triaging shit ton of other bugs to build a legit website ground up.. and i think it's a
    Copy Fail — 732 Bytes to Root
    From copy.fail
    6.2K
  • user avatar
    Brian Pak
    @brian_pak
    Apr 29
    Time to talk about this one. CopyFail (CVE-2026-31431) — a 732-byte Python script that roots every Linux distro shipped since 2017. 🧵
    user avatar
    Brian Pak
    @brian_pak
    Mar 23
    a567d09b15f6e4440e70c9f2aa8edec8ed59f53301952df05c719aa3911687f9 👀
    745K
  • user avatar
    Brian Pak
    @brian_pak
    Apr 14
    90-day disclosure policy isn't gonna cut it. Be ready.
    1.4K
  • user avatar
    Brian Pak
    @brian_pak
    Apr 1
    Naturally, the first thing we did was run it through Xint Code. Unsurprisingly, the vibe-coded app has quite a few vulnerabilities surfaced within minutes, including vuln101-level bugs (e.g. `.includes()` instead of `.startsWith()`). I guess @AnthropicAI wasn't kidding when they
    user avatar
    Chaofan Shou
    @Fried_rice
    Mar 31
    Claude code source code has been leaked via a map file in their npm registry! Code: …a8527898604c1bbb12468b1581d95e.r2.dev/src.zip
    6.7K