Profile for joern

Display name
joernchen :cute_dumpster_fire:
Username
@joern@threatactor.club
Role
admin

About joern

Bio

Your mom's favorite hacker!

My other account is @joernchen

Stats

Joined
Posts
686
Followed by
1129
Following
261

Recent public posts

exclude boosts

Ich muss sagen ich bin schon ein bisschen beeindruckt wie smooth eine Onlinezulassung für ein Kfz läuft, ABER wenn ein einfaches & in den Eingabedaten so eine Fehlermeldung auslöst triggert mich das ein bisschen zu sehr ;). :cute_dumpster_fire:

Ich hab dann aber mal nicht an dem Ast gesägt auf dem ich saß.

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @trailofbits@infosec.exchange
Trail of Bits , @trailofbits@infosec.exchange
(open profile)

Ruby's Marshal deserialization has been broken for over a decade, and patches don't solve the fundamental issue. Read our full analysis of 11 years of Ruby deserialization exploits and why fundamental change is needed: blog.trailofbits.com/2025/08/2

Today I have a more serious topic than usual, please consider reposting for reach:

My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical contact points have failed us unfortunately and he seems stuck in this condition.

We’re based in Berlin, Germany but really any contact with a specialist who would be willing to take on this case we’d be grateful for!

To reach use you can DM me or contact us via Email at unclear.condition@gmail.com

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @jiska@chaos.social
jiska 🦄:fairydust: , @jiska@chaos.social
(open profile)

Ever wanted to do practical security research on platforms like iOS and Android? Obsessed with digging through system internals, tearing apart proprietary firmware and hardware or breaking down wireless protocols? Maybe you've spent weekends battling in CTFs?

✨📱 🐞💥 🔬 🛰️

I'm growing my team at Hasso Plattner Institute and am looking for a PhD student or Postdoc. It's a full-time, paid position in a supportive academic environment with a focus on impactful, real-world systems security research.

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @simplenomad@rigor-mortis.nmrc.org
Simple Nomad , @simplenomad@rigor-mortis.nmrc.org
(open profile)

Ok for some reason when I mentioned non-human identities and tracking them, a number of people assumed aliens or something, or just AI agents. What I am looking for are some insights into authentication actions on computer systems - using tokens, APIs, stored secrets, and so on - where a human is not directly involved in the interaction. Yes, AI could be involved, think MCP especially. I know there are tools out there to manage this, just wondering. Think using Okta SSO etc but not human users at all. Thoughts? Opinions? To me this is the next step in zero trust, in that one should have the same principles in place between any and all systems be they human or automated in that are they who or what they claim to be and are they authorized to do go forward and do what they are trying to do. #infosec #security #zerotrust