15 years-old Threat Researcher on Memory-Security / General-Security-Research (I'm interested in everything). Founder of protosec, development of NLP/ML
with security-automation. CVEs and RCEs in Transformers
, Tensorflow
, LlamaFile
, Llama-cpp-python
, PrivateGPT
; Evernote
, Managebac
... (Experience at Linkedin Project Description) Blog at Retr0's Register. Aiming for MIT / googleprojectzero!
✨ Spotlight
Evernote RCE: From PDF.js font-injection to All-platform Electron exposed ipcRenderer with listened BrokerBridge Remote-Code Execution
->Supply-Chain Attacks in LLMs: From GGUF model format metadata RCE, to State-of-The-Art NLP Project RCEs
->ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE
->Electron Math: 8 Million User Note App Stored XSS -> RCE bypassing nodeintegration via preload.js in electron
->