1. X
  2. Zhenpeng (Leo) Lin
Log inSign up
Zhenpeng (Leo) Lin
depthfirst
166 posts
user avatar

Zhenpeng (Leo) Lin

depthfirst
@Markak_
AI x Security @depthfirstlabs, Ph.D., CTF player @Nu1L_team, now @StrawHat_CTF. #Pwn2Own winner. Author of #DirtyCred #Badiouring
zplin.me
Joined April 2017
403
Following
3,572
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    May 13
    NGINX rift: We autonomously discovered this 18 yr old heap overflow (CVE-2026-42945) in @nginx impacting version 0.6.27 to 1.30.0. If you use rewrite and set directive, you maybe impacted! Please update your NGINX or change the config to mitigate it. Read more at
    Image
    00:00
  • user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    Jul 30
    Stay tuned for the crazy vulns coming!
    user avatar
    Andrea Michi
    depthfirst
    @andreamichi
    Jul 30
    Today we're announcing dfs-large1, our newest cybersecurity model that achieves best-in-class performance on vulnerability detection tasks. Besides frontier AI labs, only a handful of companies have built specialized models that reach the state of the art in their domain. We're
    Image
  • user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    Jul 30
    Hi dfs-large1
    user avatar
    Andrea Michi
    depthfirst
    @andreamichi
    Jul 30
    Today we're announcing dfs-large1, our newest cybersecurity model that achieves best-in-class performance on vulnerability detection tasks. Besides frontier AI labs, only a handful of companies have built specialized models that reach the state of the art in their domain. We're
    Image
  • user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    Jul 27
    A follow up on how we found the GitLab RCE. Memory corruption issues in ruby ecosystem is an often overlook but critical attack surface. Some gems downloaded millions of time probably just enable RCE while the application layer looks completely safe. Never trust any
    user avatar
    Zheng Yu
    depthfirst
    @dataisland99
    Jul 27
    We discovered 105 vulnerabilities across 34 projects in Ruby, some of which had remained undetected for more than 15 years. Collectively, these projects have been downloaded more than 8.6 billion times. The GitLab Remote Code Execution announced by @depthfirstlabs last week
  • user avatar
    Zhenpeng (Leo) Lin
    depthfirst
    @Markak_
    Jul 25
    Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!). F5 released the security advisory a week ago on July 15th. Fun fact: this bug
    Image
    00:00
Advertisement
Advertisement