adam
banner
appsec.bsky.social
adam
@appsec.bsky.social
security at pixee | ex-aws
founder: kernelcon.org | dc402.org
twitter: @clevernyyyy
linkedin: /in/adamschaal/
Less than a week to make major strides with Navier–Stokes. 🤯

We've spent decades asking what computers can't efficiently compute. What happens when the computers start answering that question?
IANAM (I am not a mathematician) but... if @OpenAI or @anthropic.com target P=NP next, things could get really interesting.

A proof that P=NP would have enormous implications for cryptography - breaking computational assumptions that even quantum-resistant crypto is designed around.
September 9, 2026 at 5:52 AM
IANAM (I am not a mathematician) but... if @OpenAI or @anthropic.com target P=NP next, things could get really interesting.

A proof that P=NP would have enormous implications for cryptography - breaking computational assumptions that even quantum-resistant crypto is designed around.
September 9, 2026 at 5:51 AM
I'm speaking at @blueteamcon.com 2026 in Chicago.

"Too Big To Review" - what happens to AppSec when AI turns your engineering team into a 10x output machine and your review capacity stays the same.

Spoiler: hiring more security engineers isn't the answer.
blueteamcon.com
September 8, 2026 at 7:21 PM
"Since August 28th, we have been training a new internal model that has exhibited unprecedented performance in our benchmarks, including mathematics."

🤯 It took TEN DAYS to solve a millennium problem.

This is AGI in the making, wow.

openai.com/index/navier...
On the Navier–Stokes Millennium Prize Problem
We’re sharing an AI-generated solution to the Navier–Stokes Millennium Prize Problem, including a writeup and a formal proof in Lean.
openai.com
September 8, 2026 at 6:37 PM
Check out the open letter from OpenAI plus 100+ firms warning that AI models will soon enable far more sophisticated cyberattacks.

A short "defenders' window" exists to fix vulnerabilities and arm defenders with AI tools before that happens.

openai.com/collective-c...
August 27, 2026 at 9:05 PM
I vibed a fun higher/lower on CVE severities, check it out!
I scored 2910 on Patch or Panic and ranked 13 CVEs correctly, the vulnerability severity game by @pixee.ai.

Can you beat me? cve.wiki/s/98cab768ee...
cve.wiki
I scored 2910 on Patch or Panic
13 CVEs ranked correctly. Can you beat 2910 points?
cve.wiki
August 25, 2026 at 5:17 PM
I scored 2910 on Patch or Panic and ranked 13 CVEs correctly, the vulnerability severity game by @pixee.ai.

Can you beat me? cve.wiki/s/98cab768ee...
cve.wiki
I scored 2910 on Patch or Panic
13 CVEs ranked correctly. Can you beat 2910 points?
cve.wiki
August 25, 2026 at 4:27 PM
My absolute favorite Christopher Walken role of all time.
youtube.com/watch?v=7qJu...

Poolhall Junkies. Underrated movie. I haven't seen it in a while, but randomly thought of this scene today. Go give it a watch if you haven't seen it.
Poolhall Junkies - Christopher Walken - King of the Jungle speech
YouTube video by moncorp1 Inc
youtube.com
August 21, 2026 at 4:08 AM
🚂 Speaking at Hobocon this July, a hacker conference on a moving train.

"All Aboard IDOR Express" - how when submitting a CFP, I found an IDOR showing me all of the security conference's submissions.

OWASP A01. 🚂 July 17–18, KC ↔ Chicago.
www.hobocon.com

Nothing like a captive audience.
June 25, 2026 at 2:51 PM
My talk "Too Big to Review" was just accepted at @blueteamcon.com 2026 🎉

September 12th in Chicago - come hear how we scaled AppSec at AWS without scaling the team.

#AppSec #BlueTeamCon
June 16, 2026 at 8:18 PM
New blog post - Automation for AppSec
blog.adamschaal.com/posts/2026-0...
Automation for AppSec at AWS (Part 1)
How automation and generative AI are transforming application security at AWS, from deterministic checks to context-aware reviews.
blog.adamschaal.com
January 25, 2026 at 4:22 AM
The night of October 20th, I woke up ice-cold. My bed had cooled all the way to 55° F and I couldn't adjust it at all. The irony: this was due to an AWS failure. Read more about removing my bed's cloud dependency.

blog.adamschaal.com/posts/2025-1...
Rooting My Eight Sleep Pod 3
A technical deep-dive into rooting and customizing my Eight Sleep smart mattress.
blog.adamschaal.com
December 24, 2025 at 4:37 AM
I dockerized a proof-of-concept for CVE-2025-55182 (React2Shell) here - github.com/clevernyyyy/...

Original POC by github.com/msanft.
GitHub - clevernyyyy/CVE-2025-55182-Dockerized
Contribute to clevernyyyy/CVE-2025-55182-Dockerized development by creating an account on GitHub.
github.com
December 5, 2025 at 1:32 AM
Super excited for the World Cup draw on Friday. ⚽️ 🥅
Can't wait to see what matchups we can attend!
December 1, 2025 at 2:36 AM
Writing is something I'm always challenging myself to be better at. This fall, my friend @themattvirus.bsky.social and I were pleased to attend BruCON, a security conference in Belgium and I've finally managed to put together my BruCON review:

blog.adamschaal.com/posts/2025-1...
BruCON 2025 – Beer, Waffles, and a Product Review Cabal
Notes from BruCON in Belgium, our talk with Matt Virus, beer-and-waffles lore, and a solo CTF run to 22nd place.
blog.adamschaal.com
November 25, 2025 at 7:41 PM
I always appreciate the little details in the DEF CON 402 ornaments from @tvidas.bsky.social like this one from 2020. Hard to believe how long our community has been together, really thankful for the friends I've made in dc402.org. ⚡ talks in December!
November 15, 2025 at 11:45 PM
Yes, @themattvirus.bsky.social and I visited the Louvre on our trip to BruCON. Yes, we cased the jewels, and noted that their cameras were obsolete [1] for our talk, but no, we did not steal them.

[1] www.artnews.com/art-news/new...
October 23, 2025 at 1:36 AM
Speaking at BruCON in t-minus 12 hours with @themattvirus.bsky.social. We've prepared as much as we can with waffles, beer, and club mate, we are almost fully Belgian now. 🇧🇪
September 25, 2025 at 7:23 PM
Bluesky vs Twitter on my pixel fold.
July 26, 2025 at 4:50 AM
At AWS, our GenAI development is moving at 🚀 warp speed. With new tools popping up faster than browser tabs in my macbook, my team created Nebula – a system to track all our GenAI initiatives.

Today, we just launched an AI assistant to help upload new tools to Nebula tracker.
June 21, 2025 at 3:17 PM
Thrilled to share that @themattvirus.bsky.social and I are speaking at BruCON this year! The lineup is 🔥 so far and we can't wait to reconnect with our amazing European hacking friends. Always a highlight to be among that fantastic community.

www.brucon.org
BruCON | Security and hacker conference and training
BruCON is an annual security and hacker conference In Belgium with two days of an interesting atmosphere for open discussions of critical infosec issues, privacy, information technology and its cultur...
www.brucon.org
June 4, 2025 at 2:15 PM
🎯NIST's updated security guidelines finally hit the mark.

1. No more forced password changes
2. Longer passwords beat complexity rules
3. Security responsibility shifts to providers where it belongs.

Common sense security FTW.

pages.nist.gov/800-63-4/sp8...
NIST Special Publication 800-63B
NIST Special Publication 800-63B
pages.nist.gov
June 2, 2025 at 2:37 AM
1/n - Today at kernelcon.bsky.social, we were notified that our registration was down. We immediately jumped on our phones to check and sure enough, clicking our registration buttons led to a 503.

However, our eventzilla admin page was up, and we could access our event through that site, hmm?
Kernelcon (@kernelcon.bsky.social)
OMAHA’S HACKER CON https://infosec.exchange/@kernelcon 🏆Training: 4.1-2 🚦Con: 4.3-4 🔀 New venue: Hilton downtown Omaha 🏎️ CFP IS closed! 📝 http://reg.kernelcon.org
kernelcon.bsky.social
March 14, 2025 at 4:09 AM
For 311 day, don't forget to kick it Omaha Stylee and get your tickets to @kernelcon.bsky.social!

youtu.be/rokq0CIfXXk?...

kernelcon.org
Omaha Stylee
YouTube video by 311 - Topic
youtu.be
March 11, 2025 at 12:52 PM