Sidestepping a capstone control-flow jailer by handing native-compile a filename instead of a lambda, so the byte compiler reads flag.txt as Lisp and names it in an undefined-variable warning
Steering a byte-CNN malware classifier to a benign verdict with an adversarial comment, then escaping a Java SecurityManager through the trusted MethodHandles lookup
Declaring an axiom to fabricate false proofs, turning Lean 4 proof-carrying array accessors into arbitrary memory reads, and forging a closure object to call readFile
When softplus weights make every added byte incriminating, rewriting a Java SecurityManager escape token by token until a byte-CNN calls it benign
Writeup for Chusembly from EHAX CTF 2026. A miscellanious challenge involving sandbox escape and arbitrary Python code execution via an unrestricted custom assembly interpreter.