The pattern keeps repeating - stolen credentials, direct package publish, no code review involved. Most supply chain security models assume the attack flows through a PR. The ones that hurt skip that path entirely. https://t.co/98A9ZNMlUL
It has been a busy time for security folks the past two weeks with the software supply chain attack investigations.
There has never been a better time to work with engineering, legal, and business stakeholders to prepare for the inevitable.
The XZ-Utils compromise in March 2024 led to a personal mind shift to monitor software packages as it was becoming something threat actors could use to bypass traditional controls
#securityresearch #llmsecurity #opensource
Completed the Pelican Linux VM lab in about an hour, my service enumeration process has improved but I do like to read what I’m hacking first which took about 20 mins 🤓
#applicationsecurity#linuxhacking#privesc#provinggrounds
Another one bites the dust #dvr4, this windows machine was tricky on the initial access and privilege escalation. Small details matter, got some new tips added to my documentation.
#webapp#pentesting#provinggrounds
Today was a good day! Co-presented to a large audience of 800+ virtual participants on guard rails for Agentic AI. Started off with a brief walkthrough of history on the first steam powered robot prototype from Ancient Greece then discussed Alan Turing in the 50s prior to arriving to the recent breakthroughs enabled by big data, compute, and examples of automation for complex tasks with agents.
Key takeaways on using coding agents:
🧠 Don't outsource your critical thinking
🤝 Partner with your security experts
🔍 Check that LLM’s are giving you the output you requested without hallucinations
Feel free to reach out to discuss these topics further.
#AgenticAI #DevSecOps #Archytas
@j2k3k@ProfessorMesser I watched his videos back in 2015 for Sec+ and 2 weeks ago sent a friend his YoutTube playlist so he could learn the fundamentals. Still gold.
I reverse engineered an executable and discovered it was a covert SSH beacon connecting to a remote Russian server. Static analysis using strings revealed an embedded C2 domain, while behavioral analysis showed the malware silently exfiltrating desktop screenshots and saved data.
We are saddened to inform friends that our dear brother, Voddie Baucham, Jr., has left the land of the dying and entered the land of the living. Earlier today, after suffering an emergency medical incident, he entered into his rest and the immediate presence of the Savior whom he loved, trusted, and served since he was converted as a college student. Please pray for Bridget, their children, and grandchildren.
Precious in the sight of the Lord is the death of his saints. – Psalm 116:15
https://t.co/Fxd8q6JjC9
I love going to libraries anytime I visit a new city. Yesterday I was reading the writings and works of Benjamin Franklin, George Washington, and Supreme Court Reports from the 1900s. ⚖️📖
#foundingfathers#history#seattle
Our hearts are heavy, yet rejoicing, as we share the news that our beloved pastor and teacher John MacArthur has entered into the presence of the Savior. This evening, his faith became sight. He faithfully endured until his race was run.
2 Timothy 4:1-8
John Macarthur's legacy is that of a faithful warrior who encourages us to stand firm for the truth. His ministry has blessed my family and millions of people across the globe since 1969 through his expository teaching of Christ and explaining the hard truths of the Bible. He's now with the Lord and I pray that his family and friends are able to find comfort. Truly grateful to have witnessed his preaching during our lifetime. 🙏🏼