Finally! after months of analysis I can talk about our Cyber team's recent work and Project Glasswing! After observing frontier models perform vulnerability research.
https://t.co/mJbgjcKats
#CyberSecurity#ArtificialIntelligence#AppSec
Can you believe we've reached a point in tech where a package named "is-even" has millions of downloads?
hey guys, there is this thing called the modulus operator, and it works JUST FINE
Known as CVE-2023-4863 and CVE-2023-41064, an issue in WebP's BuildHuffmanTable function was found, leading to a heap buffer overflow.
This vulnerability is fascinating and I'm excited to share with you what I learned!
https://t.co/uygdynyqLq
Not to name names but I find pattern-based vulnerability detection to be a bit lazy. With all of the LLMs out there that can create semi-complex scripts, I think the SAST community is due for an overhaul. Agree? #infosec#bugbounty#AI#Coding
Has anyone else fully adopted ChatGPT into their workflow? This is the fastest I've seen a new meta get adopted, but hey, nothing wrong with having a readily available encyclopedia #ChatGPT#AI
With 24% of patches introducing new bugs, I wonder how common it is for security researchers to perform a diff against the old/new codebase. 🤔 #infosecurity#BugBounty
@DThompsonDev It's all the same now that recommendations are just spam and misinformation. Using AI is my preferred method of getting exactly what I need