@Xtrimecuador son una vergüenza su servicio al cliente es de lo peor, con tal de no permitir cancelar el servicio pese a haber pagado por las “promociones” recibidas años atrás simplemente cierran la llamada ☎️. @Arcotel_ec
An AI agent that automatically breaks stale Terraform locks sounds great, until you realize you just gave a bot `force-unlock` permissions.
That's a scary new blast radius for state corruption.
@4osp3l Great thread. That distinction between 'data' and 'leak' based on attacker utility is crucial for reducing noise. Many triagers underestimate CWE-200 because they ignore chaining.
LTX-2 is here and it’s a beast. 🔥
The first truly Open Source audio-video model designed to run locally on consumer GPUs.
It handles everything in one unified model:
🔹 Text-to-video
🔹 Image-to-video
🔹 Video-to-video
Local AI just leveled up. 🖥️📈
🔗 Link in the first comment 👇
#AI #OpenSource #LTX2 #GenerativeAI #LocalLLM
Certipy: The ultimate tool for Active Directory Certificate Services (AD CS) abuse. Enumerate templates, request malicious certificates, and authenticate as domain admin. https://t.co/C1HMNVcvH5 #RedTeam#ADCS#ActiveDirectory
Azure environments drift without governance.
Someone disables MFA for convenience. Another team opens RDP to the internet for a quick fix. Six months later, nobody remembers why or who approved it.
Configuration drift kills security posture:
Enable Azure Policy for baseline enforcement. Define what's allowed, block what's not, audit exceptions.
Turn on Activity Log for all subscriptions. Track who changed what, when, and from where. Route logs to a central workspace.
Set up Azure Advisor security recommendations. Review monthly, prioritize fixes, document accepted risks.
Use Resource Graph to query config across subscriptions. Find public storage accounts, missing encryption, stale RBAC assignments.
Schedule quarterly access reviews for privileged roles. Verify who has Owner, why they need it, when it expires.
Governance isn't optional when your attack surface grows faster than you can track it.
Chainsaw: Rapidly search and hunt through Windows Event Logs with Sigma detection rules. Written in Rust for speed. Perfect for triage in compromised environments. https://t.co/6wQsQxwbqZ #DFIR#BlueTeam#Rust
Hayabusa: A rust-based Windows Event Log timeline generator. Lightning fast analysis of Sigma rules against massive evtx files. The modern alternative to bulky forensic suites. https://t.co/KxAcze2jUB #DFIR#Rust#ThreatHunting
Stop trusting pickles! ModelScan scans data science models (H5, Pickle, SavedModel) for model serialization attacks and code injection. Essential for MLOps security. https://t.co/Q2eefHusnR #AISecurity#MLOps#AppSec