Amazing: KPMG wrote a report describing the successful use of AI by businesses. But the case studies turned out to be AI hallucinations.
https://t.co/s3LE8vedNi
Hey @TecR0c, I cannot dm you so I'll try here 🙂 do you mind sharing recommendations about windows exploit development courses/trainings that go from zero to hero?
Did you hear that?
Akamai researcher @nachoskrnl has discovered two vulnerabilities within Windows.
Leveraging the infamous custom reminder sound feature, these can be chained together to achieve full 0-click RCE against Outlook.
Full write-up:
https://t.co/W2bXFwTxJK
Use .contact file attachments for your malicious URLs. More than half of your malicious emails aren’t even reaching the target inbox and it’s sad. You can use .vcf too but the URL isn’t clickable. Make attachments malicious again. Happy holidays!
YouTube has started to artificially slow down video load times for Firefox users using the following piece of code:
setTimeout(function() { c(); a.resolve(1) }, 5E3);
5E3 being 5000ms, or simply put 5 seconds.
https://t.co/QHaTSaRYbd
AD: Local Admin to Domain Admin
It doesn't matter if you don't see active sessions, always look in the Kerberos cache.
query session VS klist sessions
Don't attempt an LSASS DUMP, move on!
GIUDA 2023090500
Now FUD again
https://t.co/BSltXqY5M8
#redteam#adprivesc#kerberos #lsass
⚠️Watch out for your #SharePoint environments in the upcoming weeks...
There is now enough info out there to implement a full #exploit chain
using #CVE-2023-29357 and #CVE-2023-24955.
If SharePoint is anything like Exchange in patchratio we are approaching dangerous waters.
Repeat after me: no amount of security awareness training will solve the social engineering problem. You might as well be relying on ancient chants and sacred crystals if this is the plan.
Thank you for coming to my TED talk...
Call of Duty multiplayer servers temporarily suspended due to a malware that's automatically propagating to players' systems. The worm was initially identified on VirusTotal on 24th July, 2023. More samples from the same source: https://t.co/9tDNEHE8n1
https://t.co/YFXa9dhC1H
GPT-4 is getting worse over time, not better.
Many people have reported noticing a significant degradation in the quality of the model responses, but so far, it was all anecdotal.
But now we know.
At least one study shows how the June version of GPT-4 is objectively worse than the version released in March on a few tasks.
The team evaluated the models using a dataset of 500 problems where the models had to figure out whether a given integer was prime. In March, GPT-4 answered correctly 488 of these questions. In June, it only got 12 correct answers.
From 97.6% success rate down to 2.4%!
But it gets worse!
The team used Chain-of-Thought to help the model reason:
"Is 17077 a prime number? Think step by step."
Chain-of-Thought is a popular technique that significantly improves answers. Unfortunately, the latest version of GPT-4 did not generate intermediate steps and instead answered incorrectly with a simple "No."
Code generation has also gotten worse.
The team built a dataset with 50 easy problems from LeetCode and measured how many GPT-4 answers ran without any changes.
The March version succeeded in 52% of the problems, but this dropped to a pale 10% using the model from June.
Why is this happening?
We assume that OpenAI pushes changes continuously, but we don't know how the process works and how they evaluate whether the models are improving or regressing.
Rumors suggest they are using several smaller and specialized GPT-4 models that act similarly to a large model but are less expensive to run. When a user asks a question, the system decides which model to send the query to.
Cheaper and faster, but could this new approach be the problem behind the degradation in quality?
In my opinion, this is a red flag for anyone building applications that rely on GPT-4. Having the behavior of an LLM change over time is not acceptable.
Have you noticed any issues when using GPT-4 and ChatGPT lately? Do you think these problems are overblown?
Here’s another interesting project that references my work at https://t.co/zZWKvsRLZs
Comprehensive toolkit for #Ghidra headless
// by @2ourc3
https://t.co/W4EsSpCqF5