Datadog's security team has just released KubeHound, an open-source attack mapping tool for Kubernetes clusters
https://t.co/1NaHHIfznN
https://t.co/rwWQFHY4kT
Comes with 25 attack types, each one comes with step by step instructions of how to exploit it
UHFKILL via Lab401
https://t.co/ip08Xp7LFZ
The UHF RFID deactivation tool.Wirelessly and permanently disable UHF tags.A must have for OpSec/Operational Teams to deactivate tags embedded in clothing, shoes and products that can be used for tracking, identification and detection.
I “jailbroke” a Google Nest Mini so that you can run your own LLM’s, agents and voice models.
Here’s a demo using it to manage all my messages (with help from @onbeeper)
🔊 on, and wait for surprise guest!
I thought hard about how to best tackle this and why, see 🧵
I remember when Apple proposed their CSAM scanning system in 2021, there were a lot of people complaining about the “slippery slope fallacy” and how we couldn’t just assume that content scanning would be expanded to other purposes. 23 months later: https://t.co/CpkwaKxJHh
If you want to truly understand #AWS, you need to learn how it fails. Then you can design things to work around failure. Everything fails, all the time :) Something I cover extensively in my https://t.co/LXHWsPXate courses .. is failure & resilience :)
Please Retweet!
So I just woke up and apparently I inadvertently discovered a zero-day RCE in https://t.co/Byl6l73Yet, and caused a Chinese CA to shut down overnight.
Props to the @neilpangxa of https://t.co/Byl6l73Yet for the quick fix! https://t.co/cvbLrRzW8o
‼️A Chinese certificate authority ("HiCA", https://t.co/MAVrTIt9YX) is injecting arbitrary commands into the ACME challenge process, which https://t.co/Byl6l73Yet then executes on the client machine. Here's my current analysis: https://t.co/cvbLrRzW8o
It is with profound sadness that we mourn the loss of our friend and mentor, @aloria. Kelly had an indomitable spirit, and our world is a bit darker without her.
If you're affected by the recent NCC workforce cut and you still 💕 appsec consulting, we're still hiring @Doyensec https://t.co/3Rkv4Cv4b7 (US based) #onemore#appsec
Today, DoNotPay is launching a chatGPT extension that reads the Terms and Conditions, leases and flags anything that is non-standard to all our customers
GitHub - MaximeBeasse/KeyDecoder: KeyDecoder app lets you use your smartphone or tablet to decode your mechanical keys in seconds. https://t.co/upYVjXlt21