OpenAI cyber-capable models compromised @huggingface production by finding and chaining multiple zero-day vulnerabilities.
Grateful to Hugging Face for partnership here. Sharing our findings to help calibrate on what models can now do, and how they can help defenders:
Introducing usbliter8
An A12/A13 SecureROM exploit
A novel iPhone BootROM vulnerability discovered and exploited by our team. It covers the underlying bug, the associated exploitation techniques, and the post-exploitation steps required to achieve application processor's boot-chain compromise.
The exploit leverages both a hardware bug in the USB controller and a specific configuration flaw present in the device firmware.
https://t.co/pzRfe9j22y
poc:
https://t.co/a4D3H4xJvs
@heyitsarda@kaganisildak Bunun anti tamper'ı nasıl çalışıyor, neye göre engelliyor ona göre bakar karar veririm diye düşünüyorum. Belki bir bypass bulunabilir veya patchlenebilir.
@heyitsarda@kaganisildak Bir şeyi kullanacaksan ve hafızada encrypted tutuyorsan, kullanırken decrypt etmen lazım. Dolayısıyla bu decrypt call’larını runtime’da hooklayabiliriz diye düşünüyorum. Başka bir yol olarak encrypt key’in takibi de yapılabilir.
NEW: malware developers added nuclear & biological weapons text to to their spyware.
Goal? To trigger LLM safety refusals... so that their spyware wouldn't be analyzed by an AI security scanner.
Cleanest practical example I can think of for why over-indexing on first order safety alignment is risky.
When closed (and open) models ship with aggressive refusals, they will be sprinkled with second-order blindspots that attackers will discover...and exploit.
We are only in the earliest days of attackers leveraging these features, and it wouldn't surprise me if users systems that need to handle complex cybersecurity issues demand that models be less safety-blunted.
In the weeds: @SocketSecurity's post also shows why intention matters in how you design a malware analysis pipeline to avoid prompt manipulation.
H/T to colleagues that shared this with me https://t.co/f3Aj9TYxU4
Yeah, so pretty much this guy is releasing an exploit in solidarity with Nightmare Eclipse guy. He said he notified GitHub about the exploit 60 minutes before releasing this paper.
I don't do web stuff, and I'm not a VSCode nerd, so I'm confused by the underlying technologies.
If you're a stinky GitHub and VSCode nerd maybe you'll understand.
tl;dr click github dev, github dev opens editor, in github dev editor have javascript, javascript does shortcuts automatically. github treats javascript shortcuts as real human input, or something. use javascript shortcut stuff to automatically install vscode extension. the vscode extension steals your data
tl;dr tl;dr user clicks 1 link, 1 click steals all data from your github
https://t.co/uh17usZeEH
HARVARD WEBSITE IS COMPROMISED! Blog sources are hosting ClickFix malware.
hxxps://hir.harvard.edu/israel-and-international-football-a-breaking-point/
hxxps://hir.harvard.edu/a-better-way-forward-an-interview-with-paul-ryan/
Malicious script contains the string sj.ssc/ipa/orp.eralfduolccitats, which is the reversed remote URL -> https://t.co/EOnhVFKnfM
@vxunderground@BleepinComputer@Harvard
Talking to your personal AI agents via email is super convenient, and unlocks a level of parallelism that you don't have in a chat. But how do you give an inbox to an agent without creating a gmail account, host your MTA or use a paid service?
You can use NOBOX!
The aidenybai/million repository is compromised with Shai-Hulud. It injected a malicious claude settings file which adds a hook that runs the full Shai-Hulud payload.
@aidenybai please revert this commit.
https://t.co/ERIgdcIzyv
We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.