Leader Builder Breaker in Product & Cloud Security. Ex @GoCardless @Justice_Digital. @SANSCloudSec instructor in development. Assessor for @cyberchallenge.
your phone number is personal and sometimes you want to connect without handing it over. that's why we're introducing usernames for WhatsApp.
starting this week, you can reserve a username to use later this year when we launch the feature. It takes just a few seconds, make sure you have the latest version of WhatsApp and then go to Settings > Account > Username.
Recently, we purchased one of each Anthropic/OpenAI subscription plan and randomly ran long horizon coding tasks until we exhausted the weekly limit. It's widely believed that a $200/month plan maxes out at ~$2000/month worth of tokens (assuming API pricing). However, we found that the subscriptions are actually far more generous. (2/4)
We built four malicious skills to test whether skill scanners actually work. Three took less than an hour to conceive and implement. ClawHub, Cisco, and Vercel's https://t.co/nUlnRcQWyG marked them as safe. 🧵
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
sent this to the team today
everything great comes from being able to delay gratification for as long as possible
and it feels like we're collectively losing our ability to do that
AI ending interior design
Nano banana 2 now can turn sketch floor plan into 4K 3D rendering with accurate dimension, take photos for each room, and 1-click furniture change
used to cost $100k and months.. now cents and mins
step by step tutorial on OpenArt:
Wow the tool my brother @balintorosz built this week - Beautiful Mermaid - is the top of hacker news.
It’s an open source tool that generates beautiful diagrams: especially helpful when working with / planning with AI
⚠️ Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts
Source: https://t.co/3vPNLgpwnG
A significant security breach has compromised approximately 17.5 million Instagram user accounts, exposing sensitive personal information that is now circulating on the dark web.
The breach encompasses a wide range of personal information that could put affected users at serious risk. Compromised data includes usernames, email addresses, phone numbers, and physical addresses.
This combination of information makes users particularly vulnerable to identity theft, phishing, and social engineering.
#cybersecuritynews #databreach
🤖 TL;DR: Every AI Talk from Hacker Summer Camp 2024
There were >60 AI-related talks at @BSidesLV, @BlackHatEvents, and @defcon this year
I wanted to know what everyone was working on, so I gathered all of the talks in one place
And then summarized their abstracts in 1 (and then 2-3 sentences) and grouped them by category
So you can quickly grok >60 talks in ~15min
https://t.co/wvfiIKBiap
Just because you get access denied accessing a folder, it doesn't mean you can't get access. A quick look at bypassing the security on the WindowsApps folder. https://t.co/2JN9GEMWLb
Thank you to everyone who brought this article to our attention. We agree that customers should not have to pay for unauthorized requests that they did not initiate. We’ll have more to share on exactly how we’ll help prevent these charges shortly.
#AWS#S3
How an empty S3 bucket can make your AWS bill explode - https://t.co/KRgL9C1u9p
The next #OWASP London Chapter in-person meetup will take place on Thursday, April 18th, 2024 at 6pm at @thoughtmachine
Talks from Tal Folkman, Anthony Harrison and Kaiwen Jiang.
Register to attend here: 👇
https://t.co/3crkzhjvPj