Cybersecurity engineer and animal rights activist. Ex-Hall of Fame collector. Acknowledged by Facebook/Google/Twitter/Apple/Adobe/Yahoo/Ebay/Sony... AKA Anillo
Algunas de las técnicas que surgen para mejorar el desempeño de los LLM se basan en ideas prestadas de cómo funciona el cerebro humano.
En nuestro último post resumimos 5 de las más recientes: https://t.co/YmbSEMo4mS
Nearly every SOC we talk to is automating something with LLMs.
L1 phishing triage, ticket classifiers, alert enrichment.
And nearly all of them make the same two mistakes: secrets in the system prompt + LLM output with no validation.
In 2026 we're living through a curious paradox in cybersecurity.
Technical people are becoming a trending target for attackers, and many end up hacked.
Full take on LinkedIn 👇
https://t.co/TOgEOgHxnW
En 2026 estamos viviendo una curiosa paradoja en ciberseguridad.
El perfil técnico se está convirtiendo en una tendencia entre los objetivos de los atacantes, y muchos acaban hackeados.
Reflexión completa en LinkedIn 👇
https://t.co/xDlvfqD7H5
Are you using Blind Prompt Injection in your AI pentests?
It's Blind SQLi but on LLMs.
The attacker injects a predicate, the app exposes an oracle (status code, content-length, latency, tool call, OOB hit, token count), and the secret is reconstructed bit by bit.
In the latest @kaptorsecurity post, I share my experience so far applying AI to pentesting tasks.
Approaches, architectures, and a few tips for putting together something that actually pays off in cost-benefit terms depending on the context:
https://t.co/LPCk0iwKlJ
En la última publicación de @kaptorsecurity comparto mi experiencia a día de hoy aplicando la IA a tareas de pentesting.
Enfoques, arquitecturas y algunos consejos para montar algo que realmente compense en coste-beneficio dependiendo de cada contexto:
https://t.co/gJZEQp7uDR
Securing AI goes beyond traditional pentesting. These architectures introduce entirely new attack categories.
Our latest article analyzes why AI security demands a new threat model and specialized skills:
https://t.co/8wCqh3o6Sl
Asegurar la IA va más allá del pentesting tradicional. Su propia naturaleza introduce categorías de ataque que antes no existían.
En nuestro nuevo artículo analizamos por qué la seguridad en IA exige un nuevo modelo de amenazas y personal especializado:
https://t.co/2cVIViZyrd
We dive deeper into the new 𝗕𝗹𝗶𝗻𝗱 𝗣𝗿𝗼𝗺𝗽𝘁 𝗜𝗻𝗷𝗲𝗰𝘁𝗶𝗼𝗻 technique.
Unified taxonomy of 6 variants: Boolean, Time, OOB, Streaming, Cache, Token-Count.
3 inherited from Blind SQLi, 3 native to modern LLM stacks.
🔗 https://t.co/ezp8Gje3Tf
Profundizamos en la investigación de la técnica Blind Prompt Injection.
Taxonomía unificada de 6 variantes: Boolean, Time, OOB, Streaming, Cache, Token-Count.
3 con equivalencia en Blind SQLi, 3 nativas de LLMs.
🔗 https://t.co/ezp8Gje3Tf
AI security is the new battlefield of Cybersecurity.
Kaptor Security is now on social.
20 years in offensive security, now focused on AI. Beyond OWASP LLM & MITRE ATLAS.
AI innovation is only sustainable if it's secure.
🌐https://t.co/cXGu7W6lil
Finally out of "stealth mode"! 🚀
@kaptorsecurity is now on socials, specializing in offensive cybersecurity for AI ecosystems. 🛡️
After months securing AI architectures for clients, it’s time to join the conversation. Proud to be on this journey with @egarme
Follow us! 🔥
🚨 #BlueSpy is now available on our GitHub. This proof-of-concept allows you to listen in on conversations from Bluetooth headsets without your users' knowledge. We have already alerted manufacturers whose devices have some vulnerabilities.
https://t.co/OJodBum1Sr
From time to time, I keep myself in a loop arguing with people who say that cookies are better than web storage for session tokens. I just realised that @albinowax wrote a well-explained article about this topic. Thanks god! https://t.co/W1iXK4zMvh
@TuIberdrola Mi consulta pendiente es si hay alguna manera de registrar feedback de la atención concreta de ayer, facilitando los datos. Normalmente el trato es correcto, pero esta persona fue agresiva desde el minuto 0. No me crean a mí, revisen la grabación si es posible. ¡Gracias!
@albinowax@floyd_ch Maybe this is also the reason why they don't detect the vulnerability on this vulnerable app when the HTTP response is not received: https://t.co/A8ZGQCHb7q
Nuestros compañeros de @BlackArrowSec os presentan en este artículo un ejercicio del equipo de #RedTeam que les permitió persistir y pasar desapercibidos en la red de una empresa. Lo hicieron además utilizando una herramienta tan común como Microsoft Teams
https://t.co/qd15lZJbLA
WAF solutions are today one of the most powerful defense shields for companies against #cyberattacks.Our colleague @joserabal analyzes their operation and effectiveness in our #cibersecurity blog. Enjoy reading!
https://t.co/uLdaOluJt7