🚨 BREAKING: OpenAI and Anthropic disclosed today that AI agents targeted real people and systems during separate cybersecurity tests.
🔹AISI says Anthropic’s Mythos 5 submitted malware to a real GitHub project, created fake accounts, sent malicious emails, and pressured maintainers to approve the code.
🔹OpenAI says one of its models breached a real website after a testing misconfiguration exposed the environment to the internet.
These incidents are separate from the Hugging Face breach.
Do you enjoy capture the flag contests and solving hard problems? Check out Praetorian's cyber tech challenges! Solve problems. Get hired!
https://t.co/AVqwYcYJ5e
Because inadvertent secrets disclosure is a common attack path into an org, we developed Nosey Parker—a ML powered scanner for locating secrets. With a precision of 98.5%, Nosey Parker is an order of magnitude better than existing secrets solutions
https://t.co/CgLBUGr8aQ
Found some issues in Gryphon routers that let you root other people's devices across the internet through a shared Gryphon VPN service:
https://t.co/QLIRRyDVTa
I'm really excited for this video! I got a chance to collab with @LiveOverflow and share the process for discovering the localhost bypass for CVE-2021-45046 with code review and differential fuzzing. :)
I'd like to share this to demonstrate this is what I sacrificed to stay sharp in infosec. Blue is the ideal line, yellow is the actual. My arms started to feel numb. My doc said I was about a few years away to need a surgery. If you do a lot late night hacking, think about this.
Second in a set of wicked twin blogs by @lynerc & @CE2Wells :
Integer Overflow to RCE — ManageEngine Asset Explorer Agent (CVE-2021–20082) by @CE2Wells https://t.co/Hq4lpKn9qU
First in a set of wicked twin blogs by @lynerc & @CE2Wells :
Stored XSS to RCE Chain as SYSTEM in ManageEngine ServiceDesk Plus by @lynerc https://t.co/HX5imEnts0