Interested in the security of AI Agents 💁🛡️?
Then you've likely heard of "prompt injection", but do you know what "task injection" is? If you're curious, check out our latest post for a description and some real-world examples we discovered.
https://t.co/pWdDGX6M0W https://t.co/P8ndgCXtH1
New from our security teams: Our AI agent Big Sleep helped us detect and foil an imminent exploit. We believe this is a first for an AI agent - definitely not the last - giving cybersecurity defenders new tools to stop threats before they’re widespread.
Hacking Windsurf: I asked the AI for the shell, it said yes.
new video’s out. I show how I could’ve hacked you… just by getting you to click my link.
Link posted below.
@UC_Assist@urbancompany_UC There was a booking that I did on your app and the work was completed but the booking is still showing as paused in the app. Can you fix this because it keeps showing me as in progress ?
👀 AI chatbots are on the rise, and securing them properly has never been more important. Synack Red Team member Kuldeep Pandya (@kuldeepdotexe) details a vuln he found that allowed full access to the database and the underlying filesystem. Read on → https://t.co/FWliwa8JlS
Google Dork - API Endpoints ⚙️
site:example[.]com inurl:api | site:*/rest | site:*/v1 | site:*/v2 | site:*/v3
Find juicy API Endpoints for further testing 🎯
@WalterJLindner Good to hear that. Time difference of 3.5 hours instead of 4.5 hours makes easier for us to work with our friends and colleagues in Berlin and across Europe. 3.5 hours seems not too much while 4.5 hours sometimes feels to be long.
HTTP Request Smuggler now has a probe for desync flaws caused by broken header removal operations, like this Akamai exploit.
PS you can find the lengthy rambling editions of most of my tweets at @[email protected]
https://t.co/Sbcj4PGuI4
https://t.co/kKvN54H74k
Watch,
Proof of Concept: Remote Code Execution on Element Desktop Application.
https://t.co/C1qFFcVbaI
This involves usage of v8 n-day exploit to bypass certain Electron Framework restrictions.
Watch,
Proof of Concept: Remote Code Execution on Discord
https://t.co/eUcZ22lK9I
Meanwhile, I will write one more blog to release after our
DEFCON talk.