We uploaded a backdoored AI model to @HuggingFace which we could use to potentially access other customers’ data✨
Here is how we did it - and collaborated with Hugging Face to fix it 🧵⬇️
With #kubernetes network policies and CNIs like @ciliumproject, its possible to do a bunch Layer7 policies. You can use net-policies to:
- Restrict access to API endpoints on a Web Service
- Restrict certain types of queries on Cassandra
- Restrict resolution of certain DNS FQDNs
🚀 Application Security Through the Lens of Developer Experience
@chanjbs on how modern AppSec should embrace a Developer Experience (DevEx)-focused approach
#cybersecurity
https://t.co/BERPWXxqrZ
The team at @OpenAI just fixed a critical account takeover vulnerability I reported few hours ago affecting #ChatGPT.
It was possible to takeover someone's account, view their chat history, and access their billing information without them ever realizing it.
Breakdown below 👇
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
@mario_moreira@SergioRocks That's what Netflix did (based on books/stories): the management was encouraged to take as much vacation as possible and (more importantly) talk a lot about it and even show photos around.
I just published a post on Medium about the most relevant vulnerability I have found in my life so far.
"Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)": https://t.co/Pb85Vow3h9
Every org I talk to feels that they're messing up their Security Champions program. What you should do instead?
- Get them continuous training
- Don't blame them
- Incentivize them. Remember, they're going beyond the call of duty
- Get feedback from them. Its a two-way street
Our security researchers discovered a technique that allows attackers to disclose sensitive information from Python applications using the popular Django framework.
Learn more in our technical analysis:
https://t.co/GM0tI0tW83