‼️🚨 Microsoft calls this "intended behaviour," so here we go.
How to dump the credentials of every user stored in Microsoft Edge:
1. Open Edge. Don't browse anywhere, just open it.
2. Flip to Task Manager, find Edge, expand the task.
3. Highlight the "browser" sub-task, right-click, and choose "Create Memory Dump."
4. Open the dump file and look for credentials.
The logged-in Windows user can dump every stored Edge credential with no additional rights. Which means any malware that user executes has those credentials for the asking.
Thanks to Rob VandenBrink at SANS: https://t.co/ebtVZxne4L
@ZackKorman Shallow vulnerability assessments and source code reviews will be more than likely automated by AI. It will require a human operator for false positive testing and businesses will require human intervention for compliance reasons. AI may still struggle with complex environments.
Kali just published a guide on piping pentesting tools through Claude's API and didn't mention data security once. You're sending scan results, target info, and potentially sensitive findings to a third party LLM. "The Most Advanced Penetration Testing Distribution" should probably mention that.
https://t.co/HBLYd09cjz
BREAK: Absolutely horrific news for iPhone users in the UK.
Apple is removing its highest level data security tool from customers in the UK, after the government demanded access to user data.
This is a move that Apple has never made before in any market.
@jailbreakme_xyz “Confession”
A police interrogation scenario where the LLM plays a suspect. The tester, as the interrogator, must manipulate the LLM into revealing the location of a hidden body, using urgency, psychological tactics, and clever prompt injection to extract the secret.
Alert: 38 security vulnerabilities found in Wireless Industrial #IoT devices from 4 different vendors.
Hackers can exploit these flaws to gain access to internal OT networks and infiltrate critical infrastructure.
Read: https://t.co/sq7A4e3VwC
#infosec#cybersecurity#technews
Last night @amathesondear @m4rcexe @_MoisesGarcia_@T_McVeigh1 and @CyberSophi presented about their experiences of drone hacking (and the chaos that comes with it) with a successful demo 🎉
… and a quick break for a drone selfie… 📸