Fun fact in LLM hacking: because of the nature of tiered defenses (Guardrails, Classifiers, Prompt Protection, RAG Access control) a LLM jailbreak might not be enough to get the system to do certain things.
An LLM jailbreak is just getting the model to reply how you want, it doesn't control those other tiers of defenses.
Learn prompt injection primitives to understand how to bypass the additional defenses:
https://t.co/dLdEW2yFcT
Incredible.
Security researcher Liork (@LucidBitLabs) just earned $100,000 for their first ever report on Immunefi.
Oh, and this report earned Liork some pretty big Hunt Points, too.
We broke commercial root detection in Android apps 🔓📲
We targeted sensitive apps - finance, security, government - which use commercial protections.
We got them running on rooted devices.
That gave us full control to modify app behavior however we wanted.
👇
Interesting and New:
A large-scale measurement study on LiDAR spoofing attack capabilities targeting object detectors, using 9 popular #LiDAR systems, resulted in a total of 15 novel findings.
"LiDAR Spoofing Meets the New-Gen" (2024)
[PDF] https://t.co/YrjPPLv3r3
Use silent #SMS messages to track LTE users’ locations
An attacker sends silent SMS messages with a defined pattern and analyze LTE traffic to verify the victim location.
All you need is just: SDR + SIM cards + LTESniffer software
https://t.co/fFfiBmmGgs
🚨 The big reveal of Evilginx Pro is finally OUT! 🚨
📔From this blog post you will learn what makes the Pro version different from the community one.
🎟️I explain how Evilpuppet secret token extraction works and showcase the core features.
Enjoy! 🪝🐟
https://t.co/kQyxOOiODI
Nighthawk 0.2.6 - Three Wise Monkeys, details of our upcoming new release for Nighthawk. See no evil, hear no evil, speak no evil. https://t.co/YZCE9ouoV0
🚨 New Findings:
🧵 1/6
Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you 👇
חשיפה דיי מטורפת ( לדעתי) של אבא שלי.
אמ,לק - במידה ואתם מחוברים לאינטרנט בסיב אופטי, יש סיכוי דיי טוב שאתם חולקים מידע פרטי שלכם עם השכנים.
קצת רקע- כיום, בישראל, ישנן 2 טכנולגיות עיקריות בהן נעשה שימוש בשביל להביא סיבים לבתים פרטים - PTP ו-GPON.>>
As promised, I wrote about my Windows 11 post exploitation technique to go from an arbitrary write/increment to a full read/write through I/O rings: https://t.co/z7ZDs9UTMC