The hackerbot-claw campaign. My take: AI is phenomenal in exploitation. Vulnerability research = craftsmanship, but exploitation? A guidebook + trial-n-error loop, which agents excel at.
Maybe novel threat detection should flag LLM-generated content? ๐ค
If you're using Codespaces in your daily routine, you must be aware of the potential consequences. Full writeup on our blog ๐
https://t.co/ew795wM0j3
I've been able to use these techniques to
1) Gain full repository control
2) Carry XSS via installed Vscode extension
3) Abuse expensive Premium Copilot models ๐ค
๐ต๐ฑ Polish Security Experts! ๐ก๏ธ
We're hiring a Security Researcher for our R&D team. Work with cutting-edge tech (eBPF, Linux, K8s, Malware analysis) to fight cybercrime!
https://t.co/FKKmVf31ZQ
RTs appreciated for reach! ๐
#CloudSecurity#CybersecJobs#PolishTech
After uncovering the #DeleFriend Google Workspace design flaw, it's time to protect against it.
Join threat researchers @yonatankhen (Axon) and @roinisimi (@orcasec) as they join forces to demonstrate how to detect and prevent an attack
Register here: https://t.co/Uce8OqM2n9
Cloud Threat Researcher @roinisimi from @Orcasec discovered a critical design flaw in the #GoogleCloud Build service that creates a significant #supplychainrisk.
https://t.co/odrc62emdj
๐ก๏ธ New flaw in #Microsoft Azure Uncovered! Hackers could exploit this weakness to gain access to storage accounts, move laterally and execute remote code ๐ต๏ธโโ๏ธ
๐ฐ Learn about this "by-design flaw" & how to protect your data: https://t.co/AsqAj76gJP
#CyberSecurity#DataSecurity
Our team of researchers continually push the limits to find #securityrisks before bad actors do.๐ Learn how we discovered a critical exploitation path, utilizing Microsoft #Azure shared key authorization, and how to mitigate this: https://t.co/MzgHxSKzNU