Have a few speaker passes for DeveloperWeek NY + AI DevSummit NY, June 9–10 at TWA Hotel, NYC.
Good fit for devs, AI builders, eng leaders & startup folks.
DM if interested — sharing while they last.
https://t.co/TUdirlXBBf
#DeveloperWeek#AIDevSummit#NYC
Tomorrow (June 1) is fwd:cloudsec North America! If you can't be there, watch the live stream:
Day 1, Room 1: https://t.co/bAHuLsL24j
Day 1, Room 2: https://t.co/Ms5oRp9LX4
Day 2, Room 1: https://t.co/IW0I85CTJE
Day 2, Room 2: https://t.co/KiRZnY3JXq
AI-Powered Red Team — 28 Specialized Agents for Offensive Security 🤖🔥
Turn Claude into a full pentesting team.
• 28 agents (Recon, AD, Web, Cloud, Mobile)
• Auto task routing → correct agent
• Real tools support (nmap, sqlmap, nuclei, BloodHound)
• Recon → Exploit → Report
🔗 https://t.co/DvJVKM2hY9
#artificialintelligence #RedTeam #Pentesting #cybersecurity #infosec
New writeup with PoCs! I used Codex to follow breadcrumbs from @calif_io’s Mythos-assisted Apple M5 memory-integrity bypass demo & see what I could recreate from the outside.
Didn’t rebuild the chain, but did find 2 new macOS kernel bugs along the way.
https://t.co/H9QJUCpgSf
4 RCE chains across 4 LiteLLM versions, each patched within days of working.
What started as #Pwn2Own Berlin prep turned into a race against the vendor’s commit log.
https://t.co/OFB7GBIosm
By @bestswngs & @bruce30262
Found a cool bug at Meta.
From misconfigured Grafana instance to R/W access on 507 private Meta repositories.
Wrote up the full chain here:
https://t.co/LYQ0prc68d
$157k bounty awarded by @metabugbounty
Research papers you must read for AI Engineer interviews:
1. Attention is all you need (Transformers)
2. LoRA (Low rank adaption)
3. PEFT ( Parameter Efficient Fine Tuning)
4. VIT (Vision Transformers) 5. VAE (Variational Auto Encoder)
6. GANs ( Generative Adversarial Networks)
7. BERT ( Bidirectional Encoder Representation from Transformers)
8. Diffusion Models (Stable Diffusion)
9. RAG (Retrieval Augment Generation)
10. GPT (Generative Pre-trained Transformers)
11. MoE (Mixture of Experts)
12. RLHF (Reinforcement Learning from Human Feedback)
13. LLaMA (Large Language Model Meta AI)
Gitleaks, a really solid open-source secret scanning tool for detecting accidentally exposed credentials in repositories and CI/CD workflows.
It can help identify:
• API keys
• AWS credentials
• GitHub tokens
• database passwords
• private keys
• OAuth secrets
One leaked secret can sometimes lead to full infrastructure compromise, which is why tools like this are heavily used in modern AppSec and DevSecOps pipelines.
Definitely worth checking out for source code review and security automation workflows.
Source: https://t.co/9PRoXZ0Xim
#CyberSecurity #BugBounty #AppSec #DevSecOps #InfoSec #GitHub #Recon #SecretScanning
[NEW BLOG]
Red-Teaming Cloud Infrastructure with Neo
We gave Neo a single prompt against an test AWS environment - no step-by-step guidance, no hints. It exploited a CI/CD auth bypass, extracted production secrets from build configs, pivoted to AWS via IMDS, and chained through a private subnet to reach the production database.
11 findings. 3 Critical. ~2.5 hours.
https://t.co/1u2GKeDUrt