🎙️In this episode of 'The Next Big Thing' #podcast, Chris and I are joined by @shelldaemon, Chief Product Officer @Darktrace to discuss the intersection of #AI and #cybersecurity.
Spotify: https://t.co/Ab3AQRryyt
Apple: https://t.co/3RQmsyWWLX
https://t.co/hB5F9Rmyp2
RE: APEX / ALGS / EAC Remote Code Execution
👋 I wrote undectable cheats for online games for challenge and sport for many, many years. I know enough to know that no one has the answers, but I'd like to call out some things you may have glazed over, and put them in context. 🧵
A lot of organizations are getting hammered by QR-code based phishing. Many SOC teams seem to be struggling to find a good answer.
We've been seeing and stopping this since (before) July this year - using machine learning.
Real-life example & tech:
https://t.co/J8kxfEKpX1
#EPSS & #KEV are great for #vulnerability management. What's usually still lacking is local organizational context though 🧐. Combining ML, graph theory & attack path modelling for vulnerability prioritization with local context 🙏: https://t.co/xg1ZHl4Mfa
The famed Stanford Smallville is officially open-source!
25 AI agents inhabit a digital Westworld, unaware that they are living in a simulation. They go to work, gossip, organize socials, make new friends, and even fall in love. Each has unique personality and backstory.
Smallville is among the most inspiring AI agent experiments in 2023. We often talk about a single LLM's emergent abilities, but multi-agent emergence could be way more complex and fascinating at scale. A population of AI can play out the evolution of an entire civilization.
Endless new possibilities ahead. Gaming will be the first to feel the impact.
Github: https://t.co/xUll7KaaTp
Paper: https://t.co/PMDQysrOz9
Authors: @joon_s_pk@joseph_c_obrien@carriejcai@merrierm@percyliang@msbernst
Do you often use ChatGPT for cybersecurity? If so, what do you use it for? Be it for writing queries, scripts, etc. I've spent just a couple of minutes so far and couldn't find a use case for myself and probably I'm missing something or just dumb.
@thegrugq@daveaitel there is very little data on size of teams, structure, setup, resource ($$) required for 'well tooled-up adverary teams' out there - @daveaitel 's q on that and the micro-discussion afterwards was good. many people think of 1000s of people when they hear 'APT'.
@Cyb3rMonk I know you are not looking for a tool, but have you heard of @CadoSecurity? They have a bunch of good resources and have worked on that very topic quite cleverly for a while. If nothing else, possibly worth a chat.
My threat research colleagues have translated last week's internal leaks of the #yanluowang#ransomware gang and analysed them. Interesting to see what impact these leaks have on the broader ransomware landscape. https://t.co/nUra9tbGTf
Image there was a ransomware variant that does not encrypt files, but change the content of files (words in docs, numbers in lists, ...) based on context, but just subtly so you won't notice and keep working with it. An attack against integrity, not availability in essence. (1/4)
This will be a thread discussing a real world breach involving a drone delivered exploit system that occurred this summer
Some details I am not able to discuss, however for the blue teams & red teams out there I hope this provides a good measure of capability.
🧵🚁 🎮🖥️🦠