Just completed the #AISecurityChallenge by @Wiz_io! 🚀 It was a challenging experience exploring AI security and prompt engineering. Think you can handle it? Take on the challenge here: https://t.co/tsBmCB3rsK https://t.co/ZXwKuVZiiP
🚨 ¡Este es el hilo más loco que he leído en todo el año! Básicamente, la NSA tendría acceso legal para llevar a cabo operaciones de espionaje en todos los servidores y comunicaciones de empresas estadounidenses.
USA is becoming China. 👇
TELEGRAM BLOQUEADO
Esto es INACEPTABLE.
Recordad que ha sido una denuncia por parte de grandes empresas de comunicación del sistema.
La ética hacker, si sigue existiendo, debe posicionarse en contra de esta persecución.
Exploitation of devices to see through walls. Vulnerability in the digital image data transmission interface allows reconstruction of high-quality image streams from passive observations of cameras’ electromagnetic emissions leaks. Reveals bedroom internals https://t.co/V02p1ZCHb2
Nominations for Security magazine's 2024 #WomenInSecurity are now open. The form closes on March 1, 2024, so nominate your colleagues and peers now!
https://t.co/RkJw2wUhaO
#Security#SecurityLeaders
HackingPT es un modelo de ChatGPT personalizado para seguridad informática, entrenado con contenido de alta calidad y configurado para proporcionar respuestas veraces desde la perspectiva de un pentester.
Si tienes ChatGPT plus, te invitamos a probarlo y compartir sus experiencias para mejorarlo en conjunto.
https://t.co/OIRhPFud0i
Here we go... I just made available the Nuclei templates for honeypots detection that I presented last week at @ekoparty (and also at @swisscyberstorm) 😊
-> https://t.co/9GB39BRhrv
🤖 The Reality of Bug Hunting Automation 🕵️♂️
">95% automated finds often lead to duplicates! 😱 Skilled automators are everywhere."
🔎 Unfortunately, this is one of the most commonly asked questions by new fellow researchers, often seeking automation strategies in hopes of quick earnings. However, the harsh reality is that these common misconceptions can result in individuals finding no issues at all, potentially causing them to abandon their bug bounty journey.
In my experience:
(1) I am sitting on 100+ XSS Issues, 20+ subdomain takeovers, and not even bothering to report, as I know they'll be duplicates (I know this for a fact cause these are way too obvious)
(2) Reported a manual XSS on a new-scope within 60 mins, It was marked "Dupe" as someone else got it in 15 (That goes to show the level at which people are automating stuff)
(3) More than 1000+ Low/Medium findings with nuclei unreported due to high likelihood of dupes.
Automation isn't always the answer. However, it doesn't mean you should avoid automation altogether. There are still effective approaches to make it yield results.
Next tweet: Unveiling the scenarios where automation can help. Stay tuned! 💡 #BugBounty, #Hackerone, #securitytips, #bugcrowd, #Security
¿Seré el único que utiliza una contraseña alfanumérica en lugar de un PIN para acceder al iPhone?
En este caso, te recomiendo hacerlo, ya que si llegaras a perder tu dispositivo o te lo roban, sería más difícil de descifrar el acceso mediante un ataque de fuerza bruta.
Sin contar con los bloqueos de acceso temporal que el iPhone tiene por defecto.