We are thrilled to announce that NetSPI and @synack have entered into a definitive agreement to merge & form the industry’s leading offensive cybersecurity platform.
Full announcement: https://t.co/O9Uy9csFQI
#NetSPI#Synack#OffensiveSecurity#ContinuousTesting
Best talk I watched today:
"Grand Theft Actions: Abusing Self-Hosted GitHub Runners at Scale"
by @adnanthekhan and John Stawinski.
https://t.co/8nS0ObjeAN
🔥Real-world takeovers and hot CI/CD tradecraft. Thanks for some very valuable stuff guys! #defcon32
@digitalocean I have raised a ticket before 1 month for issue with the account sign in through github account. Need your intervention to look into the ticket number #09157256. Still I am getting the extra bills without using it.
Back in May, I disclosed a Critical vulnerability that could have given attackers direct access to thousands of companies around the world. How? By backdooring every official Puppet module on Puppet Forge. #cicd#GitHub#puppet#hacking
https://t.co/sWK9DCbvoB
In #BHASIA Briefings “The Final Chapter: Unlimited ways to bypass your macOS privacy mechanisms” @theevilbit and @_r3ggi will discuss bypassing macOS's privacy mechanisms and show many new vulnerabilities and a couple of new techniques.
Reg now >> https://t.co/I9xVOKBE9n
BlueDucky automates exploitation of #Bluetooth pairing vulnerability that leads to 0-click code execution
▪️automatically scans for devices
▪️store MAC addresses of devices that are no longer visible but have enabled Bluetooth
▪️uses Rubber Ducky payloads
https://t.co/B1jkbNcCYq
Secureum has a free book inspired by Foundry Book that includes:
- Ethereum 101
- Solidity
- Security Pitfalls and Best Practices
- Audit Findings
If you want you can contribute to this👇🏼
https://t.co/tMI6lwNtjX
Ever came across a case where Content Security Policy (CSP) blocked your XSS? 😅
Here's a simple trick to check if your target has a CSP bypass using your own web console! 😎 👇
Technical analysis of a six vulnerabilities discovered in Android-based PAX Technology Point of Sale (POS) devices
CVE-2023-42133, CVE-2023-42134, CVE-2023-42135, CVE-2023-42136, CVE-2023-42137, CVE-2023-4818
https://t.co/DZS2mo1GFB discovered by @stm_cyber
Last few weeks I have been learning more about LLM application vulnerabilities and found my 1st prompt injection bug :D I am sharing some resources for someone trying to start.
I think OWASP did a great job here.
https://t.co/9qJEQVDAVq
Don't just read the PDF also follow the reference links and read the case scenarios.
Also, I found these two tools for prompt injections very helpful.
https://t.co/TFCS3SXyGY
https://t.co/hgGvwAoBbl
In my view for general pentests mastering Prompt Injection, Insecure Output Handling, Model Denial of Service, and Sensitive Information Disclosure related topics will make a lot of sense.
Also, Portswigger released labs on LLM vulnerabilities.
https://t.co/LRVzT0sZlt (Yet to do it but looks promising)
Happy Learning! If you have more resources do comment.
#llmsecurity #aisecurity #security #learning