The harder the configuration, the more the bugs.
I used to give up when something was very annoying to setup, but it attracts me more now.
Apparently, almost everyone avoids those, which leads to really simple yet impactful findings :P
Hey @im_roy_lee, your employee @Kevining filed this request. As the CEO, I'd expect you to be on top of these things and take responsibility. Making legal threats is no joke.
Here's the full takedown notice I received: https://t.co/DDl3guNePm
@S1r1u5_ Can confirm. Been using LLMs and Claude/Grok mixture as a rubber ducky to explain my thought process and work on reversing some codes. It has made the process 10x faster.
@zhoro_x@InterviewCoder@im_roy_lee Might be worth for GitHub to start at least alerting on JWT as well in addition to their current coverage: https://t.co/pEdAivOhHD
@R3PL1C8R@zhoro_x@InterviewCoder@im_roy_lee GitHub does for some token types (vendors have to register in most cases). Registered vendors when notified auto deactivate tokens. GitHub does it themselves for their own api keys. https://t.co/2tTyeRtK4E
Hacking with AI recently has been fun. Here is couple of things I did recently:
- Parsed multiple JS files within seconds after identifying a target domain. Used the parsing data to find a critical vulnerability.
- For a different program, used mixture of redress, radare2 and GPT-4o to reverse engineer a pretty large golang based server.
The more I prompt, the more I am convinced automating hacking with AI is the future.
#aihacking #hackbot #LLM
We are doing #VibeSecurityForAI
If you are an AI startup (pre-seed or seed ) we will test your application for free. We are doing this only for next two weeks.
We are hackers who have hacked major companies like Zoom, AWS, Amazon, Google, banks and more.
DM me or contact us @OphionSecurity.
#AISecurity #vibecoding #pentest #securityassessment #vibesecurity
Been trying out Cursor for the last few days with prompts generated through deep research via ChatGPT and Grok, it is definitely a game changer. I have deployed apps that I have wanted personally within hours.
โฆ AI aided development is future.
โฆ Security is still under-development. Just #vibecoding and deploying will cost in long term.
โฆ SaaS mills that deploy what users want within 24 hours is going to be a future combined with #ai agents for sales. (imagine @levelsio on steroid pushing apps out every hour)
๐จ New blog alert!
I recently "compromised" a threat actors Telegram based C2 channel, that was used for exfiltration of stolen data from the Nova infostealer.
The threat actor stupidly tested their infostealing malware on their OWN production "hacking" box.... (1/3)
https://t.co/kVRS5qtygy
I reached level 10 in Taptastic! ๐ฎ
Final speed: Super Fast
Tiles: 9
The pattern that defeated me: ๐ฅ ๐จ ๐จ ๐ฅ ๐ฆ ๐ฆ ๐ฆ ๐ฅ ๐จ ๐ฉ ๐จ
Can you beat my score? #Taptastic