Got my first Chrome CVE!
This was surfaced by my agentic pipeline, though the PoC was put together with a bit of manual work, AI, and a lot of digging through similar older reports and commits, since it was my first time and I honestly did not understand much of the codebase or how a PoC was supposed to be done for this case initially.
Iβve also had a few other CVEs surfaced by my pipeline over the past few months, and I might write about those some other time
Had too many AI tokens, so I vibe-coded a Malaysia Web Defacement Observatory.
It visualizes scraped Malaysian web defacement data, with the entire pipeline running on GitHub:
- GitHub Actions -> data processing
- JSON metrics generation
- GitHub Pages -> dashboard
Check it out:
https://t.co/mdsfQVrWEt
Salam, baju carisurau dah selamat dipos kepada semua contributor, terima kasih kepada semua! InsyaAllah carisurau V2 akan disambung develop ramadhan.
Boleh tengok design upcoming for V2 dekat sini:
https://t.co/8ZVILZJcc2
Carisurau codebase
https://t.co/Sknxn4GSkR
The prize pool we have collected so far is MYR600. If anyone wants to add to it or sponsor by adding their logo, please let me know. The CTF starts tomorrow at 9PM GMT+8.
We have ~140 players going to compete (solo/duo)
Parallel Pulse @nanosec_asia is excited to π welcome Jason Phang and Robbin Ooi to our panel of speakers, presenting "Following the Breadcrumbs: MacOS Unified Logs & FSEvents."
Read abstract here: https://t.co/YUMqpGgj59
Watch this space for registration - opening soon!
btw be careful, me and my colleague identified a malicious SEO poisoned GitHub Desktop download website where it has AMOS stealer in it.
This commit (https://t.co/S5ReXWF2FU) shows the threat actor modifying the README file to include his own download URL.
#AMOS#Phishing
I'm sharing my note, containing little tips and checklist on how we can attribute a piece of malware or a campaign to certain threat groups. Although it does not cover all methodologies but I think it's good for beginners to learn this topic. ππ»
https://t.co/0XyPiRUFOg