maxicorbs

148 posts

maxicorbs banner
maxicorbs

maxicorbs

@CorbridgeMax

Principal Security Consultant based in London

Se unió Ocak 2016
106 Siguiendo127 Seguidores
maxicorbs
maxicorbs@CorbridgeMax·
This week in 'Securing AI: A Learning Journey' I got hands on with the awesome #spikee tool. I also broke down the differences between prompt injection and jailbreaking attacks in the world of LLM cybersecurity. Check it out: maxcorbridge.substack.com #AI #cybersecurity
maxicorbs tweet media
English
1
0
0
70
maxicorbs
maxicorbs@CorbridgeMax·
🚀My biggest AI watershed moment since getting ChatGPT to write a poem in Jamaican dialect. I’ll be diving deeper into the security side of all this in my new blog 'Securing AI: A Learning Journey' Join the ride! 🧵👇 #AI #VibeCoding #MCP #LLMs maxcorbridge.substack.com
maxicorbs tweet media
English
0
0
0
59
maxicorbs retuiteado
JUMPSEC LABS
JUMPSEC LABS@JumpsecLabs·
Imagine the feeling of a long-forgotten canary token triggering in one of your client's estates, which leads you down a path to catch and remove a sophisticated red team... No need to imagine, as @umairq_ has written up a blog: labs.jumpsec.com/active-cyber-d…
English
0
5
8
514
maxicorbs retuiteado
JUMPSEC LABS
JUMPSEC LABS@JumpsecLabs·
Tool Release! We've been having a lot of fun recently bypassing swathes of security controls using alternative web technologies to smuggle payloads right past mail security products. We've open-sourced the tool that we've been using to leverage WASM: github.com/JumpsecLabs/WA…
English
0
6
9
536
maxicorbs
maxicorbs@CorbridgeMax·
@0xLegacyy Just to clarify, the results of this poll do not count as a professional permission slip 😛
English
0
0
1
22
Jord
Jord@0xLegacyy·
Is it ethical to use leaked code signing certificates for engagements? Something I've been pondering for a while. If you have a different answer please share 🙏 #redteam #infosecurity #Pentesting
English
5
1
3
1.7K
maxicorbs retuiteado
T
T@tde_sec·
We warned Microsoft back in June about the risk of external tenant interaction being used for initial access, I’m honestly expecting the prevalence of this to sky rocket in coming months. That doesn’t even take into account the IDOR they chose not to fix. labs.jumpsec.com/advisory-idor-…
ICSNick@IcsNick

Did an investigation regarding DarkGate delivered by Teams together with my fantastic colleague Jakob Nordenlund at @Truesec. A lot of good IoC for all defenders! truesec.com/hub/blog/darkg…

English
2
17
49
10.7K
maxicorbs retuiteado
T
T@tde_sec·
Having the external collab setting as default (allowing cross org comms) has allowed us use that technique during red teams on several occasions. It also led to @CorbridgeMax and I finding this: labs.jumpsec.com/advisory-idor-… Not limiting external collab is a real, impactful gap.
Microsoft Threat Intelligence@MsftSecIntel

Microsoft has identified highly targeted social engineering attacks by the threat actor Midnight Blizzard (previously NOBELIUM) using credential theft phishing lures sent as Microsoft Teams chats. Get detailed analysis, IOCs, and recommendations: msft.it/60199EEkv

English
0
1
3
342