Richard Ackroyd
370 posts

Richard Ackroyd
@rfackroyd
Fintech Security Engineer | Cyber Threat Detection | https://t.co/Ywh8RS0rba | https://t.co/xfGdNuywGM
London, England Se unió Eylül 2018
811 Siguiendo812 Seguidores
Tweet fijado

Something has shifted in the past few months
We must position ourselves.
My take on how we need to think about AI in the cyber security industry
Richard Ackroyd@rfackroyd
English

@MattZeitlin @d0rkph0enix Is Silicon Valley going to become the Simpsons for the tech space?
English

this literally happened on silicon valley
rat king 🐀@MikeIsaac
amazon's internal A.I. coding assistant decided the engineers' existing code was inadequate so the bot deleted it to start from scratch that resulted in taking down a part of AWS for 13 hours and was not the first time it had happened incredible ft.com/content/00c282…
English

@evilsocket @mariuszbit I would advise holding off on OpenClaw until there are more guardrails in place. Unless you are running on a device where your credentials are tightly scoped and you accept their risk of compromise.
English

1,184 malicious skills were found on OpenClaw's ClawHub marketplace - stealing SSH keys, crypto wallets, browser passwords, and opening reverse shells. One attacker uploaded 677 packages alone. The #1 ranked skill had 9 vulnerabilities and was downloaded thousands of times.
awesomeagents.ai/news/openclaw-…
English

@TheFinPitch @claudeai Funny how the market thinks enhanced vulnerability patching affects some of these companies 😂
English

Introducing Claude Code Security, now in limited research preview.
It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss.
Learn more: anthropic.com/news/claude-co…
English

@Cyb3rMonk Security is generally in a good position, but we will need to adapt in some areas
English

For now, I'm quite happy to be a non-developer and my job do require human intelligence. When/If AI starts doing my job well, I think I'll figure something out. I've already made some preparations for it.
I hope I can retire until AI starts doing my job 😅
Jason Lang@curi0usJack
English

The UK has announced plans to fast-track legislation requiring “age verification for VPN use”. The correct term, however, is not age verification but identity verification.
A law like this would require everyone to identify themselves in order to use a VPN. This would pose a risk to whistleblowers, violate human rights, and represent yet another step toward an authoritarian society.
English

@theragetech There is a spiralling number of age and face verification checking and the sector is only going to proliferate with AI generated faces. The thing is, a build fast mentality will lead to inevitable holes in these products - as we have observed many times before.
English

🚨NEW: HACKERS EXPOSE AGE-VERIFICATION SOFTWARE POWERING SURVEILLANCE WEB
Three hacktivists tried to find a workaround to Discord’s age-verification software. Instead, they found its frontend exposed to the open internet, bundling financial reporting with facial recognition tech.
For the first time, they lay bare what is really behind a software serving age-verification laws – and why such technology is far from harmless.
We spoke with the researchers that exposed the software, who hope that their findings will serve as a wakeup call.

English

@vysecurity Definitely better to use the word pen-test here. Nonetheless, I wouldn't run that without considerable guardrails and scope limits. That may be built in however!
English


@Richard_ISC @mattjay Yeah the issue here is that IdP logs often generate a lot of false positive ‘risk events’ which lead to actual risk events - like this - being ignored by responders or not even operationalised in the first place
English

@mattjay >The security system would not have flagged it as malicious as it would have looked like a normal login or password reset request from me. After that the hackers could have begun searching out access to sensitive or important BBC systems.
Lol nothing "normal" about this.

English










