uid0
1.2K posts

uid0
@uidzero
Red Team @Sophos | infosec nerd | Netflux & Chill CTF Team
@[email protected] 가입일 Şubat 2014
1.8K 팔로잉1.7K 팔로워

If your interested in the methodology behind penetration testing AI ecosystems, check out my latest blog post!
Deep dives on these methodologies to follow soon!
#cybersecurity #ai #hacking #ethicalhacking #offensivesecurity
blog.rootsignal.co.uk/blog/pentestin…
English

Most companies think the risk with AI is the model. Its not....
If an attacker can influence the model, they can influence the systems behind it!
My latest post on how we test AI Ecosystems and use LLM's to pivot to real infra. Check it out below.
blog.rootsignal.co.uk/blog/pentestin…
English


pro: got quoted in this article talking about surveillance system breaches!
con: got referred to as "he"...again
cybernews.com/news/fbi-cyber…
English

@KeithRamphal @HackingLZ Lol reverse uno 🤣 correct, if you can prompt inject or jailbreak the bot, you win prizes!
English

@HackingLZ @uidzero Reverse Uno the pentesting bot and prompt inject it.
I think you win the pentest at that point right?
English

With all these AI pentesting bots being posted recently, I decided to put my two cents into why we are not ready for fully autonomous pentesting with AI yet.
Im case you missed it, read it on my blog here:
#ai #Pentesting #CyberSecurity
blog.rootsignal.co.uk/blog/is-ai-rea…
English

@HackingLZ I saw you've been doing some research on this. Planning to go public with it? Id be interested in the findings
English

@uidzero Also fun…Look at the code for most of them and watch how little they care about security or prompt injection.
English

@JustL22866 Yeah agreed there, the legal discussions would be a requirement. Data wise I didn't touch on in this post but this would certainly be something to consider if you're planning on using any of the frontier models like Claude, GPT etc.
English

@uidzero IMO, any company wanting to use AI on assessments should first speak to legal ..
We will likely purchase an Enterprise license , giving us control of the data. But we are still trying to determine how to best deploy Claude to the actual red teamers
English

I decided to start a blog for some hacker ramblings and insights, and what better way to start than to discuss why AI is not yet ready for end-to-end pentesting.
Keen on getting people talking about this subject, let me know your thoughts on this!
blog.rootsignal.co.uk/blog/is-ai-rea…
English

@x25princess 100% would agree. Recently had an OKR to create an AI based tooling to assist with adversarial attacks / penetration testing. Given the hallucinations etc in LLM's, there ain't no way I'm throwing any AI based tool at a live env.
English

I am old school and wouldn't use AI in my red teaming. I'm not anti AI, I just am not on the pen testing side, I do physical security testing and I can't even get GPT to get dates right, so I don't trust it with my work.
Kyle 'esSOBi' Stone@essobi
Autonomous Agentic Offensive Agent in Kali. #buildinpubic
English

@HackingDave @_xpn_ Love this, it definitely works been doing it for years. Although you just lost a friend point as I spat out my correctly boiled from a kettle tea over that comment 🤣
GIF
English

Solid recommendation. Telling yourself positive things or visualizing what you want to do - your brain believes it and executes on it.
Only complaint is that she wasn't using microwavable tea.
AMIRITE all my brits out there? Superior tea == microwaved? @_xpn_
Mindset Machine @mindsetmachine
10 years worth of learning in 1 minute.
English

The days of dumpster diving, phreaking, BBS and damn cool hacks. If you are new to the industry or haven't looked at the past, I implore you do to so. Never forget where we come from!
@RayRedacted did a great talk about this a few years back for TMHC, worth a watch!
English












