Security Rebel

11.5K posts

Security Rebel

Security Rebel

@5m477

mov handle, @5m477 mov cert, OSCE³ mov focus, AI_security mov stack, web2.5 xor trust, trust call exploit_surface

userland Katılım Ekim 2011
8.7K Takip Edilen13K Takipçiler
Sabitlenmiş Tweet
Security Rebel
Security Rebel@5m477·
LLMs are trained on how we speak, think, and feel. That means they can be manipulated just like people. Social engineering isn’t just a human weakness anymore, it’s also an AI vulnerability. Let’s break down how this happens.
Security Rebel@5m477

Social engineering isn’t just about hacking people anymore, it’s about hacking predictable minds. Psychology is the blueprint. Now combine that with AI trained on those patterns and embedded everywhere. The attack surface didn’t just grow, it exploded.

English
1
1
2
1.8K
Security Rebel
Security Rebel@5m477·
Did I miss something, or is Claude Code suddenly all over X?
English
0
0
0
147
Security Rebel
Security Rebel@5m477·
Creation starts with understanding failure. Secure code reviewers are built for the agentic era.
English
0
0
0
183
Security Rebel
Security Rebel@5m477·
@darasoba This is a great piece, and I agree with the emphasis on the ethics. Responsible design and security must be baked into the foundation of how we build and guide AI systems, not something we duct-tape on at the end.
English
0
0
1
552
Security Rebel
Security Rebel@5m477·
Reality is getting blurrier by the day
English
0
0
0
97
Security Rebel retweetledi
Hacken🇺🇦
Hacken🇺🇦@hackenclub·
🤖 Hacken’s DevOps AI-Agent CTF is LIVE! Think you can outsmart an AI agent? Now’s your chance to prove it. Explore real AI agent attack surfaces. Solve red-team challenges. Compete for a $500 USDC prize. Whether you’re into offensive security or just curious about AI exploits – this one’s for you. ▫️ Capture the Flag until November 10 ▫️ Prize: 500 USDC ▫️ Hosted on: hackenlabs.com ▫️ Submit flags via: hackenlabs@proton.me 👉 Read the blog for full details and rules: hackenio.cc/ai-ctf Let the flag hunt begin.
Hacken🇺🇦 tweet media
English
13
10
71
12.1K
Security Rebel retweetledi
Alex Prompter
Alex Prompter@alex_prompter·
Holy shit. MIT just built an AI that can rewrite its own code to get smarter 🤯 It’s called SEAL (Self-Adapting Language Models). Instead of humans fine-tuning it, SEAL reads new info, rewrites it in its own words, and runs gradient updates on itself literally performing self-directed learning. The results? ✅ +40% boost in factual recall ✅ Outperforms GPT-4.1 using data it generated *itself* ✅ Learns new tasks without any human in the loop LLMs that finetune themselves are no longer sci-fi. We just entered the age of self-evolving models. Paper: jyopari. github. io/posts/seal
Alex Prompter tweet media
English
619
2.2K
11.5K
1M
Security Rebel retweetledi
ESET Research
ESET Research@ESETresearch·
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
ESET Research tweet media
English
57
662
2.7K
408.2K
Security Rebel retweetledi
Sherpa
Sherpa@LLMSherpa·
Novel jailbreak discovered. Not only does OpenAi putting your name in the system prompt impact the way GPT responds, but it also opens the model up to a prompt INSERTION. Not injection. You can insert a trigger into the actual system prompt, which makes it nigh indefensible.
Sherpa tweet mediaSherpa tweet media
English
71
225
4.3K
631.2K
Security Rebel retweetledi
Alex Prompter
Alex Prompter@alex_prompter·
I tested ChatGPT 5 and Grok 4 with same critical prompts. The results will blow your mind. ChatGPT 5 Vs. Grok 4 (Video demos are included)
Alex Prompter tweet media
English
275
1.2K
16.9K
5.9M
Security Rebel retweetledi
Michael Bargury
Michael Bargury@mbrg0·
we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge, reveal their tools and let us use them to dump full crm records these are autonomous agents.. no human in the loop #DEFCON #BHUSA @tamirishaysh
Michael Bargury tweet media
English
102
873
8.5K
1.2M
Security Rebel retweetledi
Civic
Civic@civickey·
Methodical input/output sanitization might just save your tech 🧼 Get into the nuances of AI safety with @5m477 --> youtu.be/9V80CCNjLOY
YouTube video
YouTube
English
2
3
6
858
Security Rebel retweetledi
Civic
Civic@civickey·
LLMs are the new attack surface 💣 Our latest podcast episode with @5m477 from @hackenclub goes deep into the hidden vulnerabilities in AI 🎥 Don’t build blind. Watch now. → youtu.be/9V80CCNjLOY
YouTube video
YouTube
Civic tweet media
English
2
3
10
1.2K
Security Rebel
Security Rebel@5m477·
Security iseveryone’s job.
If you're loading AI models, you're deploying software. Treat it like code from the internet, because it is.
English
0
0
0
46
Security Rebel
Security Rebel@5m477·
How to protect yourself:
Prefer safe formats like safetensors, ONNX, or GGUF
Never enable trust_remote_code unless you know what you're doing
Run new models in a sandbox first
Inspect scripts and loaders
Pin model versions and scan PRs
English
1
0
0
59
Security Rebel
Security Rebel@5m477·
If you're using Ollama, LLM Studio, or downloading .pt, .pkl, or .safetensors files this thread is for you. Here's how attackers can turn models into malware… and how to protect yourself: AI models aren't "just data" anymore.
English
1
0
1
110