Elli Shlomo

5.4K posts

Elli Shlomo banner
Elli Shlomo

Elli Shlomo

@ellishlomo

Security Researcher

Katılım Şubat 2012
64 Takip Edilen4.1K Takipçiler
Elli Shlomo retweetledi
Claude
Claude@claudeai·
Introducing Claude Opus 4.8: it builds on Opus 4.7 with sharper judgment, more honesty about its own progress, and the ability to work independently for longer than its predecessors. Available today at the same price.
Claude tweet media
English
3.6K
8.7K
67.1K
14.6M
Elli Shlomo
Elli Shlomo@ellishlomo·
Are we only one step from the AlphGo moment? An update on Project Glasswing, plus some fresh evaluation results from Mythos Preview. One of the capabilities that has been focused on since the very first tests is exploitation. This is an area where Mythos is a change over previous models and the latest results clearly back that up.
Anthropic@AnthropicAI

Last month we launched Project Glasswing, our collaborative AI cybersecurity initiative. Since then, we and our partners have found more than ten thousand high- or critical-severity vulnerabilities in essential software.

English
0
0
2
423
Elli Shlomo retweetledi
Nagli
Nagli@galnagli·
New "Critical" nginx RCE requires LFI as prereq and has 0 practical exploitation odds - CVEs & CVSS are the biggest slop in security and AI just keeps accelerating it
English
9
24
227
16.5K
Elli Shlomo
Elli Shlomo@ellishlomo·
Another day of Hands-on keyboard attack with MDE
Elli Shlomo tweet media
English
0
2
16
3K
Elli Shlomo
Elli Shlomo@ellishlomo·
I love middleware, whether it’s in the cloud, AI systems, or anywhere else. AI desktop tools introduce many forms of middleware, and some of the examples mentioned in this article focus on the Claude desktop app on macOS, including its bridges and intermediary components that are not built in by default. cyberdom.blog/the-ai-middlew…
English
0
1
3
641
Elli Shlomo
Elli Shlomo@ellishlomo·
Someone at Microsoft definitely got paid by the character. 1️⃣ The Heavyweight Champion (144 Characters) New-MgIdentityAuthenticationEventFlowAsOnGraphAPreAttributeCollectionExternalUserSelfServiceSignUpAttributeIdentityUserFlowAttributeByRefYes. It manages user attributes during external B2C sign-ups. One typo here and you’ve completely broken your customer onboarding flow. 2️⃣ The PIM Time-Bomb New-MgRoleManagementDirectoryRoleAssignmentScheduleRequest Only 65 characters, but easily the most dangerous. Accidentally tab completion to Assignment instead of Eligibility, and congratulations. You just granted a user permanent, active Global Admin rights, bypassing MFA and approval workflows. 3️⃣ The Data Exfiltrator Remove-MgExternalConnectionInformationProtectionLabelAssignment (118 characters). This drops security/sensitivity labels from 3rd-party data connectors (like ServiceNow). Run this in a cleanup script, and your encrypted corporate data is suddenly sitting exposed in the cloud. 4️⃣ The Race-Condition Nightmare: New-MgOnlineMeetingOnlineMeetingLiveShareHostedPresentation (90 characters). Handles advanced Teams meeting features. It’s notorious for API race conditions, so if your script triggers this a millisecond before the backend finishes provisioning the meeting object, it crashes with a cryptic 404. Save your keyboard and your sanity and stop using these autogenerated monstrosities. Drop down to raw API calls using a clean Invoke-MgGraphRequest. Your scripts will be shorter, faster, and far less likely to cause a self-inflicted incident.
English
0
1
6
573
Elli Shlomo retweetledi
bugcrowd
bugcrowd@Bugcrowd·
Don't be this guy
bugcrowd tweet media
English
16
20
337
12.4K
Dr. Anton Chuvakin
Dr. Anton Chuvakin@anton_chuvakin·
"If your security strategy relies on a sysadmin logging into a server to run apt-get upgrade on a Tuesday morning, you aren't running a modern security program; you’re running a historical reenactment society." #overheard
English
15
20
141
31K
Elli Shlomo retweetledi
Anthropic
Anthropic@AnthropicAI·
Our security bug bounty program is now public on HackerOne. We've run the program privately within the security research community, and their findings have strengthened our products. Now anyone can report vulnerabilities and get rewarded. Read more: hackerone.com/anthropic
English
221
530
4.5K
939.2K
Elli Shlomo retweetledi
Guardz
Guardz@GuardzCyber·
🚀 The 2026 State of MSP Threat Report breaks down how threats are evolving across RMM, identity, endpoints, and AI-powered attack paths, with real data from the field and clear patterns MSPs can actually act on. okt.to/gA7CcP #MSP #Cybersecurity #ThreatReport
Guardz tweet media
English
0
1
1
190
Elli Shlomo
Elli Shlomo@ellishlomo·
GPT-5.5 just dropped and raises the bar for automated attacks and pentesting. Stronger vuln discovery, better white and black box performance, and sharper decision making, all at the application layer. It goes deeper into logic, wastes less time on basics, and focuses on complex issues like auth bypass, privilege escalation, and business logic flaws. Still, gaps remain, app context is limited, and benchmarks are biased toward known targets. What is tested is proven, and the rest is gray.
XBOW@Xbow

Anthropic’s Mythos raised the bar for AI vuln detection but kept it invite-only. GPT-5.5 is OpenAI’s answer, and it’s open to all. We had early access. Ran the benchmarks. Blackbox GPT-5.5 already beats whitebox GPT-5. Best pentesting model we’ve tested. Read our analysis: bit.ly/48OX7v6

English
0
0
0
399
Elli Shlomo retweetledi
Guardz
Guardz@GuardzCyber·
No exploit, no malware, no noise, just a compromised OAuth integration with enough access to slip straight into Vercel’s environment and expose what shouldn’t be exposed. Reach more! okt.to/BQ1wyV
Guardz tweet media
English
0
1
1
296
Elli Shlomo
Elli Shlomo@ellishlomo·
Once I saw it, I told myself, "If it were truly that powerful, it should have stopped its own breach," and then I remembered the very old quote, "No one is immune."
English
0
0
0
168
Elli Shlomo
Elli Shlomo@ellishlomo·
😈Everything started with an AI app, even the breach. Another breach has surfaced (this time, Vercel), and once again, the root cause points to OAuth. guardz.com/blog/vercel-da…
English
0
1
3
226
Elli Shlomo
Elli Shlomo@ellishlomo·
From random input to device takeover 😈 One technique in a basic scam bypasses email security, fools detection tools, and grants attackers full device control. guardz.com/blog/from-keyb…
English
0
0
1
257