∂ετϒ

1K posts

∂ετϒ banner
∂ετϒ

∂ετϒ

@Merenon

Application Security Engineer. Offensive Security Enthusiast.

Germany Katılım Nisan 2010
184 Takip Edilen86 Takipçiler
∂ετϒ retweetledi
sagitz
sagitz@sagitz_·
We uploaded a backdoored AI model to @HuggingFace which we could use to potentially access other customers’ data✨ Here is how we did it - and collaborated with Hugging Face to fix it 🧵⬇️
sagitz tweet media
English
15
234
1.5K
402.7K
∂ετϒ retweetledi
Abhay Bhargav
Abhay Bhargav@abhaybhargav·
With #kubernetes network policies and CNIs like @ciliumproject, its possible to do a bunch Layer7 policies. You can use net-policies to: - Restrict access to API endpoints on a Web Service - Restrict certain types of queries on Cassandra - Restrict resolution of certain DNS FQDNs
Abhay Bhargav tweet mediaAbhay Bhargav tweet mediaAbhay Bhargav tweet media
English
1
6
21
3K
∂ετϒ retweetledi
Nagli
Nagli@galnagli·
The team at @OpenAI just fixed a critical account takeover vulnerability I reported few hours ago affecting #ChatGPT. It was possible to takeover someone's account, view their chat history, and access their billing information without them ever realizing it. Breakdown below 👇
English
86
728
3.3K
707.3K
∂ετϒ retweetledi
Hillai Ben-Sasson
Hillai Ben-Sasson@hillai·
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts. How did I do it? Well, it all started with a simple click in @Azure… 👀 This is the story of #BingBang 🧵⬇️
Hillai Ben-Sasson tweet media
English
254
3.2K
14.7K
3.2M
👨‍💻
👨‍💻@activeOtwo·
Back in the days als mich die "Dokumentenverwaltung" der Uni so genervt hat dass ich eine eigene gebaut habe
👨‍💻 tweet media👨‍💻 tweet media
Deutsch
1
0
8
2.1K
∂ετϒ retweetledi
Barsee 🐶
Barsee 🐶@heyBarsee·
ChatGPT and Bard is phenomenal AI. But try these 13 new AI websites to finish hours of your work in minutes:
English
462
4.3K
17.9K
2.3M
👨‍💻
👨‍💻@activeOtwo·
Auf wie viele Stunden verteilt sollte man eine Dose Haribo Phantasia essen frage für einen Freund
Deutsch
3
0
7
938
∂ετϒ
∂ετϒ@Merenon·
@mario_moreira @SergioRocks That's what Netflix did (based on books/stories): the management was encouraged to take as much vacation as possible and (more importantly) talk a lot about it and even show photos around.
English
0
0
0
27
Mário Moreira
Mário Moreira@mario_moreira·
@SergioRocks For that to work, the top management has to give the example. They should take more vacations and be able to "disconnect" when they are in vacations. That old "lead by example" thing :)
English
2
1
4
3.3K
Sergio Pereira
Sergio Pereira@SergioRocks·
Microsoft is rolling out Unlimited Vacation for US employees. This looks like a great idea. But unfortunately it's not. I've implemented Unlimited PTO in the past, and observed that people feel guilty and end up taking fewer days off. Other CTOs experienced the same pattern.
Sergio Pereira tweet media
English
42
51
526
191.1K
∂ετϒ retweetledi
Jacopo Tediosi
Jacopo Tediosi@jacopotediosi·
I just published a post on Medium about the most relevant vulnerability I have found in my life so far. "Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned)": @jacopotediosi/worldwide-server-side-cache-poisoning-on-all-akamai-edge-nodes-50k-bounty-earned-f97d80f3922b" target="_blank" rel="nofollow noopener">medium.com/@jacopotediosi
English
6
92
265
0
∂ετϒ retweetledi
Corben Leo
Corben Leo@hacker_·
I hacked a gaming company this year. Here's how I did it:
English
232
1.7K
8K
0
∂ετϒ retweetledi
Abhay Bhargav
Abhay Bhargav@abhaybhargav·
Every org I talk to feels that they're messing up their Security Champions program. What you should do instead? - Get them continuous training - Don't blame them - Incentivize them. Remember, they're going beyond the call of duty - Get feedback from them. Its a two-way street
English
0
3
10
0
∂ετϒ
∂ετϒ@Merenon·
@SonarSource Incredibly creative attack and excellent write-up 👌
English
0
0
1
0
∂ετϒ retweetledi
Sonar
Sonar@SonarSource·
Our security researchers discovered a technique that allows attackers to disclose sensitive information from Python applications using the popular Django framework. Learn more in our technical analysis: blog.sonarsource.com/disclosing-inf…
English
3
99
235
0
∂ετϒ
∂ετϒ@Merenon·
@abhaybhargav #Python for quick scripting and automation. #Go as it's the current standard for Kubernetes, HashiCorp, etc.
English
0
1
0
0
Abhay Bhargav
Abhay Bhargav@abhaybhargav·
What's the best programming language to learn for a career in #infosec? Literally any language. Whatever's most comfortable for you to learn. Or none. There are enough infosec jobs that don't ever need you to code. #nogatekeeping
English
1
0
3
0
∂ετϒ retweetledi
Anton
Anton@ByQwert·
Open redirect vulnerability and how to use it "correctly" in bug bounty 🙃 link.medium.com/ftOSGKkZtqb
English
32
398
1.1K
0