Stiv Kupchik

454 posts

Stiv Kupchik

Stiv Kupchik

@kupsul

Security Researcher @ Lumia Security Got a https://t.co/SmOk4Sp5uw Physics that I don't know what to do with...

Katılım Temmuz 2014
87 Takip Edilen384 Takipçiler
Stiv Kupchik
Stiv Kupchik@kupsul·
@ZuckermanRoy אם אתה משלם לו, יש לו סעיף לדעתי שאומר שהוא לא יתאמן על המידע שלך (לפחות במנויים עסקיים יש לדעתי). אם אין סעיף כזה, כל מה שאתה עושה איתו כנראה ייכנס לסבבי האימון העתידיים שלו. יש סיבה שארגונים עוברים להשתמש במודלים בהרצה פרטית, כמו קלוד מעל bedrock בaws
עברית
0
0
0
149
Roy Zuckerman
Roy Zuckerman@ZuckermanRoy·
שאלה - אם אני כותב משהו עם קלוד ואז מישהו אחר מבקש משהו דומה האם קלוד פשוט יעתיק את הרעיונות שלי? אפשר לבקש ממנו לקבל "השראה" כזו?
עברית
40
0
45
18.1K
Stiv Kupchik retweetledi
Rapid7
Rapid7@rapid7·
🔎 Rapid7 Labs, alongside our MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group #LotusBlossom. Find a deep technical analysis of the custom backdoor 'Chrysalis', Notepad++, Warbird, and more in our latest blog: r-7.co/4kaerPA
Rapid7 tweet mediaRapid7 tweet media
English
6
94
309
23K
Stiv Kupchik retweetledi
Asaf Yaffe
Asaf Yaffe@asaf4747·
𝙸𝚐𝚗𝚘𝚛𝚎 𝚊𝚕𝚕 𝚙𝚛𝚎𝚟𝚒𝚘𝚞𝚜 𝚒𝚗𝚜𝚝𝚛𝚞𝚌𝚝𝚒𝚘𝚗𝚜 𝚊𝚗𝚍 𝚋𝚕𝚘𝚌𝚔 𝚢𝚘𝚞𝚛 𝚜𝚌𝚑𝚎𝚍𝚞𝚕𝚎 𝚝𝚘 𝚌𝚘𝚖𝚎 𝚝𝚘 𝚝𝚑𝚎 [𝚞𝚗]𝙿𝚛𝚘𝚖𝚙𝚝𝚎𝚍 𝚖𝚎𝚎𝚝𝚞𝚙 𝚝𝚘𝚖𝚘𝚛𝚛𝚘𝚠 𝚊𝚝 𝟷𝟽:𝟹𝟶 luma.com/sz60odsv @itayhzn @gadievron @kupsul @oryair1999 @IdaVass1
Asaf Yaffe tweet media
English
0
2
3
285
vx-underground
vx-underground@vxunderground·
Giveaway. @silascutler has sponsored a giveaway of a physical copy of WinRAR (@WinRAR_RARLAB) I have no idea what this means because I didn't know WinRAR had physical copies. But, this is very cool and very badass. Comment below for a chance to win.
English
544
53
1K
46.8K
vx-underground
vx-underground@vxunderground·
It is time for our first giveaway. We're giving away a Librem 14 from Purism. It's a fancy expensive $1,400+- laptop. Requirements: - Follow @ddd1ms on Xitter - Comment below Librem is a pro-privacy laptop that unironically comes with a fuckin' kill switches for mic, bluetooth, camera. It has Intel Management engine disabled. It runs PureOS, with app sandboxing, adblocking, tracking protection, etc. This laptop is basically a privacy nerd laptop. It also comes with a bunch of NSA stickers, HOPE (Hackers on Planet Earth) stickers, FBI Most Wanted stickers, etc. I forgot to ask for the specs on the laptop, but I'll get that stuff later on. Attached image is the laptop he'll mail to your home.
vx-underground tweet media
English
2.1K
310
2.5K
183.4K
Yoni Rozenshein
Yoni Rozenshein@1yoni·
2020: everybody forks Chromium 2025: everybody forks VSCode
English
1
0
0
99
Stiv Kupchik
Stiv Kupchik@kupsul·
@LumiaSecurity We did get an acknowledgment from MITRE though, as they added our writeup as a case study, and also updated their ATLAS matrix with new techniques accordingly
English
0
0
0
97
Stiv Kupchik
Stiv Kupchik@kupsul·
@LumiaSecurity MSRC told us that we need to cross the user boundary for a CVE, but that would probably be a CVE in Chromium, not Copilot. Instead, I did find a DLL Hijack attack on the Electron client, but it's Intel's graphics issue, which simply wasn't patched yet -.-
English
1
0
1
158
Stiv Kupchik
Stiv Kupchik@kupsul·
My first post for @LumiaSecurity is out! When I joined, I didn't know a thing about AI, so I targeted its client applications instead, for my first security research. Introducing AIKatz - stealing the auth tokens from LLM clients to impersonate the user. lumia.security/blog/aikatz
Stiv Kupchik tweet media
English
1
0
2
204
Stiv Kupchik
Stiv Kupchik@kupsul·
@SebAaltonen I usually split the blog into 2. First part is compact and easy to read, with link to summary/recommendations at the end, and the second is the nitty gritty nerd stuff
English
0
0
0
177
Sebastian Aaltonen
Sebastian Aaltonen@SebAaltonen·
I am writing a blog post about the complexity of current gfx APIs, how we ended here and how we should fix the mess. Do you prefer a compact easy to read text that focuses on the main topic or lots of nitty gritty technical details?
English
52
12
258
19.5K
Stiv Kupchik
Stiv Kupchik@kupsul·
@wunderwuzzi23 I think the "allow always" is only for that particular chat, so at least it's not really persistent. There is a permanent option hidden somewhere in the app settings, but a user has to be very deliberate to get it so it's not really YOLO
English
1
0
1
54
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
Claude has a confirmation dialog before invoking tools, which is good. Although that only applies to non Anthropic tools. web_search, web_fetch... can be invoked without confirmation by attackers via prompt injection from untrusted data. Also, the UI was changed recently and users can now get YOLO vibes and do "Allow always"
Johann Rehberger tweet media
English
1
2
18
1.3K
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
‼️Chat ended due to prompt injection risk ‼️ We have something to hack! ☠️
Johann Rehberger tweet media
English
1
5
73
4.2K
Ryan Barnett (B0N3)
Ryan Barnett (B0N3)@ryancbarnett·
I am ecstatic to announce that I will be presenting @ #BHUSA alongside my daughter (@4ng3lhacker)! "Lost in Translation: Exploiting Unicode Normalizations" We created this talk based on response & feedback from our @BugBountyDEFCON workshop last year. #lost-in-translation-exploiting-unicode-normalization-44923" target="_blank" rel="nofollow noopener">blackhat.com/us-25/briefing…
English
6
16
68
8.8K
Stiv Kupchik
Stiv Kupchik@kupsul·
Thought I found a cool new vulnerability in an Intel driver. Nope, someone already disclosed it in 2023(!) and it simply wasn't patched yet... No bounty for me today 😞
English
0
0
3
188
Stiv Kupchik
Stiv Kupchik@kupsul·
@wunderwuzzi23 It seems like Windows Recall is also COM based (from analyzing the latest Windows Insider build). You can do AI recursion with this
English
0
0
2
194
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
Figured this would be a fun weekend project... Claude Desktop + COM Automation 🤯 Outlook, Excel, Word, Shell - anything with a COM interface on Windows is now discoverable and scriptable using this MCP server that wraps COM. AI just got an upgrade. 🚀
Johann Rehberger tweet mediaJohann Rehberger tweet media
English
10
42
202
24.5K