kymb0

261 posts

kymb0 banner
kymb0

kymb0

@kymb0_irl

Honestly nothing really impressive is goin down here... Offensive Security + Polite Consultation https://t.co/2siS7W9CKu Bugcrowd top #100 Australia

Darwin, Northern Territory Katılım Haziran 2021
199 Takip Edilen314 Takipçiler
Sabitlenmiş Tweet
kymb0
kymb0@kymb0_irl·
A while ago I teased a tool I was working on which allows one to not only attack intentionally vulnerable LLM implementations, but also configure the defence stack and view the verdicts and tool calls in realtime. kymb0.github.io/LLM_Security_P…
English
1
1
6
518
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
Hey hackers! I’m seeing so many more hackers on my timeline since the algorithm update! We’re so back!
English
13
4
305
8.2K
kymb0 retweetledi
vx-underground
vx-underground@vxunderground·
HOLY. The two nerds from Scattered Spider got FIVE YEARS for profiting millions from ransomware and, most notably, ransoming critical infrastructure in the United Kingdom. Dawg, move to the UK and do cyber crime. It's basically legal there. They don't even extradite you
English
62
132
2.9K
95.6K
Kyriakos
Kyriakos@Kyriakos_Pelek·
@kymb0_irl Got a fallback plan if Claude hallucinates?
English
1
0
0
76
kymb0
kymb0@kymb0_irl·
No, outsourcing your brilliant multi-tenant app idea to Claude and then releasing it is NOT a good idea. Every LLM I test that has been clearly vibecoded has very similar cross-tenancy issues. Invest in proper code review and afford your dev and security team the resources they need to protect your users data.
English
9
1
8
382
kymb0
kymb0@kymb0_irl·
@akses_0x00 Xtenant read and write on file system and rag, as well as conversation thread foolery
English
0
0
1
28
ɐʞsǝs
ɐʞsǝs@akses_0x00·
@kymb0_irl What’s the most common cross tenant dumbness you’re seeing out there at the moment?
English
1
0
1
76
vx-underground
vx-underground@vxunderground·
Helping animals is cool and badass
English
27
35
460
17K
kymb0
kymb0@kymb0_irl·
@SchizoDuckie I thought this meant actual jail and I was like woah what's this guy gonna do when he gets out (I have no idea who they are)
English
0
0
1
11
kymb0
kymb0@kymb0_irl·
@hakluke Underrated post. Imagine paying for hacking education
English
0
0
0
196
Luke Stephens (hakluke)
Learning to hack in 2026 has never been easier. You literally have an all-knowing, ever-patient tutor that you can ask any questions to, free of charge. It's so outrageous.
English
12
9
134
9.3K
kymb0
kymb0@kymb0_irl·
@akses_0x00 "before you learn to build a house, understand how to lay bricks"
English
0
0
1
22
kymb0 retweetledi
ɐʞsǝs
ɐʞsǝs@akses_0x00·
Back in late January I found an exploitable cryptographic weakness in a zero trust networking product called pangolin[dot]net. If an attacker has knowledge of a Pangolin servers' creation time, it is possible to brute force the server's root secret in a relatively short amount. The secret is used for JWT signing, licence key signing and other cryptographic duties. Good news: it was addressed quickly by the pangolin team. If you installed 1.15.2+ then you are not affected. Bad news: there is some residual risk for any users who have since updated or not rotated their secrets. If you upgraded from 1.3.2-1.15.1 to a later version, you may be running the default weak secret. Best I can tell Pangolin have not notified all of their customers about any of this, so I guess I will have to. To be clear the risks are very niche and may not affect all users so be sure to read the write up in the thread for the nuances 👇 PoC || GTFO
English
5
5
33
5.9K
kymb0
kymb0@kymb0_irl·
ATTENTION: I HAVE DETERMINED THERE IS TOO MUCH AI MUMBO JUMBO FLOATING AROUND. So here is John Romero getting smooches from a good pupper while playing myhouse.wad. Comfy and wholesome af. That is all and have a good day. #doom @romero #pupper #dogsarebetterthancats
kymb0 tweet media
English
0
0
1
90
kymb0
kymb0@kymb0_irl·
"Trust me bro, MY ai-powered-llm-exploitation-scanner-doomsday-machine3000 isn't like all the others (but actually is because it leverages an LLM missing a cognitive layer). Source? trust me bro. Evidence? sure, please review this control scenario demonstrated in the microcosm"
English
0
1
3
107
kymb0
kymb0@kymb0_irl·
@hetmehtaa This was inevitable and will be witnessed with more providers.
English
0
0
0
304
kymb0
kymb0@kymb0_irl·
@shubham_srt @krishnsec Other than more ai doomsday hyperbole? Probably nothing. The natural progression for paid tools with active development is obviously to integrate LLMs and fine tune their own models.
English
0
0
0
93
K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵
writes authoritatively long post about AI. ends with “plan accordingly”. doesnt elaborate. thanks for the advice asshole
English
2
0
8
261
kymb0
kymb0@kymb0_irl·
@hakluke Only so you have more time to increase meme productivity.
English
0
0
1
12
kymb0
kymb0@kymb0_irl·
kymb0 tweet media
ZXX
1
1
3
588
kymb0
kymb0@kymb0_irl·
How I look at Claude when it doesn't build me the world's greatest CMS after I LITERALLY just told it that it was the world's greatest CMS developer. #ai #llm #security #cms #doorbell #dresdon
kymb0 tweet media
English
0
1
3
154
kymb0
kymb0@kymb0_irl·
@akses_0x00 So that is valid for llm-as-judge but openai-mod and local classifiers are essentially just classification endpoints, we'll link up and I'll show you.
English
1
0
1
29
ɐʞsǝs
ɐʞsǝs@akses_0x00·
Thanks! I will definitely explore this angle with CAST soon - thanks for giving me access to that. My concern is that the standard kind of sets up a recursive issue in this case, i.e. if you protect LLM A with LLM B, then the standard reads as though LLM B must also be protected by something
English
1
0
0
15
ɐʞsǝs
ɐʞsǝs@akses_0x00·
Name a single product that adequately prevents this
ɐʞsǝs tweet media
English
4
0
6
277