stefan avgoustakis

4.8K posts

stefan avgoustakis

stefan avgoustakis

@savgoust

Cloud Security stuff @Googlecloud | Opinions = mine

Sydney, New South Wales Katılım Ağustos 2008
2.9K Takip Edilen787 Takipçiler
stefan avgoustakis retweetledi
Royal Hansen
Royal Hansen@royalhansen·
"We have also seen research on AI platforms demonstrating more classic attacks against the underlying infrastructure like remote code execution via deserialization and lambda layers." @amlweems bughunters.google.com/blog/567986357…
English
0
4
19
1.8K
stefan avgoustakis retweetledi
Royal Hansen
Royal Hansen@royalhansen·
In the U.S., more than 21 million people fell victim to fraud last year, and 42% now say they’ve lost money or sensitive info to scams. Read about @Google’s tips and tools for avoiding scams online for whatever platform you use: blog.google/technology/saf…
English
0
1
3
375
stefan avgoustakis retweetledi
Google Cloud ANZ
Google Cloud ANZ@GoogleCloud_ANZ·
Keen to unlock some Google swag? ✨ Here are 3 ways to do so, when you join the Gen AI Study Jam. 1️⃣ Complete the Gemini learning path 2️⃣ Play Google Cloud Arcade games 3️⃣ Join a Trivia Challenge Find out more ➡️ goo.gle/4esea6P
Google Cloud ANZ tweet media
English
1
2
2
508
stefan avgoustakis retweetledi
Oliver Chang
Oliver Chang@halbecaf·
One week later the bug count is now at 25 bugs total (#bugs-discovered" target="_blank" rel="nofollow noopener">github.com/google/oss-fuz…) There's still many improvements to be made to improve success rate of generated targets, but we now have the problem of too many crashes to triage. Automating this will a focus of our future research.
Oliver Chang@halbecaf

This week we've added another 8 trophies to OSS-Fuzz-Gen (for a total of 14)! These are vulnerabilities found by LLM-generated harnesses. The interesting bit here is many of these are in well-fuzzed projects with thousands of hours of fuzzing already. #bugs-discovered" target="_blank" rel="nofollow noopener">github.com/google/oss-fuz…

English
1
10
46
6.6K
stefan avgoustakis retweetledi
RooCon
RooCon@RooCon_AU·
The #RooCon24 agenda is up on the website! We will have 11 captivating presentations that include representation from government, external private sector, and Google Threat Intelligence teams. We also have #RooCon24 t-shirts planned this year 👀 rsvp.withgoogle.com/events/roocon24
English
0
7
20
4.8K
stefan avgoustakis retweetledi
Jordi Mon Companys
Jordi Mon Companys@JordiMonPMM·
Yesterday we announced that our security advisory feed was being now published following the OSV schema. This was a herculean job by @danluhring and @comedordexis.
Jordi Mon Companys tweet media
English
1
4
7
1.5K
stefan avgoustakis retweetledi
Oliver Chang
Oliver Chang@halbecaf·
Second OSS-Fuzz blog post on fuzz harness generation for Java! blog.oss-fuzz.com/posts/introduc… We've been quiet for a while but have a few interesting posts coming in the pipeline about our research.
English
0
28
103
8.3K
stefan avgoustakis retweetledi
J. Passing
J. Passing@jpassing·
Just-in-Time Access 1.4 is out, introducing UI improvements, additional configuration options, and the ability to choose the duration for which to activate a role. github.com/GoogleCloudPla… #GoogleCloud #IAM
English
1
1
1
107
stefan avgoustakis retweetledi
Google Cloud ANZ
Google Cloud ANZ@GoogleCloud_ANZ·
Protecting your organisation's information 🔐? Let gen AI lend a helping hand. Join Shash Hedge, our Security Practice Lead, as he shares why security cannot be an after-thought, and how innovation from #GoogleCloud can supercharge security.
English
5
1
11
225K
stefan avgoustakis
stefan avgoustakis@savgoust·
Here is an idea ... don't run your production systems on an OS that requires high privilege or kernel access and shits itself each time some software agent goes rogue ...fix the cause so the symptoms are less impactful
Christopher Stanley@cstanley

This is a wake up reminder that you shouldn’t have an internet connected privileged binary running on your production systems. What was a bad update could have easily been a massive adversary backdoor. A third party vendor will always be the weakest link. Isolate critical systems

English
0
0
2
98
stefan avgoustakis
stefan avgoustakis@savgoust·
If 2024 isn't the year for Linux on the desktop it will never happen....
English
0
0
1
75
stefan avgoustakis
stefan avgoustakis@savgoust·
@evilsocket given your AI and security expertise, there might be a better fit in the security side of the team ... happy to reach out to the local EMEA director if you are interested
English
1
0
30
8.2K
Simone Margaritelli
Simone Margaritelli@evilsocket·
rejected by both Google and Cloudflare in less than 48h 🕺
English
45
30
1.8K
4.8M