Securing Bits

743 posts

Securing Bits banner
Securing Bits

Securing Bits

@securing_bits

I explain application security using comic art.

Katılım Nisan 2023
515 Takip Edilen612 Takipçiler
𝕡𝕨𝕟.𝕋∅𝕔𝕙!
Appreciate the replies and shares on the Pwn2Own Berlin 2026 notes. A bunch of you have been asking about Chompie @chompie1337 and her Day 1 wins. She pulled off two solid ones: a single-bug pwn on the NVIDIA Container Toolkit for 50k dollars, plus a race condition privilege escalation on Red Hat Enterprise Linux for Workstations that got her another 20k. I am thinking about starting a short series on stuff like “how targets get cracked like Chompie did it”, walking through the techniques that showed up in her demos and pointing to practice challenges on the same platforms we covered before (pwn.college for race conditions and kernel stuff, Exploit Education VMs, or the binary tracks on Pwnable.kr). What part of her pwns interests you most? The NVIDIA container one, the Red Hat race condition, or just general tips on getting into that level of research? Drop it below and I will kick the series off based on what you all say. If you missed the full notes I'll drop the link in the comments. #Pwn2Own #P2OBerlin #CyberSecurity
English
3
6
81
5.1K
antirez
antirez@antirez·
Read @fchollet book to understand the discipline foundations. Write a few neutral networks from scratch, without a framework: training and inference. Then read LLM papers, and use LLMs to fill the gaps if you understand you don't have certain knowledge. DeepSeek R0 paper is particularly important for RL. Have fun.
English
1
1
10
437
antirez
antirez@antirez·
If you se DwarfStar with CUDA, update to latest main branch. It contains a correctness fix for attention. Now the long context test passes.
English
3
3
81
9.6K
Critical Thinking - Bug Bounty Podcast
We did a 10h long live Hackalong session on Discord and found a few bugs! Here are some of the cool stuff we learned from it
English
3
7
138
6.6K
Securing Bits
Securing Bits@securing_bits·
I hope you've found this thread helpful. Follow me here @securing_bits or on Linkedin linkedin.com/in/vasilikos-p… for more, and if you enjoy my content make sure to subscribe to my weekly free newsletter at securingbits.com/newsletter. Like/Repost the quote below if you can:
Securing Bits@securing_bits

Building your next LLM integration? Beware of Indirect Prompt Injection vulnerability. Previous models like GPT4 and Bing have been affected. #llm #applicationsecurity #chatgpt

English
0
0
0
82
Securing Bits
Securing Bits@securing_bits·
Learn more about indirect prompt injections from the paper 'Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection' Link: arxiv.org/pdf/2302.12173
English
1
0
0
85
Securing Bits
Securing Bits@securing_bits·
Building your next LLM integration? Beware of Indirect Prompt Injection vulnerability. Previous models like GPT4 and Bing have been affected. #llm #applicationsecurity #chatgpt
Securing Bits tweet media
English
1
2
2
385
Securing Bits
Securing Bits@securing_bits·
I hope you've found this thread helpful. Follow me here @securing_bits or on Linkedin linkedin.com/in/vasilikos-p… for more, and if you enjoy my content make sure to subscribe to my weekly free newsletter at securingbits.com/newsletter. Like/Repost the quote below if you can:
Securing Bits@securing_bits

HTTP Response Headers: Usage 🛠 and Security Abuse ☠. Those complement the HTTP Request Headers we saw last week :) #websecurity #bugbounty #bugbountytips

English
0
0
0
81
Securing Bits
Securing Bits@securing_bits·
@sephr @ABouhoula @AmitZac1 I haven’t checked their methodology either, just trusting the reputation of the conference which involves peer review already .
English
1
0
0
22
🕊
🕊@sephr·
@securing_bits @ABouhoula @AmitZac1 I'm unsure about the reliability of their methodology. I can't determine if the crawler was also in the EU and set up to accurately represent an EU citizen. I requested the code on April 17, 2024, to peer review this study. I never received a response. @ABouhoula @AmitZac1
English
2
0
0
66
Securing Bits
Securing Bits@securing_bits·
Recent research conducted by ETH reveals that 65.4% of the most visited websites in the EU offer a cookie rejection option, yet they could still potentially gather user data even after users explicitly reject their cookies. 🕵️‍♂️ Is privacy compliance so difficult? #privacy #gdpr
Securing Bits tweet media
English
1
0
1
170
Securing Bits
Securing Bits@securing_bits·
I hope you've found this thread helpful. Follow me here @securing_bits or on Linkedin linkedin.com/in/vasilikos-p… for more, and if you enjoy my content make sure to subscribe to my weekly free newsletter at securingbits.com/newsletter. Like/Repost the quote below if you can:
Securing Bits@securing_bits

Guard your LLM against prompt injection with these powerful tools: - github.com/protectai/llm-… - github.com/protectai/rebu… - github.com/NVIDIA/NeMo-Gu… - github.com/amoffat/Heimda… - github.com/guardrails-ai/… - github.com/whylabs/langkit #AI #MachineLearning #LLM #Security 🛡️🔒

English
0
0
0
44
Securing Bits
Securing Bits@securing_bits·
I hope you've found this thread helpful. Follow me here @securing_bits or on Linkedin linkedin.com/in/vasilikos-p… for more, and if you enjoy my content make sure to subscribe to my weekly free newsletter at securingbits.com/newsletter. Like/Repost the quote below if you can:
Securing Bits@securing_bits

What could go wrong during the ML model development lifecycle (Part 2) ? Example threat model based on the talk "Kubernetes MLSec: Securing AI in Space" by @d1gital_f and James Callaghan of @controlplaneio at @CloudNativeFdn. #ai #machinelearning #security

English
0
0
0
28