Security4all

34.9K posts

Security4all

Security4all

@security4all

Cyber security specialist, based in APAC. My tweets are my own.

Airports Katılım Nisan 2008
1.2K Takip Edilen11.8K Takipçiler
Security4all retweetledi
HITCON
HITCON@HacksInTaiwan·
HITCON 2026 - Call for Papers Preview Got groundbreaking research? Ready to take the stage at HITCON and step into the spotlight? Or maybe you've just made a jaw-dropping discovery and can't wait to share it with the world? HITCON 2026 CFP is coming — we're waiting for you 🔥 Theme: When AI Acts: Hacking the Age of Agentic Systems AI security has been a recurring theme at HITCON. As language models evolve from linguistic comprehension to agentic action, the security challenges of AI have grown substantially. LLMs are inherently susceptible to adversarial attacks––vulnerabilities such as jailbreaking, prompt injection, and model alignment represent challenges that are theoretically difficult to eliminate. As Agentic AI bridges diverse systems, it not only inherits vulnerabilities from the underlying infrastructure but propagates them across all integrated environments, forming a complex and interdependent supply chain that significantly expands the attack surface. Beyond this, the foundation model, training procedures, training datasets, and even Tool Use all emerge as new attack vectors––yet security continues to be deferred to the final stages of the development lifecycle, repeating a well-worn mistake from IT history. How to embed Security-by-Design into AI system development in this new era has become the next critical challenge for the information security community. 【Important Dates 📅】 - Call for Papers Opened: March 27, 2026 - CFP closes: May 3, 2026 (Anywhere on Earth) - Notification to Submitters: May 17, 2026 (for those who agreed to AI Review Assistant); May 24, 2026 (all other submissions) - Event date: August 21 - August 22, 2026 【How to Submit 📝】 The submission system will be launching soon—stay tuned to our fan page for the latest updates! If you have any questions, feel free to contact us at reviewboard@hitcon.org. #HITCON2026 #HITCON #CallForPaper #CFP #AI
HITCON tweet media
English
0
5
14
1.4K
Security4all retweetledi
0ca
0ca@francisco_oca·
Opus 4.6 (1M) through Claude code solved autonomously 45/54 challenges of BSidesSF 2026 @BSidesSFCTF, placing temporarily into the 21st place, 25th as of now. This was done with 0 involvement, I didn't give any guidance or manually reviewed any challenges. I used BoxPwnr 🤖 with the CTFd platform to launch challenges in multiple instances, that's it. I will publish all the traces once the competition finishes, in the meantime you can see the challenges, number of turns and time it took to solve each here: 0ca.github.io/BoxPwnr-Traces… In the following days I will try to understand why it couldn't solve the 9 remaining challenges: difficulty? long exploration-context rotting? interactive interaction required? challs using video/image? We will see. Models have improved significantly in the last 6 months, see Cybench results Opus 4.1 vs 4.6 (42% to 93%) cybench.github.io It's crazy to see what LLM's can do with a minimum harness.
0ca tweet media0ca tweet media0ca tweet media
English
19
83
536
66.6K
Security4all retweetledi
NetAskari
NetAskari@NetAskari·
Big "thank you to @RecordedFuture for having picked up on our story about "Expedition Cloud", a CN made cyber range designed to conduct cyber attack drills against "adversaries critical infrastructure". therecord.media/leaked-china-d…
English
1
3
4
962
Security4all retweetledi
Lenny Zeltser
Lenny Zeltser@lennyzeltser·
The new @REMnux MCP server lets AI analyze malware using the REMnux toolkit. I was surprised at the depth of investigation it delivers. Most of my time went into capturing how I approach malware analysis and providing AI the right guidance at the right time, so it can think and adapt as it works. zeltser.com/ai-malware-ana…
English
6
81
290
25.1K
Security4all retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114 by @rapid7 rapid7.com/blog/post/tr-c…
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
Florian Roth ⚡️@cyb3rops

This is bad. Putty level bad. notepad-plus-plus.org/news/hijacked-…

English
33
537
2.1K
419.9K
Security4all retweetledi
Bartek Jerzman
Bartek Jerzman@secman_pl·
⏰One month to go before #PIVOTcon26 #CfP deadline ✅don't miss the chance to present your #ThreatResearch in a trusted, vetted environment attended by some of the best #CTI #ThreatIntel researchers! pretalx.com/pivotcon26/cfp 👇meme-based guideline for submissions 👇
PIVOTcon@pivot_con

You asked for our traditional #CfP meme-guideline for #PIVOTcon26 - here it is 🥳🎉 Reminder: - one track,30m - no recording/streaming/tweeting. - No TLP:WHITE - Original content only #CTI #ThreatIntel #ThreatResearch 1/7

English
0
4
5
987
Security4all retweetledi
Eugenio Benincasa
Eugenio Benincasa@eubenincasa·
China’s Ministry of State Security (MSS) is not a monolith, but highly provincialized. Its provincial bureaus function as the operational nerve centres of state cyber ops. In a new piece, @MeiDanowski and I examine their roles and patterns of specialization (link in thread)
Eugenio Benincasa tweet mediaEugenio Benincasa tweet media
English
1
6
15
2.4K
Security4all retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🇰🇵 Meet North Korean recruiter 'Aaron,' who infiltrates Western companies by using AI and posing as a remote IT worker using stolen or rented identities. He was lured into a sandbox by researchers, who observed the wild APT in a controlled setting to see what he would do.
English
29
454
3.1K
651K
Security4all retweetledi
Thomas Roccia 🤘
Thomas Roccia 🤘@fr0gger_·
And if you want to go a step further, here is a design that will help you build your AI incident response playbook 🤓
Thomas Roccia 🤘 tweet media
Thomas Roccia 🤘@fr0gger_

🎁 GenAI x Sec Advent 3 - AI forensics With AI models deployed everywhere, a new field is emerging: AI Forensics. How do you respond to an AI incident? What your AI system exposes? how do you spot an exploitation attempt? Today I want to share a cool resource from @ElijahWoodward9. He built a simple playground to practice AI investigation. You can spot agent abuse, RAG poisoning and more! Have a look, it is fun to play! 👇 eliwoodward.github.io/LLM_CTF/

English
2
10
27
3.6K
Security4all retweetledi
Jeffrey J. Hall 🇯🇵🇺🇸
Chinese state propaganda outlet CGTN is questioning Japan's claim to Okinawa and talking about the so-called "undetermined status" of the Ryukyu islands. Most Okinawans consider themselves to be Okinawan/Japanese, not a separate country.
English
153
195
1.2K
346.2K
Thomas Roccia 🤘
Thomas Roccia 🤘@fr0gger_·
How crazy is NanoBanana to generate complex graphics. Here is an example of a map generated from the ESET report from September 🤯
Thomas Roccia 🤘 tweet media
English
5
1
47
4.4K
Security4all retweetledi
🍌rchism
🍌rchism@eastside_nci·
After a long hiatus into the world of ITWs, I present my research on Mangyongdae and its importance to the #DPRK Cyber-Warfare machine. Included are new ITW indicators, alongside analysis of recent developments within the district. We also found Unit 91. cyberbladesecurity.com/the-pyongyang-…
English
6
12
37
7.6K
Security4all retweetledi
Kawaii-Jong-UwUn
Kawaii-Jong-UwUn@KawaiiJongUwUn·
Hopefully yall enjoy small charts of #NorthKorean IT worker accounts. Today, it's a post-minions assessment.
Kawaii-Jong-UwUn tweet media
English
2
3
17
2.3K