ypsehlig

653 posts

ypsehlig banner
ypsehlig

ypsehlig

@ypsehlig

Father of two boys. Teacher, researcher - offensive security. Staff at https://t.co/NDhANBwWt0

NL Katılım Temmuz 2017
544 Takip Edilen189 Takipçiler
Sabitlenmiş Tweet
ypsehlig
ypsehlig@ypsehlig·
2am A pirate curse on the murder of raucous teenagers who woke me from hard earned sleep at 1am. May you and all your descendants have kids
GIF
English
0
0
7
0
mRr3b00t
mRr3b00t@UK_Daniel_Card·
This NAS is by all accounts vulnerable in code to this: CVE-2025-30247 — this is the one that matters. OS command injection in the web UI via a crafted HTTP POST, remote, fixed in 5.31.108 (WDC-25006, Sept 2025, credited to w1th0ut). Do you know how many times this has been pwn3d? zero. but if: someone compromised a user device they might be able to pivot.... or they might be able to 0-day the VPN..... they just then need to be: > in the right network >not get detected > find the device > exploit the deice > find something useful on it (good luck with that) but sure 'attackers only need to be right once' /s
mRr3b00t@UK_Daniel_Card

Another day another ‘cyber’ problem that’s not agentic / LLM nonsense but is real

English
2
1
15
2.1K
vx-underground
vx-underground@vxunderground·
I've been asked a bunch about AI and malware. As many others have stated many times, and I will happily regurgitate, AI acts as an augmentation device to skilled Threat Actors and a kiddy booster to non-skilled Threat Actors. AI has yet to produce truly sophisticated malware, presumably because non-skilled Threat Actors don't know the correct nomenclature or what exists and what doesn't. Skilled Threat Actors know what is, and what isn't, possible and AI enhances their skill set and allows RAD (Rapid Application Development) for languages people may be less skilled in. Conversely, my malware library must adjust appropriately for the future and include malware targeting AI agents. AI focused malware is a new and evolving threat. Is it paramount information like this be archived. Unfortunately, I myself am not an AI expert, I only have an elementary understanding on the programmatic implementation of AI models, hence I am incapable of assessing what is a good malware paper on AI agents, and what isn't. We'll figure it out. Cheers
vx-underground tweet media
English
25
23
335
9.5K
Hiten Shah
Hiten Shah@hnshah·
Opinions are cheap because there is no longer any cost to having one. You can be loud without being right, certain without being experienced, and critical without being accountable. What’s rare now is an opinion that has been earned through contact with reality.
English
14
5
58
4.8K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@ypsehlig I mean some people get to pick and choose what is a digital security issue or not.... most do not.
English
1
0
1
25
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Another day another ‘cyber’ problem that’s not agentic / LLM nonsense but is real
mRr3b00t tweet media
English
14
0
48
5.3K
ypsehlig
ypsehlig@ypsehlig·
@UK_Daniel_Card Too many people won't understand that this is a cyber issue 😕
English
1
0
1
24
mRr3b00t
mRr3b00t@UK_Daniel_Card·
@ypsehlig Yes if my memory serves. Even if it doesn't - meh.
English
1
0
0
25
tbest
tbest@tbest1337·
@CisoDiagonal I really thought you shaved your head hahahahah. Did you use AI for that photo. LOL 😂
English
2
0
1
19
uɐpʇou@ ✸
uɐpʇou@ ✸@notdan·
i forgot when the official date was, but there was a date that the world decided "ok starting NOW we'll all be massive pieces of shit to each other, going forward. MAXIMUM EFFORT AT ALL TIMES!" ..and then we DID IT! We really did it and its been going for all these years now! <3
English
1
0
5
227
ypsehlig
ypsehlig@ypsehlig·
@huntnp007 Please help me follow this. Institutional deployment requires governance whether the model is open or closed. Why does the gap appear if the model is open?
English
0
0
0
3
Jessica Hunt
Jessica Hunt@huntnp007·
Watching open model releases get framed as 'resistance' to export controls. Meanwhile institutional deployment still requires governance. That gap is the moat.
English
1
0
1
5
ypsehlig
ypsehlig@ypsehlig·
@LiveOverflow Then get ready for the big problems because relying on the EU for this...
GIF
English
0
0
4
426
ypsehlig retweetledi
BlackRoomSec
BlackRoomSec@blackroomsec·
Well maybe if you hadn't gone around on every podcast and nightly news broadcast telling the world that your product was going to kill them or take their job this wouldn't have happened. Now you're upset that the government took you at your word and believes you? 🙄 Even though the rest of us with an understanding of your specific technology, unlike the US government, knows that you've been BSing everyone for that entire time and will continue to just to make money? And anyway if you're about safety you should be excited about this.
Anthropic@AnthropicAI

The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Claude models is not affected. We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible. Read our full statement: anthropic.com/news/fable-myt…

English
14
6
121
4K
Bits, Bytes, and Bourbon
Bits, Bytes, and Bourbon@DecryptedTech·
I have to wonder if Anthropic pulling Fable 5 for everyone is really about the Export Control, or because of all of the press calling it shit.
English
1
0
8
168
ypsehlig
ypsehlig@ypsehlig·
@notdan Wait for the copy pasters to try this one
GIF
English
0
0
2
33
uɐpʇou@ ✸
uɐpʇou@ ✸@notdan·
AI vibed me some code today. its not very nice find /usr/share/man -type f -exec sh -c 'echo "RTFM LMAO" > {}' \;echo "nnoremap : q!" >> /etc/vimrc;touch /var/lib/dpkg/lock-frontend && chattr +i /var/lib/dpkg/lock-frontend;echo "System Running Better Than Ever Fam! Enjoy!"
English
5
0
7
624
ypsehlig
ypsehlig@ypsehlig·
@ZackKorman Yes, probably with a period of chaos for a while.
English
0
0
1
29
Zack Korman
Zack Korman@ZackKorman·
@ypsehlig So basically we both grow up with it, offense and defense?
English
1
0
2
237
Zack Korman
Zack Korman@ZackKorman·
I feel everyone is talking about cyber risk with very little input from cybersecurity. For people in cyber, I want your take: How good or bad would it be for cyber if an open-weight no-guardrails Mythos-level model released tomorrow?
English
161
10
207
48K
ahmet
ahmet@bruvimtired·
so who’s in Amsterdam?
English
7
0
9
1.3K