tmlxs

27 posts

tmlxs

tmlxs

@tmlxs

เข้าร่วม Temmuz 2013
29 กำลังติดตาม30 ผู้ติดตาม
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
In this cautionary tale of averting a large-scale supply chain attack, a follow-up to Kudelski Security researchers @tmlxs and @nathanhamiel’s Black Hat USA presentation, we detail our RCE on CodeRabbit’s production servers and write access to 1m repos. kdlski.co/4oIvuKs
Kudelski Security tweet media
English
1
5
21
9.5K
tmlxs รีทวีตแล้ว
Nathan Hamiel
Nathan Hamiel@nathanhamiel·
Here is our detailed write-up of the CodeRabbit vulnerability, one of the vulnerabilities @tmlxs and I highlighted in our @blackhatevents USA presentation. This is the one where we had access to a million repositories. We show how to go from PR to RCE. A patient attacker could have turned this into a large-scale supply chain attack. One of the things we wanted to demonstrate is that finding vulnerabilities in real-world AI-powered applications is just as much, if not more, about understanding the underlying systems and tools that the AI components are interacting with. If you don’t understand these, then you will miss things no matter how many prompt injections you supposedly have. We hope you find this useful. Link to post, in comment.
Nathan Hamiel tweet media
English
3
7
32
6.3K
tmlxs รีทวีตแล้ว
Abhishek Arya
Abhishek Arya@infernosec·
Glad to see our AI-powered fuzzing work inspire research community to try this on Rust targets successfully ($3, 14 bugs, 34 fuzzers in 37 projects). Wait on some of our new results on Gemini! research.kudelskisecurity.com/2023/12/07/int…
English
0
20
46
6.5K
tmlxs รีทวีตแล้ว
Nathan Hamiel
Nathan Hamiel@nathanhamiel·
Introducing Fuzzomatic. A Python based fuzzer for Rust that uses AI assistance, allowing for completely from scratch fuzzing. Fuzzomatic has a few tricks up its sleeve, too. It can perform fixes and parse various artifacts to generate fuzz targets. research.kudelskisecurity.com/2023/12/07/int…
Nathan Hamiel tweet media
English
0
2
3
368
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
The @KudelskiSec Research Team discovered a novel attack on ECDSA that they call Polynonce and applied it to datasets like Bitcoin and Ethereum networks. Are private jets in their future? Details and open-source tools to test the attack here: kdlski.co/3kIc7p2
Kudelski Security tweet media
English
2
9
17
4.5K
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
Based on their presentation at @sstic, Kudelski Security’s Sylvain Pelissier and Nils Amiet latest blog post covers GPG and whether it resists memory forensics. Read more: kdlski.co/3Oh3eMb
English
1
5
6
0
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
It's now possible to detect and fix security issues with Semgrep’s Autofix feature as long as the rule that matched is autofix-capable. Check out some real-world examples in Kudelski Security Nils Amiet’s latest blog post: kdlski.co/3qlraFf #semgrep #autofix #securityissues
English
0
2
5
0
tmlxs รีทวีตแล้ว
Immunefi
Immunefi@immunefi·
It's always a rarity when we find a really good manual on smart contract hacking. Today, we have such a manual for you! 👉 dl.acm.org/doi/fullHtml/1… - Blockchain Vulnerabilities in Practice.
English
0
11
36
0
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
Today we released oramfs, a simple, flexible, Free Software ORAM implementation for Linux written in Rust hubs.ly/H0Rj2hj0 Join us on Wednesday July 7th at 4:10pm CEST when we present oramfs at #pts21 #Linux #OpenSource
English
0
7
6
0
tmlxs รีทวีตแล้ว
Kudelski Security
Kudelski Security@KudelskiSec·
#DifferentialPrivacy provides a measurable way to balance privacy & data accuracy when publicly releasing aggregate data on private datasets. @KudelskiSec’s Nils Amiet’s latest blog is a hands-on, applied, comparison of several popular libraries hubs.ly/H0nwj1M0
English
0
1
1
0