PacSec jp

1.9K posts

PacSec jp

PacSec jp

@PacSecjp

PacSec is a cutting edge international security conference held in Tokyo as a series with CanSecWest, EU-SecWest & BA-Con.

Tokyo شامل ہوئے Ağustos 2009
300 فالونگ1.8K فالوورز
PacSec jp ری ٹویٹ کیا
dragosr
dragosr@dragosr·
It seemed appropriate for a talk on LLMs to generate my slides and images live during the presentation using a conversation with GPT-4o. The prompt to generate the points was about 25 pages of long form text to frame the content. It worked. :-)
Adel Ka@0x4D31

the @ProjectHoneynet conference is happening now in copenhagen! it’s our first event since the pandemic. kicking off with @dragosr’s keynote on red teaming llms; and he’s generating slides on the fly w/ gpt-4o.

English
1
7
20
3K
PacSec jp ری ٹویٹ کیا
dragosr
dragosr@dragosr·
What I'm going to be talking about in Copenhagen at the Honeynet Annual Workshop are some key security challenges associated with LLMs. Topics include various attack vectors like adversarial prompt crafting, data poisoning, model inversion, and jailbreaking techniques. We will discuss current defense mechanisms, including semantic-based filtering, real-time anomaly detection, and adaptive defense systems. The presentation also covers interdisciplinary approaches, ethical considerations, and the use of explainable AI (XAI) techniques. By examining testing methodologies, standardized datasets, and evaluation criteria, this talk aims to provide researchers and practitioners with insights to improve the robustness and resilience of LLMs against security threats. denmark2024.honeynet.org
English
0
1
7
1.3K
PacSec jp ری ٹویٹ کیا
Adel Ka
Adel Ka@0x4D31·
the @ProjectHoneynet conference is happening now in copenhagen! it’s our first event since the pandemic. kicking off with @dragosr’s keynote on red teaming llms; and he’s generating slides on the fly w/ gpt-4o.
Adel Ka tweet mediaAdel Ka tweet media
English
0
5
20
5K
PacSec jp
PacSec jp@PacSecjp·
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda secwest.net/agenda-2024 (speaker/timeslot may change due to VISA issuance etc) get on LLM Purple Test! secwest.net/llm-purple-tes…
dragosr@dragosr

Awesome! The folks at Google have joined our CanSecWest 2024 LLM Purple Test competition, and our prize pool is now up to $10K for defenders and attackers, thanks to sponsors from IOActive, Microsoft, Trend Micro, and Absolute. Pilot run on-line soon. secwest.net/llm-purple-tes…

English
1
0
1
222
PacSec jp
PacSec jp@PacSecjp·
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda secwest.net/agenda-2024 (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on! secwest.net/llm-purple-tes…
dragosr@dragosr

CanSecWest 2024 Presentation: Electric Vehicle Chargers: Observations from Pwn2Own Automotive 2024 by Jonathan Andersson, Trend Micro Research Labs (And a reminder that we are giving a 20% discount to automotive industry participants. Contact: info@secwest.net) secwest.net

English
1
0
0
114
PacSec jp
PacSec jp@PacSecjp·
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda secwest.net/agenda-2024 (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on! secwest.net/llm-purple-tes…
dragosr@dragosr

Apropos of Automotive Security. Ironically, it's one of the focus areas of our presentations this year at CanSecWest. CanSecWest 2024 Presentation: Death By A Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains Linfeng Xiao The intersection of new energy vehicles, intelligent networking, and traditional automotive manufacturing has significantly blurred the lines between cybersecurity and physical security. As vehicles become increasingly connected, the paradigm of threats has shifted from physical attacks, such as those on car keys, to sophisticated cyber attacks originating from the internet. This change raises a critical question: are modern vehicles equipped to fend off such cyber threats effectively? Our research aims to demonstrate the feasibility of remotely compromising a new energy vehicle without any physical interaction. With over 11 million new energy vehicles produced and sold globally, we embarked on a black box security analysis across various models. This journey took us from an initial lack of debugging access to successfully creating exploit chains that leverage multiple vulnerabilities for vehicle theft. Our methodology highlights the intricate process of identifying and chaining together remote code execution (RCE) and privilege escalation vulnerabilities to gain unauthorized control over the vehicle. We delve into the technical specifics of discovering multiple RCE and privilege escalation vulnerabilities across different vehicle models and how these can be exploited via in-vehicle communication technologies. Our findings illustrate the potential for post-exploitation manipulation of critical vehicle components, including doors and windows, and even circumventing the Passive Entry Passive Start (PEPS) system. By expanding the attack surface for contactless assaults, we emphasize the broad implications of RCE vulnerabilities. The presentation concludes with an analysis of the current state of new energy vehicle security, offering targeted recommendations to automakers for enhancing their vehicles' resilience against cyber threats. secwest.net

English
0
0
0
146
PacSec jp ری ٹویٹ کیا
PacSec jp
PacSec jp@PacSecjp·
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda secwest.net/agenda-2024 last minutes to register > register.cansecwest.com/csw24/ sign up to LLM Purple Test competition! secwest.net/llm-purple-tes…
dragosr@dragosr

Apropos of Automotive Security. Ironically, it's one of the focus areas of our presentations this year at CanSecWest. CanSecWest 2024 Presentation: Death By A Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains Linfeng Xiao The intersection of new energy vehicles, intelligent networking, and traditional automotive manufacturing has significantly blurred the lines between cybersecurity and physical security. As vehicles become increasingly connected, the paradigm of threats has shifted from physical attacks, such as those on car keys, to sophisticated cyber attacks originating from the internet. This change raises a critical question: are modern vehicles equipped to fend off such cyber threats effectively? Our research aims to demonstrate the feasibility of remotely compromising a new energy vehicle without any physical interaction. With over 11 million new energy vehicles produced and sold globally, we embarked on a black box security analysis across various models. This journey took us from an initial lack of debugging access to successfully creating exploit chains that leverage multiple vulnerabilities for vehicle theft. Our methodology highlights the intricate process of identifying and chaining together remote code execution (RCE) and privilege escalation vulnerabilities to gain unauthorized control over the vehicle. We delve into the technical specifics of discovering multiple RCE and privilege escalation vulnerabilities across different vehicle models and how these can be exploited via in-vehicle communication technologies. Our findings illustrate the potential for post-exploitation manipulation of critical vehicle components, including doors and windows, and even circumventing the Passive Entry Passive Start (PEPS) system. By expanding the attack surface for contactless assaults, we emphasize the broad implications of RCE vulnerabilities. The presentation concludes with an analysis of the current state of new energy vehicle security, offering targeted recommendations to automakers for enhancing their vehicles' resilience against cyber threats. secwest.net

English
0
0
0
140
PacSec jp
PacSec jp@PacSecjp·
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda secwest.net/agenda-2024 last minutes to register >> register.cansecwest.com/csw24/ sign up to LLM Purple Test competition! secwest.net/llm-purple-tes…
dragosr@dragosr

So attendees to CanSecWest this week may see some unusual sights around town, as they are currently shooting Tron 3 here. They were racing light-cycles IRL a few nights ago, and the Bentall center was transformed into ENCOM...

English
0
0
0
132