March 2, 2024
March 2, 2024
Administrivia: good news, first section is with the editor. Bad news, next section is due March 3rd.
We published our in-depth analysis of the I-Soon leak. We detail their offerings, victimology and relationships with known APT activities:https://t.co/yDNG0oRpOk
— Ariel Jungheit (@ArielJT) March 1, 2024
The specter of .NET Remoting haunts unsuspecting ASP. NET applications even today, whispering valid ObjRefs to those who dare listen. Dive into our latest post to see how these apparitions can lead to remote code execution: https://t.co/MRyOANe2Vh
— CODE WHITE GmbH (@codewhitesec) February 27, 2024
ARM reversing and exploitation (@8kSec)https://t.co/bgcKhZHRXihttps://t.co/5wfe1djthThttps://t.co/BYfC90anxwhttps://t.co/ZjiYNmZkXEhttps://t.co/0mgg8B2bzPhttps://t.co/crBKanod1ihttps://t.co/CJ2jDl1YHVhttps://t.co/ZE0bLIRMolhttps://t.co/jsUeLrh2YChttps://t.co/unFsjyKvbT pic.twitter.com/uPTffwL2EQ
— 0xor0ne (@0xor0ne) March 1, 2024
At what point does a large scale ransomware incident that is affecting the ability of average Americans to get access to prescription drugs become a national emergency?
— Chris Bing (@Bing_Chris) March 1, 2024
As always it is a question of political will. Preemptively ceding national interest by inaction, thereby abdicating .gov responsibility to protect private sector & the population, has been the default decision for so long even proposing alternatives is deemed radical
— JD Work (@HostileSpectrum) March 1, 2024
Apologies to anyone who attended my Dune Experience. I was let down by suppliers at the last minute and I'm very sorry. pic.twitter.com/a9f8FRXudH
— Nick Mao (@NickMao42) February 29, 2024
Re-upping this paper on destructive cyber attacks on ICS systems enabled by AI. One researcher is tied to Zhejiang Labs, which hosts a cyber range I've tied to China's security services. https://t.co/9SfM72kjzg
— Dakota Cary (@DakotaInDC) March 1, 2024
#OnThisDay in #hacking #history, 1990, Secret Service raided offices of Steve Jackson Games, maker of roleplaying games.
— realhackhistory ۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗۗ (@realhackhistory) March 1, 2024
Two company employees were Erik Bloodaxe & The Mentor, at the time infamous hackers. The SS claimed a Cyberpunk roleplaying tabletop was a hacking tutorial. pic.twitter.com/Gzkym9QO2O
"Social Learning with Intrinsic Preferences", Fabian Dvorak, Urs Fischbacherhttps://t.co/PECP7IVd3p pic.twitter.com/EmXDJUhdHt
— Alberto Acerbi (@acerbialberto) March 2, 2024
#OpenNMS #Vulnerabilities: Securing Code against Attackers’ Unexpected Ways
— raptor@infosec.exchange (@0xdea) March 2, 2024
// by @SonarSource https://t.co/ZkmqgFiqnHhttps://t.co/PmT29LtyTU
🚀 Check out our 🆕 open-source network security monitor & traffic analysis tool suite, Malcolm v24.02.0! This update includes new features, improvements, and bug fixes. More at https://t.co/G0zMibsdhF
— CISA Cyber (@CISACyber) March 1, 2024
Who did this? pic.twitter.com/GlB2t3aq3t
— Daniel Fella Bonker (@DanielFellaBonk) March 1, 2024
I wrote up some speculative thoughts why memory safety could appear more urgent for the whitehouse than it does for an average tech developer working adjacent to or within infosechttps://t.co/qJiGOk4nw4
— Alex Rad (@defendtheworld) March 1, 2024
More than 50% of the reported reasoning abilities of LLMs might not be true reasoning.
— Saurabh Srivastava (@_saurabh) March 1, 2024
How do we evaluate models trained on the entire internet? I.e., what novel questions can we ask of something that has seen all written knowledge? Below: new eval, results, code, and paper.… pic.twitter.com/wy1mJQmun4
We are excited to share #OceanWatch, a new 40-minute film with mesmerizing #DeepSea footage from the ground-breaking discoveries on Research Vessel #FalkorToo in 2023. Made with the always amazing @naturalwfacts.
— Schmidt Ocean (@SchmidtOcean) March 1, 2024
Trailer attached, full video here: https://t.co/WmVHvE2KE1 pic.twitter.com/jTB9C0KelE
On LLMs, morality, and German military attire in my latest Substack post - "Gemini: how did we end up here?"https://t.co/teCMW85XZW
— lcamtuf (@lcamtuf@infosec.exchange) (@lcamtuf) March 2, 2024
the end of dune 2 went so hard pic.twitter.com/O7KNmHL0CH
— hannah gais (@hannahgais) March 2, 2024
I am thrilled to share our two preprints about attack and defense for LLM safety.
— Fenqing Jiang (@fengqing_jiang) February 20, 2024
🗡 ArtPrompt: https://t.co/s0u99D5GLL
🛡 SafeDecoding: https://t.co/C6dRHR12TT
Net als je denkt dat men de gevaren van digitale telecommunicatie een beetje beseft, schaft nota bene de minister van Veiligheid het luchtalarm af... https://t.co/6Z7JLQe74U
— Electrospaces (@electrospaces) March 2, 2024