Category: Mix

XSS via reportError
12
Oct
2023

XSS via reportError

reportError란 함수를 아시나요? Chrome 95, Firefox 93 버전에 추가된 글로벌 메소드로 JS의 uncaught exception을 콘솔이나 글로벌 이벤트 핸들러로 넘겨주는 기능을…

[tl;dr sec] #203 - Stealing CI/CD Secrets, Sliver & Cursed Chrome, Career Advice
12
Oct
2023

[tl;dr sec] #203 – Stealing CI/CD Secrets, Sliver & Cursed Chrome, Career Advice

My heart goes out to those facing violence, loss, and displacement. I hope there is a return to peace soon….

Extracted Wisdom Series: David Perell & Sam Parr
12
Oct
2023

Extracted Wisdom Series: David Perell & Sam Parr

Premium Content This content is reserved for premium subscribers of Unsupervised Learning Membership. To Access this and other great posts,…

Jailbreaking Humans vs Jailbreaking LLMs · Joseph Thacker
11
Oct
2023

Jailbreaking Humans vs Jailbreaking LLMs · Joseph Thacker

“Jailbreaking” an LLM and convincing it to tell you things it’s not supposed to is very similar to social engineering…

ZAP Map Local로 쉽게 Fake Response 만들기
09
Oct
2023

ZAP Map Local로 쉽게 Fake Response 만들기

보안 테스팅에선 HTTP Response를 자주 변경해야할 경우가 많습니다. 이럴 때 저는 보통 ZAP에선 breakpoint와 replace 기능, 그리고 스크립팅을 주로 사용했었습니다….

Israeli Footage & Analysis, WSFTP + MOVEIT, AI Explainability, Andreessen vs. Perell on Writing, and more…
09
Oct
2023

Israeli Footage & Analysis, WSFTP + MOVEIT, AI Explainability, Andreessen vs. Perell on Writing, and more…

Unsupervised Learning is a Security, AI, and Meaning-focused podcast that looks at how best to thrive as humans in a…

Spotlight on Injection
07
Oct
2023

Spotlight on Injection

Welcome to the 12th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…

Passing the New OSEE Exam After Forgetting Everything
07
Oct
2023

Passing the New OSEE Exam After Forgetting Everything

The Offensive Security Exploitation Expert (OSEE) certification is a legendary apex achievement among OffSec’s offerings, unabashedly featuring a skull logo…

Hackerone logo
06
Oct
2023

New SEC Cybersecurity Regulation: CISO Requirements & Recommendations

The rule requires public companies to report material cybersecurity incidents and annually report on elements of their cybersecurity risk management…

Extracted Wisdom Series: Marc Andreesen and David Perell
06
Oct
2023

Extracted Wisdom Series: Marc Andreesen and David Perell

Premium Content This content is reserved for premium subscribers of Unsupervised Learning Membership. To Access this and other great posts,…

[tl;dr sec] #202 - KubeHound, Supply Chain Security Vendor Landscape, CSPM Evaluation Matrix
05
Oct
2023

[tl;dr sec] #202 – KubeHound, Supply Chain Security Vendor Landscape, CSPM Evaluation Matrix

I hope you’ve been doing well! I’m thrilled to announce that Part 2 of Francis Odum’s supply chain security report…

Bug bounty DIY: The pros and cons of managing vulnerability disclosure in-house 
04
Oct
2023

Bug bounty DIY: The pros and cons of managing vulnerability disclosure in-house 

So you’ve decided that your business or organization should launch a bug bounty program, a great first step in taking…