Category: Mix

The Prompt Injection Primer · rez0
25
Aug
2023

The Prompt Injection Primer · rez0

Bringing clarity to questions about Prompt Injection Security Everyone loves talking about prompt injection, but the real impact to an…

Act Now to Prepare for New NCUA Cyber Incident Reporting Requirements
24
Aug
2023

Act Now to Prepare for New NCUA Cyber Incident Reporting Requirements

We recently discussed the new SEC rule requiring all registered companies to report material cyber incidents within four (4) days….

[tl;dr sec] #196 - How Secrets Leak in CI/CD, AI Threat Modeling, Supply Chain
24
Aug
2023

[tl;dr sec] #196 – How Secrets Leak in CI/CD, AI Threat Modeling, Supply Chain

I hope you’ve been doing well! What We’re Known For It’s long had a place in my heart, as I…

What Happens to Content When Top-Tier Presentation is Commoditized?
24
Aug
2023

What Happens to Content When Top-Tier Presentation is Commoditized?

I think AI is about to massively improve the quality of our best content. But not for the reason you…

Thoughts on the Eliezer vs. Hotz AI Safety Debate
24
Aug
2023

Thoughts on the Eliezer vs. Hotz AI Safety Debate

The debate was quite fun to watch, but also frustrating. What irked me about the debate—and all similar debates—is that…

Punicoder – discover domains that are phishing you – honoki
23
Aug
2023

Punicoder – discover domains that are phishing you – honoki

So we’re seeing homograph attacks again. Examples show how ‘apple.com’ and ‘epic.com’ can be mimicked by the use of Internationalized…

Buy me a coffee
23
Aug
2023

RCE in Slanger, a Ruby implementation of Pusher – honoki

While researching a web application last February, I learned about Slanger, an open source server implementation of Pusher. In this…

Bug Bytes #208 – Burp gets an update, Sharefile gets a CVE and JavaScript files get analysed
23
Aug
2023

Bug Bytes #209 – The only graphQL wordlist you need, ML bug hunting and VDP submissions

Bug Bytes is a weekly newsletter curated by members of the bug bounty community. The second series is curated by…

I’ve Got You Under My Skin, Bill Evans Solo Transcription – honoki
23
Aug
2023

I’ve Got You Under My Skin, Bill Evans Solo Transcription – honoki

Download my transcription of Bill Evans’ piano solo in I’ve Got You Under My Skin below. The solo starts around…

Burp ♥ OpenVPN – honoki
23
Aug
2023

Burp ♥ OpenVPN – honoki

When performing security tests, you will often be required to send all of your traffic through a VPN. If you…

architectuur, balkon, brandtrap
23
Aug
2023

XXE-scape through the front door: circumventing the firewall with HTTP request smuggling

In this write-up, I want to share a cool way in which I was able to bypass firewall limitations that…

how I bruteforced my way into your Active Directory – honoki
23
Aug
2023

how I bruteforced my way into your Active Directory – honoki

Last May, I discovered that a critical vulnerability I had reported earlier this year had resulted in my first CVE….