Category: Mix

Hackerone logo
08
Aug
2023

10 LLM Vulnerabilities and How to Establish LLM Security [OWASP]

LLM01: Prompt Injection What Is Prompt Injection? One of the most commonly discussed LLM vulnerabilities, Prompt Injection is a vulnerability…

High-Entropy Writing
07
Aug
2023

High-Entropy Writing

I read a post by Derek Sivers recently that reminded me of Claude Shannon’s concept of Entropy. The post was…

API2:2023 Broken Authentication
05
Aug
2023

API2:2023 Broken Authentication

Welcome to the 3rd post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…

Hackerone logo
03
Aug
2023

Company Update | HackerOne

HackerOne CEO, Marten Mickos, emailed the following note to employees on August 2, 2023. H1 Team, I have made the painful…

[tl;dr sec] #193 - ATT&CK for AI and SaaS, GitHub Actions Goat, Finding Bugs in Web App Routes
03
Aug
2023

[tl;dr sec] #193 – ATT&CK for AI and SaaS, GitHub Actions Goat, Finding Bugs in Web App Routes

I hope you’ve been doing well! Hack Week This week we had people fly in from all over the world…

Hello Noir 👋🏼
02
Aug
2023

Hello Noir 👋🏼

Hi all! I am excited to announce the release of my toy project called ‘Noir’ 🎉🚀 Noir is a source…

Beware of BOLA (IDOR) Vulnerabilities in Web Apps and APIs
02
Aug
2023

Beware of BOLA (IDOR) Vulnerabilities in Web Apps and APIs

Introduction In a recent advisory, the Cybersecurity and Infrastructure Security Agency (CISA) warned vendors, designers, developers, and end-user organizations of…

Ranged bounties: a flexible and granular bounty mechanism 
01
Aug
2023

Ranged bounties: a flexible and granular bounty mechanism 

At Intigriti, we are continually enhancing our platform to better serve our community. Today, we’re introducing a significant update: ranged…

Can LLMs create new things? · rez0
01
Aug
2023

Can LLMs create new things? · rez0

Is Generative AI Output Novel Creation or Simple Imitation? I’ve heard many people say that LLMs (and generative AI overall)…

Unsupervised Learning NO. 392
31
Jul
2023

Unsupervised Learning NO. 392

Unsupervised Learning is a Security, AI, and Meaning-focused podcast that looks at how best to thrive as humans in a…

Optimizing ZAP and Burp with JVM
31
Jul
2023

Optimizing ZAP and Burp with JVM

누군가가 저에게 Application Security, Pentest 등에서 가장 활발하게 사용되는 도구를 선택하라고 하면 당연히 Burpsuite와 ZAP 같은 Proxy 도구를 선택할 것…

Do Burnout and Addition Have the Same Root Cause?
31
Jul
2023

Do Burnout and Addition Have the Same Root Cause?

I heard a great thing on a podcast recently. It was a guy saying alcohol addiction is confused because people…