Category: Mix

[tl;dr sec] #283 - Awesome Black Hat Tools, Evading EDR, Disrupting Malicious Uses of AI
12
Jun
2025

[tl;dr sec] #283 – Awesome Black Hat Tools, Evading EDR, Disrupting Malicious Uses of AI

Huge list of tools presented at various Black Hat conferences, how attackers evade modern EDR, OpenAI’s report on threat actor…

Rick Bohm on AI, Collaboration & API Security Future
12
Jun
2025

Rick Bohm on AI, Collaboration & API Security Future

Nestled in a log cabin high in the Rocky Mountains, Rick Bohm starts his day the same way he’s approached…

Security maturity, complexity, and bug bounty program effectiveness: A deep dive
10
Jun
2025

Security maturity, complexity, and bug bounty program effectiveness: A deep dive

There are three key elements that, when combined, support the planning of a bug bounty program to attract the right…

apple-google-ai
09
Jun
2025

Why Google I/O Scared This 2007 Apple Fanboy for the First Time

As an Apple Fanboy going back to 2007, this is the first year I’ve felt fear for Apple’s future. And…

This Is How They Tell Me Bug Bounty Ends · Joseph Thacker
09
Jun
2025

This Is How They Tell Me Bug Bounty Ends · Joseph Thacker

An AI agent will soon be able to find all the vulnerabilities in any application. Or that’s what they say….

09
Jun
2025

Hive Five 227 – Developers, Developers, Developers.

I made two new musical discoveries this week: Acid Bath and Ryo Fukui, exploring swamp metal and jazz. I also…

Opaque Thinking Machines
09
Jun
2025

The Chinese Room Problem With the ‘LLMs only predict the next token’ Argument

I’m sure you’ve heard the argument that LLMs aren’t really thinking because, according to them, LLMs are just predicting the…

Jwt-Hack: Reborn in Rust | HAHWUL
08
Jun
2025

Jwt-Hack: Reborn in Rust | HAHWUL

jwt-hack v2 is a complete Rust rewrite, boosting performance, safety, and stability. Back in October 2020, I created a tool…

DevSecOps | HAHWUL
08
Jun
2025

DevSecOps | HAHWUL

Roadmap for everyone who wants DevSecOps DevSecOps is a culture and practice that aims to integrate security into every phase…

JWT-HACK | HAHWUL
06
Jun
2025

JWT-HACK | HAHWUL

JSON Web Token Hack Toolkit # Cargo cargo install jwt-hack # Brew brew tap hahwul/jwt-hack brew install jwt-hack JWT-HACK is…

[tl;dr sec] #282 - Weaponizing Dependabot, Ultimate Guide to JWT Vulnerabilities, Multi-Agent Automated Vulnerability Discovery
05
Jun
2025

[tl;dr sec] #282 – Weaponizing Dependabot, Ultimate Guide to JWT Vulnerabilities, Multi-Agent Automated Vulnerability Discovery

Using Dependabot to merge malicious code and bypass branch protections, JWT attack guide with mitigations and labs, AI agents found…

Addressing API Security with NIST SP 800-228 — API Security
05
Jun
2025

Addressing API Security with NIST SP 800-228 — API Security

According to the Wallarm Q1 2025 ThreatStats report, 70% of all application attacks target APIs. The industry can no longer…