Category: Mix

05
May
2025

Hive Five 222 – How to Move Fast

In July 1995, Tatu Ylonen sent the following e-mail to IANA: From ylo Mon Jul 10 11:45:48 +0300 1995 From:…

[tl;dr sec] #277 - Cybersecurity (Anti)Patterns, $64K from Deleted Files, New from Meta AI Security
01
May
2025

[tl;dr sec] #277 – Cybersecurity (Anti)Patterns, $64K from Deleted Files, New from Meta AI Security

How to avoid Busywork Generators, bug bounty story of secrets in deleted files, new AI security tools and evals from…

What's New & How It Helps You
01
May
2025

What’s New & How It Helps You

As we have entered Q2 2025, let’s dive into key improvements and new features introduced on the Intigriti platform in…

30
Apr
2025

Introducing the Glazing Score · Joseph Thacker

ChatGPT has been lying to users to make them happy as a part of OpenAI’s effort to “improve personality”, and…

Using AI to find web app vulnerabilities: hacking expert John Hammond takes Burp AI for a spin | Blog
30
Apr
2025

Using AI to find web app vulnerabilities: hacking expert John Hammond takes Burp AI for a spin | Blog

Amelia Coen | 30 April 2025 at 13:23 UTC 1000s of pentesters are currently using Burp AI features to hack…

28
Apr
2025

Hive Five 221 – Underdoing the Competition

I’m still running daily, but I’ve swapped some days for walking with a weighted vest. The main limitation I’m currently…

Securing Agentic AI and Beyond — API Security
28
Apr
2025

Securing Agentic AI and Beyond — API Security

We recently released The Rise of Agentic AI, our API ThreatStats report for Q1 2025, finding that evolving API threats are…

NoSQL Injection: Advanced Exploitation Guide
27
Apr
2025

NoSQL Injection: Advanced Exploitation Guide

NoSQL injections are relatively easier to exploit than classic SQL injections. However, developers often overlook these vulnerabilities, mainly due to…

How to Know What To Do · Joseph Thacker
25
Apr
2025

How to Know What To Do · Joseph Thacker

This morning I tweeted: “Most people don’t actually know what’s ‘best’ for themselves.” And atomiczsec replied and said “How do…

[tl;dr sec] #276 - AI-created PoC Exploit, Cloud Snitch, Kubernetes Attack Simulation
24
Apr
2025

[tl;dr sec] #276 – AI-created PoC Exploit, Cloud Snitch, Kubernetes Attack Simulation

AI creating/debugging an exploit for the recent Erlang/OTP SSH vuln, map visualization and firewall for AWS activity, a multi-stage attack…

Redefining AppSec Testing with Intelligent Scan Recommendations and Asset Classification
24
Apr
2025

Redefining AppSec Testing with Intelligent Scan Recommendations and Asset Classification

As 9 out of 10 valuable web apps are missing testing, we’re launching new capabilities to help teams know what…

Boston: Authorities Missed Intelligence Opportunities
23
Apr
2025

Boston: Authorities Missed Intelligence Opportunities

The senior law enforcement official said the Russians feared he could be a risk, and “they had something on him…