Dhruv AHUJA

@new23d.bsky.social

Making network egress filtering effective, reliable and usable. Founder & Chief Engineer at @chasersystems.bsky.social Blog: https://www.new23d.com/

Proxy-less outbound traffic filtering is way easier to introduce into a network and adopt. ~90% of our customers have been able to achieve secure #egress.

Chaser Systems@chasersystems.bsky.social · 5d ago

For agent sandboxes needing domain-based #egress filtering on outbound traffic «without» TLS termination, #DiscrimiNAT OTF offers policy discovery, and SNI spoofing prevention. DNS spoofing and abuse of shared IPs on CDNs won't work thru it. Search in cloud console: DiscrimiNAT

Mandiant's analysis of ShinyHunters' Oracle Peoplesoft exploitation leans heavily on patching, monitoring, hunting and auditing. "restricting them from public internet access" is under Reduce Exposure but an impractical advice on prevention. OS updates,🧵 cloud.google.com/blog/topics/...

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft | Google Cloud Blog

This follow-up report details how UNC6240 (ShinyHunters) is mass-exploiting Oracle PeopleSoft (CVE-2026-35273) by bypassing WAF rules via a single URL-encoded character, providing full analysis of the...

cloud.google.com

Is «intent» the posh word for «vibe-check»? I pray for these startups. No wait, I pray for their customers. Security is architecture, and not a probabilistic gate - which can generate false positives and false negatives, both. "Yes, you're right. I was wrong earlier." 🤖

"Part of the problem is that we’ve become sceptical of acquired taste and have lost much of the vocabulary with which to talk about aesthetic experience as a serious end in itself. There was 🧵 Superb piece in the FT today "Want to resist the AI bros? Play the piano". www.ft.com/content/5055...

Want to resist the AI bros? Play the piano

In an age in which all activities must be optimised, there is something rare about devoting yourself to something that cannot be turned into content

ft.com

Docker containers, VMs, etc at 'run' time in Prod envs should just start, and not install deps (incl monitoring tools) at boot. Those tasks are for 'build' time. Helps with outbound traffic filtering domain lists as well since unlikely you'll need api·github·com in Production!

Anyone worried about, or scared of "machine speed" attacks probably hasn't spent any time babysitting an LLM vulnerability discovery and/or verification pipeline. ;-P

I first thought of getting a ham radio licence during '20-21😷. Never got around to it even though I bought the study guides then. Passed the Foundation Level last week and today was issued a callsign, M7XIT, by Ofcom to transmit at 25W. Don't have a transceiver so don't CQ yet🫠

Bild

eval'ed gpt-5.6-luna & deepseek-v4-flash-0731 vs my prev fav mimo-v2.5-pro today. gpt preferred using python for tool calling & subtasks; the others bash/gnu cli. gpt also had a greater breadth of understanding the natural language. gpt-5.6-luna is my new fav for a few days!

Does anybody know an illustrator/graphics designer who can tweak and convert AI-generated two sticker ideas I have to print-ready? Theme is computer circuits, LCD screens and a bit retro Windows 95 dialog boxes. Need this done asap, really. Preferably Cambridge/London based.

This isn't a reason to be complacent. We're working on an Agentic Defence Assurance and Product Integrity Testing (ADAPT) harness to continually challenge our assumptions and discover new evasions. More to be released in a few weeks on that. Outbound Traffic Inspection (OTF)...

Chaser Systems@chasersystems.bsky.social · 2mo ago

Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI & HuggingFace incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact in our demo, we show these attacks being caught. #2 is SNI spoofing, btw huggingface.co/blog/agent-i...

"security systems architecture experts" TIL about MITRE D3FEND: Detection, Denial, and Disruption Framework Empowering Network Defense. It's updated quarterly and useful to map "defensive cybersecurity techniques" to TTPs. Nice one. d3fend.mitre.org

MITRE D3FEND Knowledge Graph

D3FEND is a knowledge base of cybersecurity countermeasure techniques. In the simplest sense, it is a catalog of defensive cybersecurity techniques and their relationships to offensive/adversary techn...

d3fend.mitre.org

Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1]. "Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance" They seem to 1/3

VPC Endpoint Bucket Policies are completely ineffectual in preventing exfiltration if the workload has access to the Internet. Just upload to the $otherCloud's storage endpoint. This is where #egress filtering at the NAT gateway layer prevents a compromise.

Interestingly, in Salesforce, IP ranges security is only applied at login time at Org or User Profile/Session levels by default. Once the token is issued post login, it can be used outside of the IP ranges perimeter. Unless one ticks ✅ the additional 1/2

There is a computational, time and environmental cost to #PQC in TLS... Google enabled it server-side on Feb 12 and any OpenSSL v3.5+ or Go crypto/tls v1.24+ client since then is sending ~1200 bytes of additional session key data than before. This takes the TCP packet of the 1/4