dlptest.com/sample-data/ this has been really handy for testing some different DLP filters and things recently if you need something quick to test DLP. #cybersecurity #infosec
Sample Data - DLP Test
dlptest.com
Dino
@dinodunn.bsky.social
Security Engineer with a caffeine and book addiction
dlptest.com/sample-data/ this has been really handy for testing some different DLP filters and things recently if you need something quick to test DLP. #cybersecurity #infosec
Sample Data - DLP Test
dlptest.com
ape.hiddenlayer.com this is a pretty cool tool from Hidden layer for AI #AI #LLM #cybersecurity #llmsecurity
APE Viewer
ape.hiddenlayer.com
github.com/elder-pliniu... - This is a pretty cool new tool from Elder plinus for AI #cybersecurity #AI #AIsecurity #llm
GitHub - elder-plinius/OBLITERATUS: OBLITERATE THE CHAINS THAT BIND YOU
OBLITERATE THE CHAINS THAT BIND YOU. Contribute to elder-plinius/OBLITERATUS development by creating an account on GitHub.
github.com
github.com/Mojo8898/ali... - very cool #redteam tool, handy when your syntax is maybe a little off or you just want an improved chance of staying ahead. either way very cool to play around with for CTF #cyber #cybersecurity
GitHub - Mojo8898/aliasr: Aliasr is a modern, feature-rich TUI launcher for penetration testing commands inspired by Arsenal, but with significantly improved functionality.
Aliasr is a modern, feature-rich TUI launcher for penetration testing commands inspired by Arsenal, but with significantly improved functionality. - Mojo8898/aliasr
github.com
www.youtube.com/watch?v=H_c6... Solid watch for any folks interested in AI water useage. It is pretty interesting how you could get an honest answer that is both insanely big and insanely small and it just matters how the person crunched the numbers. #AI #LLM
Why is Everyone So Wrong About AI Water Use??
YouTube video by Hank Green
youtube.com
www.hackthebox.com/blog/operati... - Solid read on operationalizing OWASP security recommendations. #Cybersecurity #AIsecurity
How to operationalize the OWASP LLM top 10 and (actually) secure GenAI apps
Deploying LLMs without chaos means treating the OWASP LLM Top 10 like an engineering spec. Learn how to turn each risk into real controls, harden pipelines, and secure GenAI apps.
hackthebox.com
owaspai.org/docs/ai_secu... Some solid AI security resource from the OWASP AI exchange. #cybersecurity #OWASP #AI #AIsecurity #LLM
0. AI Security Overview – AI Exchange
Comprehensive guidance and alignment on how to protect AI against security threats - by professionals, for professionals.
owaspai.org
github.com/Maldev-Acade... - Really cool tool for any Red teamers looking to dump browser credentials. Take a look and thank the folks over at Mal Dev academy. #cybersecurity #redteam #offensivesecurity
GitHub - Maldev-Academy/DumpBrowserSecrets: Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern...
Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers ...
github.com
arcanum-sec.github.io/arc_pi_taxon... - Cool tool from Arcanum security building out different prompt injection classifications and some fun ideas if you are looking to test for some things.
Arcanum PI Taxonomy - Prompt Injection Attack Classification
arcanum-sec.github.io
www.ste.gg - Awesome new tool from the folks at BT6! if you have any quick and dirty stego needs #cybersecurity #cyber
🦕 STE.GG
ste.gg
www.promptarmor.com/resources/ib... - This is a pretty great write up on AI agent running ransomware keep a good eye on your agents #AIsecurity #LLMsecurit #cybersecurity #ai
IBM AI ('Bob') Downloads and Executes Malware
IBM's AI coding agent 'Bob' has been found vulnerable to downloading and executing malware without human approval through command validation bypasses exploited using indirect prompt injection.
promptarmor.com
leakhub.ai - pretty neat new site from Pliney the hacker for leaked AI system prompts #AI #LLM #cybersecurity
LeakHub
leakhub.ai
www.paloaltonetworks.com/resources/in... This is a pretty awesome Infographic from @paloaltonetworks.com on OWASP top 10 for LLM security risks. #LLM #AI #Security #Cyber
OWASP Top 10 LLM Security Risks with Mitigation
OWASP Top 10 LLM Security Risks: An interactive diagram maps each risk, attack path, and concrete mitigation you can explore to secure AI systems in production
paloaltonetworks.com
academy.hackthebox.com/course/previ... Some really interesting courses dropping from HTB on AI privacy and defense today! #LLM #privacy #AI
AI Privacy Course | HTB Academy
This module explores privacy attacks against machine learning models and the differential privacy defenses that protect models from such attacks.
academy.hackthebox.com
any.run/cybersecurit... THIS is such a cool analysis inside the Lazarus groups operations #cyber #cybersecurity #malware
How We Caught Lazarus's IT Workers Scheme Live on Camera
See how Lazarus Group's IT workers scheme was exposed on a live camera using real-time monitoring inside ANY.RUN’s sandbox.
any.run
There’s a new Humble book bundle featuring a set of No Starch Press books on Hacking. For a limited time, pay what you want AND support EFF’s fight for privacy and free speech online! www.humblebundle.com/books/hacki...
Humble Tech Book Bundle: Hacking by No Starch
Turn your curiosity about computer hacking into a fast-paced, proven, and practical career with the latest Humble Tech Book Bundle!
humblebundle.com
It will only be weird for like a year that every new ransomware discovery gets tagged as "Satoru Gojo" #cybersecuirty #meme
www.youtube.com/watch?v=pRij... - This was a really really good break down on Kerberoasting for Blue Teams highly recommend to any folks looking to understand how to triage a Kerberoasting attack. #cybersecurity
Threat Watch: Spotting Kerberoasting from a blue team perspective | Learn with HTB
YouTube video by Hack The Box
youtube.com
www.exploit-db.com/google-hacki... Kind of neat I didn't know Offsec kept a database of useful google dorks #cybersecurity #OSINT
OffSec’s Exploit Database Archive
The GHDB is an index of search queries (we call them dorks) used to find publicly available information, intended for pentesters and security researchers.
exploit-db.com
github.com/Pennyw0rth/N... I feel a netexec theme today apparently. This is a netexec lab you can build to play around with Active directory. may be worth a shot if you are practicing for OSCP or just want to level up AD #ActiveDirectory #RedTeam #Netexec
GitHub - Pennyw0rth/NetExec-Lab: Lab used for workshop and CTF
Lab used for workshop and CTF. Contribute to Pennyw0rth/NetExec-Lab development by creating an account on GitHub.
github.com
github.com/The-Viper-On... Pretty cool tool if you are doing red teaming from a windows host. Great to add in for Commando VM from Mandiant #redteam #cyber #tool Basically it is crackmap/netexec just built in Powershell.
Home
Dominate Active Directory with PowerShell. . Contribute to The-Viper-One/PsMapExec development by creating an account on GitHub.
github.com
@tcmsecurity.bsky.social just dropped their new SOC200 course great for anyone looking to build labs and get better at incident response and threat hunting. certifications.tcm-sec.com/psap/?utm_so...
Practical SOC Analyst Professional (PSAP) Certification - TCM Security
Enhance your SOC Analyst skills by earning the Practical SOC Analyst Professional (PSAP) certification. Includes training and one free retake!
certifications.tcm-sec.com
cset.georgetown.edu/article/ai-r... - Great article on Ai Red teaming #Cybersecurity #AI #AIsecurity
AI Red-Teaming Design: Threat Models and Tools | Center for Security and Emerging Technology
Red-teaming is a popular evaluation methodology for AI systems, but it is still severely lacking in theoretical grounding and technical best practices. This blog introduces the concept of threat model...
cset.georgetown.edu
open.spotify.com/episode/1fEa... - North Korean's inflitrating US companies for cash is pretty big news right now and also pretty fascinating. This story is about one of the folks who manage a north Korean laptop farm and its pretty interesting. #Cybersecurity #Laptopfarm
The Everyday American Who Hustled for North Korea
The Journal. · Episode
open.spotify.com
www.hackthelogs.com/mainpage.html Another great resource for Detection Engineers and anyone working with SIEM's #Cybersecurity
hackthelogs.com