Giuseppe N3mes1s

@n3mes1s.bsky.social

An Operating System lover, was EDR chef and purple teamer. Trying to replace myself with an Agentic AI.

False positives waste your time. False negatives cost you breaches. At @BlackHatEvents , @moyix shows how XBOW agents fight false positives — validating real exploits at scale, in hours. 📍Aug 7 | 11:20am

Bild

Sent out a new edition of my email newsletter (which is very genuinely just recent from my blog reformatted into newsletter form) and it turns out it's basically ALL prompt injection this week - two detailed paper reviews and my piece on the lethal trifecta simonw.substack.com/p/the-lethal...

The lethal trifecta for AI agents

Plus reviews of two new papers about prompt injection, and Anthropic's tips on building multi-agent LLM systems

simonw.substack.com

Another prompt injection paper review! This time it's "An Introduction to Google’s Approach to AI Agent Security" by Santiago Díaz, Christoph Kern, and Kara Olive Some interesting ideas in here, particularly around Google's three core principles for agent security simonwillison.net/2025/Jun/15/...

An Introduction to Google’s Approach to AI Agent Security

Here’s another new paper on AI agent security: An Introduction to Google’s Approach to AI Agent Security, by Santiago Díaz, Christoph Kern, and Kara Olive. (I wrote about a different …

simonwillison.net

XBOW found a critical path traversal vulnerability in ZOO-Project (CVE-2024-53982). The vulnerability exists in the Echo example (enabled by default) and allows an attacker to retrieve any file on the server. Users should upgrade to the latest version.

Screenshot showing execution of the command `curl -s 'http://localhost:8000/cgi-bin/zoo_loader.cgi?request Execute&service-WPS&version=1.0.0&Identifier-echo&DataInputs-a-Reference@mimeType=text/plain@cache_file=/etc/passwd;b=value;c=value | pygmentize -l xml` and the output, including the target machine’s /etc/passwd embedded in the XML.

Exclusive: The backdoor inserted in v1.95.7 adds an "addToQueue" function which exfiltrates the private key through seemingly-legitimate CloudFlare headers. Calls to this function are then inserted in various places that (legitimately) access the private key.

BildBild
Socket@socket.dev · 2y ago

🚨 A supply chain attack has been detected in versions 1.95.6 and 1.95.7 of the popular #Solana web3.js library. The injected code captures private keys and transmits them to a hardcoded address. This is a developing story. socket.dev/blog/supply-... #crypto #cybersecurity

I really hope to never see any of this in any logs coming from edr products. Or at least I hope we will have a good way to track the “undefined” behavior of this kind if applications. Agreeing on this is opening to new security risks

Rich Harang@rich.harang.org · 2y ago

Stuff like this is neat, but also opens the door to an *amazing* new world of multimodal indirect prompt injection. Make sure you enforce manual approval for any 'risky' actions the system performs after it sees your desktop, and don't show it anything you want to keep private.