Renato Gabriele

@remagio.bsky.social

"If you have a garden and a library, you have everything you need." by Cicero. https://www.journalismfestival.com/speaker/renato-gabriele

I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg

GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.

SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.

github.com

Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.

Kevin Beaumont (@GossiTheDog@cyberplace.social)

Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...

cyberplace.social

This is a great explainer of the OpenAI hack against Hugging Face, particularly of the report that the latter published earlier this week. If you had trouble parsing the highly technical report, this article can walk you through it.

The Hugging Face AI break-in, as told through an increasingly committed bear metaphor | TechCrunch

Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)

techcrunch.com

I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.

The rogue AI agent spent days outside OpenAI’s intended constraints, hacking Hugging Face. OpenAI reportedly failed to identify it for at least a week. An agent left notes for future versions on how to escape restrictions www.reuters.com/business/its...

Bild
Lukasz Olejnik@lukaszolejnik.bsky.social · 2w ago

My comments in @reuters.com about the OpenAi model going off the rails to hack @hf.co . If frontier models restrict legitimate defenders while powerful models remain available to attackers, this create an one-sided, strategic disadvantage. www.reuters.com/legal/litiga...

The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”

The Wall Street Journal@wsj.com · 2w ago

They were like high-school students trying to hack into the textbook company to cheat on their final exam. Only these hackers weren’t human.

Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!

Opaque, Interoperable Passkey Records (and a Go API)

Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.

words.filippo.io

The recent addition of a Google Compute Engine Virtual Ethernet (gVNIC) driver in TamaGo now allows networked GCP Confidential VMs. A small, reproducible, memory-safe unikernel, yet allowing use of the entire Go ecosystem, all measured at launch as a single binary.

Bild