Tim (Wadhwa-)Brown :donor:
@timb.me.uk
push(@fediverse, "Adversarial Engineer"); # i hack in Perl 🌉 bridged from ⁂ https://infosec.exchange/@timb_machine, follow @ap.brid.gy to interact
I bet the clowns advocating for AGI won''t be voting for it to "live free"...<snark />
[todayinai] It's both hilarious and concerning that someone thought limiting an AI LLM model only to GET requests constituted some kind of security control.
This is fascinating. My wife is applying for research funding adjacent to her major PhD focus of neurodiversity. She has to demonstrate the ability to cross domains and she has chosen to look at cyber. I suspect it may be a write up of Tim's rants over the last decade.
Strategy: * https://ai-killchain.airwars.org/ - all the most ethical armed forces are using AI, discuss... * https://securstack.io/blog/en/risk-acceptance-in-security-when-and-how-to-document-it - how to accept risk * […]
Original post on infosec.exchange
infosec.exchange
Interesting Git repos of the week: Bugs: * https://github.com/MSNightmare/FalconFlank - everyone's favourite new source of 0day pops CrowdStrike Falcon * https://github.com/MSNightmare/HardBreacher - everyone's favourite new source of 0day pops Kaspersky AV Hard hacks: * […]
Original post on infosec.exchange
infosec.exchange
Oh my: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ #routeros, #threatintel
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended
The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.
cert.pl
In the absence of a canonical toot, to retoot. This is bad: https://keepitfree.ai/announcements/a/i-shuts-down-stay-human/ thank you friendly Italians (and others, no doubt), for your service. #autisticiInventati
Inspired by that Falcon Force blog post, something I've never really given much consideration for, except in the case of AIX where it resulted in an LPE bug. Sending false logs might be fun. Might play with it on the mainframe exercise next week.
Strategy: * https://ai-killchain.airwars.org/ - all the most ethical armed forces are using AI, discuss... * https://securstack.io/blog/en/risk-acceptance-in-security-when-and-how-to-document-it - how to accept risk * […]
Original post on infosec.exchange
infosec.exchange
Interesting Git repos of the week: Bugs: * https://github.com/MSNightmare/FalconFlank - everyone's favourite new source of 0day pops CrowdStrike Falcon * https://github.com/MSNightmare/HardBreacher - everyone's favourite new source of 0day pops Kaspersky AV Hard hacks: * […]
Original post on infosec.exchange
infosec.exchange
RE: https://infosec.exchange/@timb_machine/117214900530092315 There, I have put the Fediverse in a sandbox.
Stop doing naughty things.
🎉 Another year, another change request training completed! ✅ I’m excited to share that I’ve successfully completed my Change Request Training for another year. 📚💪 It’s always great to refresh the knowledge, sharpen the skills, and stay up to date with the latest processes and best practices […]
Original post on infosec.exchange
infosec.exchange
[todayinai] Getting sent sales pursuits that it turns out the AI has hallucinated.
[meta] Having a pint and trying to work out what to burn down and rebuild first.
Your conversations with vendors when procuring new systems, solutions and software will go a lot better if you can describe your use cases and requirements upfront rather than participating in solution requirement sessions where we work out what buttons and nobs to push and turn on the interface […]
Original post on infosec.exchange
infosec.exchange
Someone has suggested a naming convention of "Palaces and Estates" and fuck that.
[meta] Watching: My wife crafting research survey questions in a SaaS platform and trying to include CSS and images in her text. Thinking: If that works, it's vulnerable to XSS attacks.
Learning a new protocol by manual fuzzing. If it's any consolation to the AI overlords, none of the models can offer the square root of fuck all based on the available data.
Congratulations to ChatGPT on this award: https://x.com/EU_Commission/status/2094379702546784496
An interesting take from Theo on using AI to write code: https://marc.info/?l=openbsd-tech&m=177425035627562&w=2
'Re: [patch] ext4fs rw' - MARC
marc.info
“I’m going to delete them all except for the one that can follow instructions” “That’s fucked up” “Nah my God wiped out all my ancestors but for one boatload and I turned out fine” “If you really think that you did not turn out fine” “They’re only programs” “So are you” #Tootfic […]
Original post on aus.social
aus.social
Interesting Git repos of the week: Detection: * https://github.com/sunlife3/needre - home made EDR in Rust * https://github.com/All3xJ/fixing-google-secops-detections - improving GOOG's Chronicle Exploitation: * https://github.com/PShlyundin/ldap_shell - shell based tool for abusing LDAP 🤖 * […]
Original post on infosec.exchange
infosec.exchange
I'd suggest replacing "meat proxies" with .forward files but apparently the non-determinism is a feature not a bug.