_Drag0s_'s profile picture. All-Time Learner | Current deployment: NZ

Dragos

@_Drag0s_

All-Time Learner | Current deployment: NZ

Dragos reposted

Twitter used to be my favorite place on the Internet. I've derived enormous value from it in the past 16 years. Not true anymore. Most of the people I enjoyed reading have left. My feed, which used to feature art and science and technology and humor, has become constant…


Dragos reposted

Tempted to change up the update script to provide a link to the latest blogpost, and then have the user enter a password that they could only know if they've read and digested the release notes... Only joking. Maybe.


Dragos reposted

Yes and also, interestingly, this tool takes all of the most commons steps used to hack people & companies — from OSINT (open source intelligence) via social media, to target selection, to pretext development, to contact + phishing — and automates it completely for attackers.

Huge news: we've raised $1.2M to build the first AI marketer that acts like a human. Astral can browse the internet to find potential customers, then convert them while you sleep:



Dragos reposted

大寒波で雪化粧した鶴ヶ城がやばい

onotch_x's tweet image. 大寒波で雪化粧した鶴ヶ城がやばい

Dragos reposted

#DietPi v9.10 is here: - New: "dietpi-display" to control display mode and rotation, and toggle @FriendlyARM_ NanoPi M6 DSI displays - Kernel migration for @Raspberry_Pi - @risc_v systems migrated to @debian Trixie - @orangepixunlong 5 Max Ethernet fixed dietpi.com/docs/releases/…


Dragos reposted

I want you to know, this is the second company I've had to quit due to the company mistreating my listener's privacy. Megaphone was my old hosting provider, they shared my listener data with advertisers. Left them. And now Patreon got caught sharing my lister data to Facebook.


Dragos reposted

Malware Bible is now opensource: github.com/Perkins-Fund/M… Feel free to make pull requests how you see fit, ilysm!


Dragos reposted

#AmazonCognito supports identity provider-initiated login, encrypted SAML responses, & signed SAML login requests. go.aws/4ht5xu5

AWSIdentity's tweet image. #AmazonCognito supports identity provider-initiated login, encrypted SAML responses, & signed SAML login requests. go.aws/4ht5xu5

Dragos reposted

Today, I'm releasing the first version of a small web 🚀: rosti.bin.re It provides IOCs and YARA rules collected semi-automatically from public blog posts and reports of almost 200 cybersecurity sites. I hope it proves useful to some of you ... 🙏✨ #ThreatIntel

viql's tweet image. Today, I'm releasing the first version of a small web 🚀:  rosti.bin.re

It provides IOCs and YARA rules collected semi-automatically from public blog posts and reports of almost 200 cybersecurity sites.

I hope it proves useful to some of you ...  🙏✨ #ThreatIntel

Dragos reposted

"Reality is what we take to be true. What we take to be true is what we believe. What we believe is based upon our perceptions. What we perceive depends upon what we look for. What we look for depends on what we perceive”—David Bohm to Albert Einstein 1956


Dragos reposted

OpenAI furious DeepSeek might have stolen all the data OpenAI stole from us 🔗404media.co/openai-furious…

404mediaco's tweet image. OpenAI furious DeepSeek might have stolen all the data OpenAI stole from us

🔗404media.co/openai-furious…
404mediaco's tweet image. OpenAI furious DeepSeek might have stolen all the data OpenAI stole from us

🔗404media.co/openai-furious…

Dragos reposted

made a site to run deepseek r1 for free -- locally in your browser, no downloads, no servers purely using WebGPU r1-web is open source, made in america, run on american servers, available below forever


Dragos reposted

😂😂


Dragos reposted

Two new side-channel attacks against Apple CPUs that can leak sensitive data from the processor's memory SLAP (Speculation Attacks via Load Address Prediction) and FLOP (False Load Output Predictions) predictors.fail


Dragos reposted

Today Google announced a new OSV-SCALIBR: A library for Software composition analysis. It allows to extract software dependencies, generate SBOM’s and scan them via osv.dev! More details in our blogpost: security.googleblog.com/2025/01/osv-sc…


Dragos reposted

Building container images FROM scratch? Then you need to be aware of these pitfalls 👇 By default, scratch containers lack: - Rootfs layout - CA certificates - Time zone info - Shared libraries - /etc/{passwd,group} Learn more in my new blog post: labs.iximiuz.com/tutorials/pitf…

iximiuz's tweet image. Building container images FROM scratch? Then you need to be aware of these pitfalls 👇

By default, scratch containers lack:

- Rootfs layout
- CA certificates
- Time zone info
- Shared libraries
- /etc/{passwd,group}

Learn more in my new blog post:
labs.iximiuz.com/tutorials/pitf…

Dragos reposted

Any model hosted on HuggingFace and loaded via AutoModel with trust_remote_code=true can be backdoored to execute malicious code, without changing any of the its weights files. Using SafeTensors is not enough, just add a custom class to auto_map in config.json and 💥

evilsocket's tweet image. Any model hosted on HuggingFace and loaded via AutoModel with trust_remote_code=true can be backdoored to execute malicious code, without changing any of the its weights files. Using SafeTensors is not enough, just add a custom class to auto_map in config.json and 💥
evilsocket's tweet image. Any model hosted on HuggingFace and loaded via AutoModel with trust_remote_code=true can be backdoored to execute malicious code, without changing any of the its weights files. Using SafeTensors is not enough, just add a custom class to auto_map in config.json and 💥

NEW open source tool from Dreadnode's @evilsocket and Ads Dawson: dyana, an eBFP sandbox environment designed to load, run, and profile a wide range of files and provide dynamic testing for AI models. ‼️ Supports a variety of files including, machine learning models, ELFs,…



Dragos reposted

Data Leakage and deduplication are critical when training LLMs! SemHash is a new, blazingly fast semantic text deduplication library that combines Model2Vec embeddings with ANN-based similarity search through Vicinity, making it possible to deduplicate millions of records in…

_philschmid's tweet image. Data Leakage and deduplication are critical when training LLMs! SemHash is a new, blazingly fast semantic text deduplication library that combines Model2Vec embeddings with ANN-based similarity search through Vicinity, making it possible to deduplicate millions of records in…

Loading...

Something went wrong.


Something went wrong.