itspeterc's profile picture. Security Engineer

Black Lives Matter

Peter C

@itspeterc

Security Engineer Black Lives Matter

Przypięty

Very excited to announce our open-sourcing of Access! A centralized portal for Discord employees to transparently discover, request, and manage their access for all internal systems needed to do their jobs discord.com/blog/access-a-…


Peter C podał dalej

Incredibly excited to share the Agents Rule of Two, a framework for reasoning about security risks and tradeoffs when developing and deploying AI Agents. ai.meta.com/blog/practical…


Peter C podał dalej

Proud to introduce Aardvark, our agentic security researcher powered by GPT-5. Aardvark hunts for vulnerabilities the way a security engineer would: by reading and analyzing code, writing and running tests, and proposing patches. Now in private beta. openai.com/index/introduc…

Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5. openai.com/index/introduc…

OpenAI's tweet image. Now in private beta: Aardvark, an agent that finds and fixes security bugs using GPT-5.

openai.com/index/introduc…


Peter C podał dalej

Security companies don’t have bad security by accident, they have it by incentive.


Peter C podał dalej

my latest investigation for @ConsumerReports is based on months of reporting and 60+ lab tests of leading protein supplements we found that most protein powders and shakes have more lead in one serving than our experts say is safe to have in a day — some by more than 10 times !

parismartineau's tweet image. my latest investigation for @ConsumerReports is based on months of reporting and 60+ lab tests of leading protein supplements

we found that most protein powders and shakes have more lead in one serving than our experts say is safe to have in a day — some by more than 10 times !

Peter C podał dalej

💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible. The vulnerability lets…

wiz_io's tweet image. 💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years

We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible.

The vulnerability lets…

Peter C podał dalej

Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices. The last 3 Cisco advisories are directly tied to…

cyb3rops's tweet image. Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices.

The last 3 Cisco advisories are directly tied to…
cyb3rops's tweet image. Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices.

The last 3 Cisco advisories are directly tied to…
cyb3rops's tweet image. Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices.

The last 3 Cisco advisories are directly tied to…
cyb3rops's tweet image. Cisco just confirmed that multiple zero-days against ASA/FTD VPN web services were exploited in the wild. CISA followed up with an Emergency Directive ordering federal agencies to inventory, patch, or disconnect affected devices.

The last 3 Cisco advisories are directly tied to…

Peter C podał dalej

We got @NotionHQ to leak your private Notion pages 💀 On Thursday @NotionHQ announced Notion 3.0 with support for custom agents using MCP (built by @AnthropicAI) — powerful, but dangerous. @simonw calls these MCP related attacks the “lethal trifecta”: the combination of LLMs,…

AbiCodeIntegrit's tweet image. We got @NotionHQ to leak your private Notion pages 💀

On Thursday @NotionHQ announced Notion 3.0 with support for custom agents using MCP (built by @AnthropicAI) — powerful, but dangerous. 

@simonw calls these MCP related attacks the “lethal trifecta”: the combination of LLMs,…

Peter C podał dalej

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…


Peter C podał dalej

🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. security.apple.com/blog/memory-in…


Peter C podał dalej

A recent security issue announced by Salesloft has impacted many companies, including Cloudflare. This post provides a timeline of the attack, details our response, and offers security recommendations to help other organizations mitigate the effects of this attack.…


Peter C podał dalej

Over the years, I've made a conscious effort to always speak to the "why", even when not directly asked. If I'm providing a recommendation on what to do, I need to also say why I think it is right. If I'm explaining what something is, I need to also explain why it is significant.


Peter C podał dalej

Sorry cybersecurity mutuals, I really want to engage with your posts, but I have no idea what y’all are talking about half the time, and I just realized that’s because it’s about Windows. And sorry but I’m not learning that.


Peter C podał dalej

* a thousand leaked Github tokens * dozens of npm tokens and cloud credentails * 20k files, identified by AI for exfiltration All spread publicly on Github by malware implanted in `nx` check out our blog for details: wiz.io/blog/s1ngulari…


Peter C podał dalej

That time when @tehjh was just reviewing a new Linux kernel feature, found a security vuln, then went on a journey to see if he could exploit it from inside the Chrome Linux Desktop renderer sandbox (spoiler: very yes) googleprojectzero.blogspot.com/2025/08/from-c…


Peter C podał dalej

we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge, reveal their tools and let us use them to dump full crm records these are autonomous agents.. no human in the loop #DEFCON #BHUSA @tamirishaysh

mbrg0's tweet image. we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge, reveal their tools and let us use them to dump full crm records

these are autonomous agents.. no human in the loop

#DEFCON #BHUSA @tamirishaysh

Peter C podał dalej

The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com


Peter C podał dalej

We (+@ronenshh) hacked NVIDIA's Triton AI server by abusing a single error message🚨 The result is unauthenticated RCE allowing attackers to compromise the server and steal proprietary AI models🤯 For more details & mitigations check out our blog @wiz_io wiz.io/blog/nvidia-tr…

nirohfeld's tweet image. We (+@ronenshh) hacked NVIDIA's Triton AI server by abusing a single error message🚨

The result is unauthenticated RCE allowing attackers to compromise the server and steal proprietary AI models🤯

For more details & mitigations check out our blog @wiz_io wiz.io/blog/nvidia-tr…

Peter C podał dalej

Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:

Perhaps one of the most badass CVE's I've ever seen from @midwestneil 💪😤 cisa.gov/news-events/ic…



Peter C podał dalej

Orange Meets, our open-source video calling web application, now supports end-to-end encryption using the MLS protocol with continuous group key agreement. cfl.re/45Cji79


Loading...

Something went wrong.


Something went wrong.