Skip Navigation
Posts
29
Comments
3
Joined
2 yr. ago
  • You build a derivation yourself... which I never do. I am on mac so I brew install and orchestrate brew from home manager. I find it works good as a compromise.

  • AI Infosec @infosec.pub
    0xCBE @infosec.pub

    A framework to securely use LLMs in companies - Part 1: Overview of Risks

    Cloud Security @infosec.pub
    0xCBE @infosec.pub
    AI Infosec @infosec.pub
    0xCBE @infosec.pub

    Impact of remote-code execution vulnerability in LangChain

    AI Infosec @infosec.pub
    0xCBE @infosec.pub

    PoisonGPT: How we hid a lobotomized LLM on Hugging Face to spread fake news

    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    ALFA: Automated Audit Log Forensic Analysis for Google Workspace

    cross-posted from: https://infosec.pub/post/397812

    Automated Audit Log Forensic Analysis (ALFA) for Google Workspace is a tool to acquire all Google Workspace audit logs and perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework.

    By Greg Charitonos and BertJanCyber

    AI Infosec @infosec.pub
    0xCBE @infosec.pub

    Prompt Injection Attacks and Mitigations

    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    We’ve made a few changes to the way we host and distribute our Images over the last year to increase security, give ourselves more control over the distribution, and most importantly to keep our costs under control [...]

    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    Kubernetes Security Basics Series Part I - Deployment and Container Orchestration

    This first post in a 9-part series on Kubernetes Security basics focuses on DevOps culture, container-related threats and how to enable the integration of security into the heart of DevOps.

    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    Kubernetes Grey Zone: Risks in Managed Cluster Middleware

    Cloud Security @infosec.pub
    0xCBE @infosec.pub
    Red Team @infosec.pub
    0xCBE @infosec.pub
    Security News @infosec.pub
    0xCBE @infosec.pub
    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    GCP Pentesting Guide

    Blue Team @infosec.pub
    0xCBE @infosec.pub

    Enterprise Purple Teaming: an Exploratory Qualitative Study

    Security News @infosec.pub
    0xCBE @infosec.pub

    CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability

    Cloud Security @infosec.pub
    0xCBE @infosec.pub
    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    Securing the EC2 Instance Metadata Service

    AI Infosec @infosec.pub
    0xCBE @infosec.pub

    Not really technical, but gives some pointers to wrap your head around the problem

    Cloud Security @infosec.pub
    0xCBE @infosec.pub

    "Toyota said it had no evidence the data had been misused, and that it discovered the misconfigured cloud system while performing a wider investigation of Toyota Connected Corporation's (TC) cloud systems.

    TC was also the site of two previous Toyota cloud security failures: one identified in September 2022, and another in mid-May of 2023.

    As was the case with the previous two cloud exposures, this latest misconfiguration was only discovered years after the fact. Toyota admitted in this instance that records for around 260,000 domestic Japanese service incidents had been exposed to the web since 2015. The data lately exposed was innocuous if you believe Toyota – just vehicle device IDs and some map data update files were included. "

    AI Infosec @infosec.pub
    0xCBE @infosec.pub

    AI Risk Database

    "database [...] specifically designed for organizations that rely on AI for their operations, providing them with a comprehensive and up-to-date overview of the risks and vulnerabilities associated with publicly available models."

    welcome

  • ahah thank you, we shall all yell together then

  • Introduce yourself!

  • đź‘‹ infra sec blue team lead for a large tech company