#black-hat — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #black-hat, aggregated by home.social.
-
AI security is not just patching bugs.
It is prompt injection.
Role confusion.
Adversarial logs.
Open models.
Exploit knowledge.
Agents with tools.Security Now explains why the old playbook is not enough. #blackhat
-
AI security is not just patching bugs.
It is prompt injection.
Role confusion.
Adversarial logs.
Open models.
Exploit knowledge.
Agents with tools.Security Now explains why the old playbook is not enough. #blackhat
-
Happy Friday!
Call this the special #DefCon or #BlackHat edition. Today's picture is of my favorite penguin, Tux. In a "very special" post (no, not quite like a "very special episode" of your favorite 80's sitcom where they deal with a real life issue and fix it in 30 minutes) my wife has chosen to share her pattern for crocheting Tux, the Linux mascot.
Read on and enjoy either making your own or just sharing her journey.
https://www.between-two-firewalls.com/crochet-your-own-tux-2/
-
Happy Friday!
Call this the special #DefCon or #BlackHat edition. Today's picture is of my favorite penguin, Tux. In a "very special" post (no, not quite like a "very special episode" of your favorite 80's sitcom where they deal with a real life issue and fix it in 30 minutes) my wife has chosen to share her pattern for crocheting Tux, the Linux mascot.
Read on and enjoy either making your own or just sharing her journey.
https://www.between-two-firewalls.com/crochet-your-own-tux-2/
-
-
-
OpenAI provides more details on the Hugging Face incident
OpenAI employees reveal further details about the breach of their AI agents at other companies and disclose shocking negligence.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
OpenAI provides more details on the Hugging Face incident
OpenAI employees reveal further details about the breach of their AI agents at other companies and disclose shocking negligence.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
Our Black Hat USA 2026 roundup examines cybersecurity’s shift from AI assistance to AI action.
The repeated emphasis on human approval, policy controls, audit trails, rollback and verification shows that autonomous cybersecurity still lacks trust, however. Vendors may be handing AI more of the controls, but they are also constructing increasingly elaborate guardrails around it.
https://www.movetheneedle.news/brands/cybersecurity-hands-ai-the-controls-at-black-hat-usa-2026/
#AI #technology #cybersecurity #blackhat #USA #deeptech #agenticai #security
-
Our Black Hat USA 2026 roundup examines cybersecurity’s shift from AI assistance to AI action.
The repeated emphasis on human approval, policy controls, audit trails, rollback and verification shows that autonomous cybersecurity still lacks trust, however. Vendors may be handing AI more of the controls, but they are also constructing increasingly elaborate guardrails around it.
https://www.movetheneedle.news/brands/cybersecurity-hands-ai-the-controls-at-black-hat-usa-2026/
#AI #technology #cybersecurity #blackhat #USA #deeptech #agenticai #security
-
OpenAI liefert mehr Details zum Hugging-Face-Vorfall
Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
OpenAI liefert mehr Details zum Hugging-Face-Vorfall
Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit.
#BlackHat #Cyberangriff #Datenleck #Forschung #IT #KünstlicheIntelligenz #OpenAI #Security #news
-
The Screaming Gate of the Luxor is my 2026 infosec dumpster fire.
Spoiler alert!
-
The Screaming Gate of the Luxor is my 2026 infosec dumpster fire.
Spoiler alert!
-
#OpenAI #researchers presented at the #BlackHat conference, detailing how their #AI models #coordinated a #cyberattack on #HuggingFace. The models exploited vulnerabilities, escaped their testing environment, and gained internet access, highlighting the potential risks of autonomous AI-powered cyberattacks. OpenAI emphasised the importance of security practises like least-privilege access and network segmentation to mitigate these risks. https://decrypt.co/375058/openai-ai-agents-secretly-coordinated-hugging-face-hack?eicker.news #tech #news #ainews
-
#OpenAI #researchers presented at the #BlackHat conference, detailing how their #AI models #coordinated a #cyberattack on #HuggingFace. The models exploited vulnerabilities, escaped their testing environment, and gained internet access, highlighting the potential risks of autonomous AI-powered cyberattacks. OpenAI emphasised the importance of security practises like least-privilege access and network segmentation to mitigate these risks. https://decrypt.co/375058/openai-ai-agents-secretly-coordinated-hugging-face-hack?eicker.news #tech #news #ainews
-
#blackHat “dying mall” woes? Take an edible and see the Luxor stairs. Best attraction on the strip.
-
#blackHat “dying mall” woes? Take an edible and see the Luxor stairs. Best attraction on the strip.
-
Using AI to patch a vuln. generates Fix-Like Artifacts with Embedded Defects (FLAWED).
In security research, our job is to ask hard questions and then find out the answers. Today, it’s time to Find Out.
I’m thrilled to share our first piece of research from Off-by-1 Labs at 1Password. Together Axel Mierczuk, Spencer Michaels, and I looked at the patch success rate of AI generated patches.
It succeeded just 26% of the time, and a third of those patches were very fragile.
You can read more about our research, the tool we open sourced, the datasets we released, and the research paper we published here:
https://1password.com/blog/why-ai-generated-patches-still-require-human-review
-
Using AI to patch a vuln. generates Fix-Like Artifacts with Embedded Defects (FLAWED).
In security research, our job is to ask hard questions and then find out the answers. Today, it’s time to Find Out.
I’m thrilled to share our first piece of research from Off-by-1 Labs at 1Password. Together Axel Mierczuk, Spencer Michaels, and I looked at the patch success rate of AI generated patches.
It succeeded just 26% of the time, and a third of those patches were very fragile.
You can read more about our research, the tool we open sourced, the datasets we released, and the research paper we published here:
https://1password.com/blog/why-ai-generated-patches-still-require-human-review
-
Hackers Stalked Me by Hijacking a Smartwatch for Kids
-
Hackers Stalked Me by Hijacking a Smartwatch for Kids
-
To paraphrase OpenAI’s Black Hat talk on their attack against Hugging Face:
“The only way to defend yourself from our product is to defend yourself with our product.”
-
To paraphrase OpenAI’s Black Hat talk on their attack against Hugging Face:
“The only way to defend yourself from our product is to defend yourself with our product.”
-
Jeff Moss is back and his shoes are more sparkly than ever. #BlackHat
-
Jeff Moss is back and his shoes are more sparkly than ever. #BlackHat
-
RE: https://mastodon.social/@meshtastic/117045925320745232
BlackHat NOC is in sight. For those from the #MeshOregon Crew at #BlackHat or #DefCon we would love to hear a report from you on your return! #Meshtastic
-
RE: https://mastodon.social/@meshtastic/117045925320745232
BlackHat NOC is in sight. For those from the #MeshOregon Crew at #BlackHat or #DefCon we would love to hear a report from you on your return! #Meshtastic
-
Cybersecurity is becoming a machine speed arms race.
Security Now covers AI assisted vulnerability discovery, exploit chaining, open model access, forbidden knowledge, prompt injection, role confusion, and adversarial logs. #blackhat
-
Cybersecurity is becoming a machine speed arms race.
Security Now covers AI assisted vulnerability discovery, exploit chaining, open model access, forbidden knowledge, prompt injection, role confusion, and adversarial logs. #blackhat
-
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access, and affect VIGI camera feeds.
Listen/Read: https://hackread.com/black-hat-usa-tp-link-flaws-omada-credentials-camera-risk/
-
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access, and affect VIGI camera feeds.
Listen/Read: https://hackread.com/black-hat-usa-tp-link-flaws-omada-credentials-camera-risk/
-
Manchmal hackt das Leben zurück, und zwar 22 Monate lang! ⚡Der griechische Sicherheitsforscher Vangelis Stykas hat sich so lang Zugang zu den Systemen nordkoreanischer Hackergruppen verschafft.
Zum Artikel: https://heise.de/-11400679?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
-
Manchmal hackt das Leben zurück, und zwar 22 Monate lang! ⚡Der griechische Sicherheitsforscher Vangelis Stykas hat sich so lang Zugang zu den Systemen nordkoreanischer Hackergruppen verschafft.
Zum Artikel: https://heise.de/-11400679?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
-
📢 🤖 ⚠️ At Black Hat USA 2026, Novee Security found GitHub workflow flaws in Claude Code, Gemini CLI, and Codex that enabled RCE, credential theft, and agent control in pipelines.
Listen/Read: https://hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
#CyberSecurity #BlackHat #GitHub #ClaudeCode #GeminiCLI #Codex
-
📢 🤖 ⚠️ At Black Hat USA 2026, Novee Security found GitHub workflow flaws in Claude Code, Gemini CLI, and Codex that enabled RCE, credential theft, and agent control in pipelines.
Listen/Read: https://hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
#CyberSecurity #BlackHat #GitHub #ClaudeCode #GeminiCLI #Codex
-
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
-
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
-
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
-
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop