Happy Friday... PATCH YO' IOS (EXPLOITATION ITW)
Apple security releases - Apple Support (SA) m.cje.io/4bTDrc3.
@robertauger
25 years Appsec,PurpleTeam,Web Application Security Consortium(WASC) cofounder,Baythreat Organizer,Ex-PayPal/eBay/Box/Workday/Coinbase infosec. http://Sectemplates.com | https://www.cgisecurity.com/ | https://github.com/securitytemplates/sectemplates
Happy Friday... PATCH YO' IOS (EXPLOITATION ITW)
Apple security releases - Apple Support (SA) m.cje.io/4bTDrc3.
ok this is freaking cool... spaceraccoon/vulnerability-spoiler-alert-action: GitHub Action to alert on security patches before the CVE drops. m.cje.io/4a6lZjc
βFrom an attacker perspective, #React2Shell is the kind of vulnerability that affords massive opportunity for crime, but that also has a narrow window for exploitation, partly because of public awareness leading to patching, and partly because of competition.β
securityboulevard.com/2025/12/atta...
What do pentesters think of aws security agent pentesting capabilities?
Future of CVE Program in limbo as CISA, board members debate path forward
At defcon today if anyone wants to chat
Same desert as Hellβs Kitchen I think which makes sense!
Hellβs Kitchen?
About 75% done with a new pack for Sectemplates.com focusing on appsec 'Security Partnerships'. How many of you have leveraged such as program and how did it go for you?
I wonder how long it will take for AI interfaces into your brain to
1. read your βdatabaseβ of memories to help with memory recovery
2. Read your thoughts on current tasks and help you optimize it
3. Write access to your memory or βramβ to aid with tasks
5-10 years?
I have a bunch of solid security domain names I'm thinking of finally selling. What would be the best way to sell them to security vendors?
Random rant: If security teams understood how to represent their work as dollar savings, how much more funding and support they'd receive?
Announcement - Incident Response Program Pack v1.5
This release is to provide you with everything you need to establish a functioning security incident response program at your company.
Announcement: www.sectemplates.com/2025/02/anno...
GitHub: github.com/securitytemp...
It was nice knowing you ;)
It gets worse
I need to spend more time here, Twitter is just political yelling and screaming
POTUS can do whatever he wants now that heβs king
I imagine people using botnets to train AI models in the near future.
Chinese AI models will be cheaper at the cost of censoring certain topics and people will eat it up... Ask it about Tank man or Xi and you'll see some obvious examples. www.wsj.com/tech/ai/chin...
Feels like the future for automating exploitation is training llms and using agents to perform these attacks. Agree? Disagree?
BREAKING: Chinese hackers accessed Yellen's computer in US Treasury breach, per Bloomberg.
100%, 2025 likely not going to be much better on the world stage. Letβs hope Iβm wrong
Hacking campaign compromised at least 16 Chrome browser extensions
I'm pleased to announce the latest SecTemplates.com release, External Penetration Testing Program Pack v1.1.
Announcement: www.sectemplates.com/2024/12/anno...
GitHub: github.com/securitytemp...
This is a good idea, however I doubt that this code on average is getting proper security testing/updates. As a result there may be a surge in agencies adopting vulnerable code and increasing their attack surface fedscoop.com/agencies-mus...
An attacker successfully phished a Cyberhaven employee.
They gained access to their Chrome Web Store admin credentials and published a malicious version of the Cyberhaven extension.
Read my full writeup here:
www.vulnu.com/p/breaking-c...
Thanks @jaimeblascob.bsky.social and @johntuckner.me
You know what one of the best uses for #AI is going to be that nobody is talking about? When you're arguing with an internet stranger about a point and you need to find facts to 'teach them', you can ask the AI to summarize the best sources and paste it back. Soon arguing will be automated. ;)
These Jersey drones are worrying. Feeling more and more like they are searching for something that has the possibility of a very negative outcome. #drones