Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. "AI is giving attackers a huge advantage!"

"AI is giving attackers a huge advantage!"

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
129 Indlæg 39 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • krypt3ia@infosec.exchangeK krypt3ia@infosec.exchange

    @cR0w @Viss @FuturisticRobert Unfortunately, I suspect all of us will be trying to just survive in some post apocalyptic hellscape.

    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote sidst redigeret af
    #90

    @krypt3ia @Viss @FuturisticRobert Realistically, that's where I'm at too. But there's too much planning and luck for that so I'm doing what I can and accepting the rest of the risk. Like another Cascadia earthquake.

    1 Reply Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      @darthnull @iagox86 Seems to be the way most of the current orgs that claim community involvement are already heading too.

      iagox86@infosec.exchangeI This user is from outside of this forum
      iagox86@infosec.exchangeI This user is from outside of this forum
      iagox86@infosec.exchange
      wrote sidst redigeret af
      #91

      @cR0w @darthnull Then labs/research makes their own blog, then that ALSO gets filled with AI slop because more quantity = better right?

      I'm gonna start embedding one of those "email me for a $100 gift card" into every slop post to prove that nobody reads them

      da_667@infosec.exchangeD tindrasgrove@infosec.exchangeT 2 Replies Last reply
      0
      • iagox86@infosec.exchangeI iagox86@infosec.exchange

        @cR0w @darthnull Then labs/research makes their own blog, then that ALSO gets filled with AI slop because more quantity = better right?

        I'm gonna start embedding one of those "email me for a $100 gift card" into every slop post to prove that nobody reads them

        da_667@infosec.exchangeD This user is from outside of this forum
        da_667@infosec.exchangeD This user is from outside of this forum
        da_667@infosec.exchange
        wrote sidst redigeret af
        #92

        @iagox86 @cR0w @darthnull If I had a dollar for every time I was looking up PoC/exploits for a given CVE, and its some slop report from a website that just seems to scrape cve.org and regurgitate it along with very generic remediation recommendations, I probably wouldn't be rich, but like, I could have a fairly nice lunch.

        iagox86@infosec.exchangeI 1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          @iagox86 @cR0w @darthnull If I had a dollar for every time I was looking up PoC/exploits for a given CVE, and its some slop report from a website that just seems to scrape cve.org and regurgitate it along with very generic remediation recommendations, I probably wouldn't be rich, but like, I could have a fairly nice lunch.

          iagox86@infosec.exchangeI This user is from outside of this forum
          iagox86@infosec.exchangeI This user is from outside of this forum
          iagox86@infosec.exchange
          wrote sidst redigeret af
          #93

          @da_667 @cR0w @darthnull omg, it's the worst.

          The WORST part is that I've found that an LLM is the best way to deal with that shit.. it's way better at filtering results down to just useful PoCs (having to use AI to fight AI makes me incredibly sad though 😞 )

          da_667@infosec.exchangeD viss@mastodon.socialV 2 Replies Last reply
          0
          • cr0w@infosec.exchangeC cr0w@infosec.exchange

            "AI is giving attackers a huge advantage!"

            "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

            katalogeur@mastodon.socialK This user is from outside of this forum
            katalogeur@mastodon.socialK This user is from outside of this forum
            katalogeur@mastodon.social
            wrote sidst redigeret af
            #94

            @cR0w

            People, not the machines, have chosen to destroy these things by pretending that LLMs are the AGI they were hungry for, and told they were getting, and investing accordingly despite all evidence to the contrary.

            1 Reply Last reply
            0
            • iagox86@infosec.exchangeI iagox86@infosec.exchange

              @da_667 @cR0w @darthnull omg, it's the worst.

              The WORST part is that I've found that an LLM is the best way to deal with that shit.. it's way better at filtering results down to just useful PoCs (having to use AI to fight AI makes me incredibly sad though 😞 )

              da_667@infosec.exchangeD This user is from outside of this forum
              da_667@infosec.exchangeD This user is from outside of this forum
              da_667@infosec.exchange
              wrote sidst redigeret af
              #95

              @iagox86 @cR0w @darthnull what's incredibly fun is looking at nuclei-templates repo, thinking you've found something that can serve as a proof of concept for some thing you really needed, and its a GET request that they parse with regex for version strings.

              Thanks for that, I guess.

              viss@mastodon.socialV 1 Reply Last reply
              0
              • futuristicrobert@infosec.exchangeF futuristicrobert@infosec.exchange

                @krypt3ia @cR0w @Viss

                I have a stash of bottle caps....

                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.socialV This user is from outside of this forum
                viss@mastodon.social
                wrote sidst redigeret af
                #96

                @FuturisticRobert @krypt3ia @cR0w my hottub runs off the powerwall. when the grid goes down that party's ay my place. bring swimtrunks and something for the smoker

                cr0w@infosec.exchangeC 1 Reply Last reply
                0
                • futuristicrobert@infosec.exchangeF futuristicrobert@infosec.exchange

                  @Viss @cR0w @krypt3ia

                  Sodium batteries! Nice!

                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.socialV This user is from outside of this forum
                  viss@mastodon.social
                  wrote sidst redigeret af
                  #97

                  @FuturisticRobert @cR0w @krypt3ia yup. need big long term stuff to go behind the high discharge lipos. also need to see how many zinc and copper poles are needed to get 12v at any reasonable amperage out of an earth battery

                  1 Reply Last reply
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    "AI is giving attackers a huge advantage!"

                    "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

                    tslst@mastodon.socialT This user is from outside of this forum
                    tslst@mastodon.socialT This user is from outside of this forum
                    tslst@mastodon.social
                    wrote sidst redigeret af
                    #98

                    @cR0w AI is giving its user an advantage and that only shows how human nature is destructive in general. It's still time to apply it to better means. What are YOU doing?

                    cr0w@infosec.exchangeC 1 Reply Last reply
                    0
                    • viss@mastodon.socialV viss@mastodon.social

                      @FuturisticRobert @krypt3ia @cR0w my hottub runs off the powerwall. when the grid goes down that party's ay my place. bring swimtrunks and something for the smoker

                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchangeC This user is from outside of this forum
                      cr0w@infosec.exchange
                      wrote sidst redigeret af
                      #99

                      @Viss @FuturisticRobert @krypt3ia Swim trunks? I thought it was a party.

                      1 Reply Last reply
                      0
                      • da_667@infosec.exchangeD da_667@infosec.exchange

                        @iagox86 @cR0w @darthnull what's incredibly fun is looking at nuclei-templates repo, thinking you've found something that can serve as a proof of concept for some thing you really needed, and its a GET request that they parse with regex for version strings.

                        Thanks for that, I guess.

                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.socialV This user is from outside of this forum
                        viss@mastodon.social
                        wrote sidst redigeret af
                        #100

                        @da_667 @iagox86 @cR0w @darthnull i keep getting the impression that nuclei is just nmap nse with extra steps

                        da_667@infosec.exchangeD nf3xn@mastodon.socialN 2 Replies Last reply
                        0
                        • tslst@mastodon.socialT tslst@mastodon.social

                          @cR0w AI is giving its user an advantage and that only shows how human nature is destructive in general. It's still time to apply it to better means. What are YOU doing?

                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchange
                          wrote sidst redigeret af
                          #101

                          @TSLST Me? I can't talk about a lot of what I'm doing on the public Internet. But I can assure you that it is not with the imaginary advantage of AI.

                          tslst@mastodon.socialT 1 Reply Last reply
                          0
                          • viss@mastodon.socialV viss@mastodon.social

                            @da_667 @iagox86 @cR0w @darthnull i keep getting the impression that nuclei is just nmap nse with extra steps

                            da_667@infosec.exchangeD This user is from outside of this forum
                            da_667@infosec.exchangeD This user is from outside of this forum
                            da_667@infosec.exchange
                            wrote sidst redigeret af
                            #102

                            @Viss @iagox86 @cR0w @darthnull sometimes, it can be pretty helpful. If for no other reason, the references sometimes point to an actual write-up instead of nuclei's meta-request template bullshit.

                            1 Reply Last reply
                            0
                            • iagox86@infosec.exchangeI iagox86@infosec.exchange

                              @da_667 @cR0w @darthnull omg, it's the worst.

                              The WORST part is that I've found that an LLM is the best way to deal with that shit.. it's way better at filtering results down to just useful PoCs (having to use AI to fight AI makes me incredibly sad though 😞 )

                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.socialV This user is from outside of this forum
                              viss@mastodon.social
                              wrote sidst redigeret af
                              #103

                              @iagox86 @da_667 @cR0w @darthnull ive found making gpt 5.4 do research for me and force it to provide sources seems to take marginally less time than slogging through websites by hand and clicking through the 200 modal popups, login with google, youve reached your free article limit, solve this capacha to see the blogpost, 10 second timer newsletter popup modal bullshits

                              1 Reply Last reply
                              0
                              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                @TSLST Me? I can't talk about a lot of what I'm doing on the public Internet. But I can assure you that it is not with the imaginary advantage of AI.

                                tslst@mastodon.socialT This user is from outside of this forum
                                tslst@mastodon.socialT This user is from outside of this forum
                                tslst@mastodon.social
                                wrote sidst redigeret af
                                #104

                                @cR0w I read this as: rather than figure out a positive use of this tool, you would rather prevent anyone from using it? What' your policy on kitchen knives and cars?

                                cr0w@infosec.exchangeC 1 Reply Last reply
                                0
                                • jackryder@infosec.exchangeJ jackryder@infosec.exchange

                                  @cR0w I got this great idea, right?
                                  So you know the game darts? You throw a sharp pointy metal spike at a wall... right?

                                  What if... get this... instead of a tiny little bitch spike, we go full 9inches? Have kids throw them just straight in the air... see what happens.

                                  What'cha think?

                                  S This user is from outside of this forum
                                  S This user is from outside of this forum
                                  sjcooke66@mastodon.social
                                  wrote sidst redigeret af
                                  #105

                                  @jackryder @cR0w I think that;s what's happening in Ukraine right now, but the kids aren't the ones throwing the darts!

                                  1 Reply Last reply
                                  0
                                  • tslst@mastodon.socialT tslst@mastodon.social

                                    @cR0w I read this as: rather than figure out a positive use of this tool, you would rather prevent anyone from using it? What' your policy on kitchen knives and cars?

                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchange
                                    wrote sidst redigeret af
                                    #106

                                    @TSLST Kitchen knives and cars were created for a specific benefit. AI is a grift trying hard to find a benefit beyond further enriching the rich. The fact that it's being pushed so hard while people "figure out a positive use of this tool" should be the tell.

                                    1 Reply Last reply
                                    0
                                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                      "AI is giving attackers a huge advantage!"

                                      "Yes, it is. It's amazing how quickly it has destroyed dev, sec, ops, management, company missions and priorities, regulations, information literacy, and civil society, making everyone more vulnerable."

                                      cjd@pkteerium.xyzC This user is from outside of this forum
                                      cjd@pkteerium.xyzC This user is from outside of this forum
                                      cjd@pkteerium.xyz
                                      wrote sidst redigeret af
                                      #107
                                      Junior Dev: I gotta deliver this database app tomorrow, can you code it for me?

                                      Claude: Sure!

                                      Hacker: This shitty database thingy looks vibe coded, can you find an exploit in it?

                                      Claude: Find? I already know one!
                                      1 Reply Last reply
                                      0
                                      • mustardfacial@infosec.exchangeM mustardfacial@infosec.exchange

                                        @rootwyrm @cR0w @jackryder God dammit. This is the worst fucking timeline.

                                        S This user is from outside of this forum
                                        S This user is from outside of this forum
                                        sjcooke66@mastodon.social
                                        wrote sidst redigeret af
                                        #108

                                        @Mustardfacial @rootwyrm @cR0w @jackryder The Matrix timeline anybody? Better?..

                                        1 Reply Last reply
                                        0
                                        • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                          @lycanoid I wish I could tell if you were being genuine or sarcastic, but this is the Internet so... help me out please. 😆

                                          lycanoid@ieji.deL This user is from outside of this forum
                                          lycanoid@ieji.deL This user is from outside of this forum
                                          lycanoid@ieji.de
                                          wrote sidst redigeret af
                                          #109

                                          @cR0w of course they care about children. A good part of the world’s “elite” had (and probably still has) parties on private islands with children attending.

                                          cr0w@infosec.exchangeC 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper