application security person with an interest in music, AI, and digital art

Joined September 2019
3 Photos and videos
welcome to the future #chatgpt5
9
🚀@github can now leverage @MSFTCopilot to auto-magically fix your code if there are any breaking changes introduced by a @dependabot update. only supports #typescript for now but this will be huge github.blog/changelog/2024-1… #appsec #cybersecurity #githubuniverse2024

1
1
380
very interesting conversation from @lexfridman and the @cursor_ai team about the tools we use to write code, how to best incorporate AI, and the future of programming more generally. youtube.com/watch?v=oFfVt3S5… #AI #githubcopilot #vscode

28
AppSec Charlie retweeted
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6). * Still no working fix. * Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot. * Devs are still arguing about whether or not some of the issues have a security impact. I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
82
484
2,766
364,868
AppSec Charlie retweeted
This is a wake up reminder that you shouldn’t have an internet connected privileged binary running on your production systems. What was a bad update could have easily been a massive adversary backdoor. A third party vendor will always be the weakest link. Isolate critical systems
692
1,898
11,596
27,167,076
if you're sourcing scripts from cdn.polyfill.io, don't

20
here's #PrintListener.. in example #1434 of why audio hackers are doing the most interesting work, how about using the sound of your finger on a touchscreen to reconstruct your fingerprint and bypass biometrics? ndss-symposium.org/wp-conten… #hacking #biometrics #cybersecurity

17