Joined November 2008
4 Photos and videos
Kelvin Arcelay retweeted
Amazon is holding a mandatory meeting about AI breaking its systems. The official framing is "part of normal business." The briefing note describes a trend of incidents with "high blast radius" caused by "Gen-AI assisted changes" for which "best practices and safeguards are not yet fully established." Translation to human language: we gave AI to engineers and things keep breaking? The response for now? Junior and mid-level engineers can no longer push AI-assisted code without a senior signing off. AWS spent 13 hours recovering after its own AI coding tool, asked to make some changes, decided instead to delete and recreate the environment (the software equivalent of fixing a leaky tap by knocking down the wall). Amazon called that an "extremely limited event" (the affected tool served customers in mainland China).
949
3,214
18,660
29,868,530
Kelvin Arcelay retweeted
A little over a year ago I published research on how you could leverage non-production AWS API endpoints to enumerate permissions without logging to CloudTrail. A year later...I'm still finding them. Red Teamers, these can be super useful and really up your game!
2
21
120
7,737
Kelvin Arcelay retweeted
#Spain 🇪🇸 - Aviva Database Allegedly Leaked Reports have surfaced of a potential data breach impacting Aviva’s Spanish customer database. This alleged leak includes approximately 2.7 million records with sensitive information, such as IDs, full names, and IBANs, amounting to 288MB of data. The breach could pose significant risks to the privacy and financial security of Aviva’s customers in Spain. dailydarkweb.net/alleged-dat… #cybersecurity #databreach #Aviva #Spain
6
13
5,344
Kelvin Arcelay retweeted
29 Oct 2024
🚨DDoS ‼️ 🇮🇱Israel - Shva On October 29, 2024, a denial-of-service (DoS) cyberattack targeted Shva, Israel's main provider of IT services for the banking sector, disrupting credit card transactions across various businesses. The attack began at 7 a.m. and led to issues in transaction approvals for companies connected to Shva's network. The disruption was resolved by 9:50 a.m., with regular service restored. Though the attacker was not officially identified, reports from Bizportal suggest that "Anonymous Sudan," a group allegedly linked to Iran, may be responsible, having previously attacked Israeli entities. More details: jns.org/cyberattack-causes-c…
13
15
3,008
Kelvin Arcelay retweeted
11 Oct 2024
ssh-mitm: intercepting proxy server for security audits meterpreter.org/ssh-mitm-int…

1
59
190
9,815
Finland’s Top Power Utility Targeted With Daily Cyber Attacks | OilPrice.com oilprice.com/Latest-Energy-N… #oilprice

47