Join me for the next @offby1security stream at 11AM PT Thursday, June 11th (Today) with @Alh4zr3d for a session on offensive tooling, tradecraft, research, and perhaps a little black magick!
youtube.com/watch?v=4Es2Sc3s…
Join us this Friday (May 22nd) at 11AM PT on the next @offby1security stream with guest Brooks McMillin for a session on "Confused Deputies & Stolen Tokens: Breaking and Rebuilding MCP Auth!"
youtube.com/watch?v=Wp8U1CEl…
ACID, the offensive AI security testing platform is now available to enterprises. It solves a lot of the challenges seen out there such as using a connector agent that runs on your prem allowing for control & internal testing. Reach out for a demo below:
acidapp.ai/#contact
Join us this Friday (May 22nd) at 11AM PT on the next @offby1security stream with guest Brooks McMillin for a session on "Confused Deputies & Stolen Tokens: Breaking and Rebuilding MCP Auth!"
youtube.com/watch?v=Wp8U1CEl…
The video from @htejeda & I "The Challenges of Building an AI-driven Security Testing Platform & How We Solved Them" is up on YouTube!
We discuss challenges like transparency, validation, authentication, access limitations, ...
youtube.com/live/3s1fXVqzn9E…acidapp.ai
Please join us on the next @offby1security stream this Friday at 11AM PT with @htejeda for a session on "The Challenges of Building an AI-driven Security Testing Platform and How We Solved Them." We will be announcing more streams shortly!
youtube.com/watch?v=3s1fXVqz…
With the low barrier to entry for vulnerability research due to AI, that used to require advanced and niche skills, I'm seeing that exploit mitigation bypasses are still difficult for AI. Weaponizing vulnerabilities still requires advanced knowledge. Disclosure != Skill...
We at @offby1security saw an interesting defense against AI-powered offensive agents recently. Fingerprinting of the agents performing the testing resulted in misleading, honeypot-like responses, attempting to distract or redirect them. It didn't work but worth noting.
Would you be interested in a stream on the @offby1security channel covering the costs between using different Frontier models to discover the same vulnerabilities and the changes to the prompts and testing methodologies to find them?
Join me this Wednesday at 10AM PT for the next @offby1security stream with guest Josselin Feist (@Montyly) for a session on "Offensive Security in Web3: From Exploit Mindset to DeFi Precision Bugs!"
youtube.com/watch?v=HuWi863z…