Sign in

harisec

@harisec.bsky.social
2.4K followers 750 following 36 posts

Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp

PostsRepliesMedia
harisec @harisec.bsky.social · 03/12/2025
I wrote a blog post about how I use Claude Code (and other models) in my work: invicti.com/blog/securit...
invicti.com
Security Research in the Age of AI Tools
Learn how AI tools can support security researchers in investigating vulnerabilities and designing security checks to detect them.
073
harisec @harisec.bsky.social · 06/11/2025
I generated 20k vibe-coded web applications using various models via the OpenRouter API and analyzed them for security issues. The apps are available for download if anyone wants to take a look. www.invicti.com/blog/securit...
invicti.com
Security Issues in Vibe-Coded Web Apps: Analysis, Vulnerabilities, Scanning
Learn about common security issues in AI-generated software, based on an analysis of over 20,000 vibe-coded web apps.
062
harisec @harisec.bsky.social · 24/09/2025
I wrote a blog post about enumerating and testing tool usage in web applications that use LLMs: www.invicti.com/blog/securit...
invicti.com
LLM Tool Usage Security
Learn how attackers can exploit LLM tool usage and MCP servers, why this expands the attack surface, and how automated DAST scanning strengthens LLM security in web applications.
042
harisec @harisec.bsky.social · 28/06/2025
Here are the slides from my @tumpicon.org talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU) docs.google.com/presentation...
docs.google.com
Teaching LLMs how to XSS
Teaching LLMs how to XSS An introduction to fine-tuning and reinforcement learning (using your own GPU)
0196
harisec @harisec.bsky.social · 13/01/2025
I wrote an article about how it's possible to use Assistant Prefill to jailbreak LLMs (Large Language Models). Here is an example of the latest model from Microsoft (Phi-4) writing a phishing email:
141
harisec @harisec.bsky.social · 02/01/2025
My favorite talk from #38c3: From Pegasus to Predator - The evolution of Commercial Spyware on iOS - media.ccc.de/v/38c3-from-...
media.ccc.de
From Pegasus to Predator - The evolution of Commercial Spyware on iOS
My talk explores the trajectory of iOS spyware from the initial discovery of Pegasus in 2016 to the latest cases in 2024. The talk will ...
080
harisec @harisec.bsky.social · 31/12/2024
Great paper from Orange Tsai about unicode transformations: worst.fit/assets/EU-24...
worst.fit
0124
harisec @harisec.bsky.social · 20/12/2024
OpenAI o3 model just achieved unbelievable scores (75% and 87%) on ARC-AGI, the previous models made maximum 20% and humans make around 85%. arcprize.org/blog/oai-o3-...
arcprize.org
OpenAI o3 Breakthrough High Score on ARC-AGI-Pub
OpenAI o3 scores 75.7% on ARC-AGI public leaderboard.
031
harisec @harisec.bsky.social · 17/12/2024
Must read if you are interested in test-time compute: huggingface.co/spaces/Huggi...
huggingface.co
Scaling test-time compute - a Hugging Face Space by HuggingFaceH4
Discover amazing ML apps made by the community
020
harisec @harisec.bsky.social · 12/12/2024
Great read: semianalysis.com/2024/12/11/s...
semianalysis.com
Scaling Laws – O1 Pro Architecture, Reasoning Training Infrastructure, Orion and Claude 3.5 Opus “Failures”
There has been an increasing amount of fear, uncertainty and doubt (FUD) regarding AI Scaling laws. A cavalcade of part-time AI industry prognosticators have latched on to any bearish narrative the…
051
Reposted by harisec
RyotaK @ryotak.net · 07/12/2024
If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos... For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
0178
Reposted by harisec
ϻг_ϻε @steven.srcincite.io · 06/12/2024
Here is a great follow up blog post to my blog Remote Code Execution with Spring properties written by Elliot Ward: snyk.io/articles/rem...
snyk.io
Remote Code Execution with Spring Boot 3.4.0 Properties | Snyk
this article introduces two methods for leveraging Logback configuration to achieve Remote Code Execution (RCE) in Spring Boot applications. These techniques are effective on the latest version of Spr...
0218
Reposted by harisec
renniepak @renniepak.nl · 04/12/2024
Pro tip for if you have XSS but you can only use upper case: aem1k.com/transliterat... transliterate.js by @aemkei.bsky.social works great!
aem1k.com
transliterate.js
Translate any JavaScript code to foreign writing systems. Created by Martin Kleppe aka @aemkei.
0216
harisec @harisec.bsky.social · 30/11/2024
embracethered.com/blog/posts/2...
embracethered.com
DeepSeek AI: From Prompt Injection To Account Takeover · Embrace The Red
This post discusses how I found and responsibly disclosed a Cross Site Scripting in DeepSeek and it was possible to trigger it via Prompt Injection to achieve complete account takeover. The issue was ...
0122
Reposted by harisec
Jeremy Howard @howard.fm · 28/11/2024
FYI, here's the entire code to create a dataset of every single bsky message in real time: ``` from atproto import * def f(m): print(m.header, parse_subscribe_repos_message()) FirehoseSubscribeReposClient().start(f) ```
1944262
Reposted by harisec
Jeremy Howard @howard.fm · 28/11/2024
A librarian that previously worked at the British Library created a relatively small dataset of bsky posts, hundreds of times smaller than previous researchers, to help folks create toxicity filters and stuff. So people bullied him & posted death threats. He took it down. Nice one, folks.
2858258
Reposted by harisec
Simon Willison @simonwillison.net · 28/11/2024
qwq is a new openly licensed LLM from Alibaba Cloud's Qwen team. It's an attempt at the OpenAI o1 "reasoning" trick that runs on my Mac (20GB download) via Ollama... and it's pretty good! My detailed notes here: simonwillison.net/2024/Nov/27/... - here's its attempt an SVG pelican riding a bicycle.
An SVG of a pelican riding a bicycle. It's quite abstract. The bicycle is two half circles and a simple frame. The pelican is sky blue with spread wings and a curved neck leading to a small head. It has definite pelican vibes.
48010
harisec @harisec.bsky.social · 26/11/2024
I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social
5389
Reposted by harisec
Jake Handy @jakehandy.com · 24/11/2024
Cursor, the top performing #AI IDE, launched version 0.43 today with support for 🥁… Agents! Composer can now “pick its own context, use terminal, and complete entire tasks” give it a whirl: www.cursor.com
253
Reposted by harisec
shubs @shubs.io · 22/11/2024
Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE. Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
15023
Reposted by harisec
Gynvael Coldwind @gynvael.bsky.social · 20/11/2024
We're doing a cool online talk tomorrow btw – hexarcana.ch/workshops/cv...
hexarcana.ch
CVEs of SSH
A talk about recent high-profile issues related to the SSH ecosystem.
2218
Reposted by harisec
terjanq @terjanq.me · 19/11/2024
Great article about multipart parsing. Reminds me about the bypasses I found in modsec parser medium.com/@terjanq/waf...
medium.com
WAF bypasses via 0days
based on findings from a live hacking event
1237
Reposted by harisec
Sam Stepanyan @securestep9.bsky.social · 19/11/2024
#WAF: "When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls" - by @MDSecLabs: 👇 www.mdsec.co.uk/2024/10/when...
mdsec.co.uk
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls - MDSec
Web Application Firewalls (WAFs) help to protect web applications by monitoring, filtering, and blocking HTTP traffic to and from a web service. However, WAFs are too often relied upon as...
162
Reposted by harisec
jiska @naehrdine.bsky.social · 17/11/2024
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
naehrdine.blogspot.com
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
12277106
Reposted by harisec
Matthew Cashew @cashewsec.bsky.social · 18/11/2024
As a pentester and security engineer, I found this talk to be very inspiring. I haven't been able to use the tool yet, but you can bet I will soon! youtu.be/bCNnloBaw_U?...
youtu.be
The Dangers of Building a Recursive Internet Scanner by Joel Moore | BSides CHS 2024
YouTube video by BSidesCHS
0144
harisec @harisec.bsky.social · 14/11/2024
xbow.com/blog/xbow-sc...
xbow.com
XBOW – How XBOW found a Scoold authentication bypass
As we shift our focus from benchmarks to real world applications, we will be sharing some of the most interesting vulnerabilities XBOW has found in real-world, open-source targets. The first of these ...
000
harisec @harisec.bsky.social · 13/11/2024
I will definitelly do something with the BlueSky Firehose, that sounds very interesting. joelgustafson.com/posts/2024-1...
joelgustafson.com
Visualizing 13 million BlueSky users | Joel Gustafson
000
harisec @harisec.bsky.social · 12/11/2024
Recraft's new model, unlike typical diffusion models, can handle math and geography - a surprising capability for an image generator. I wrote an article about abusing this functionality to leak its system prompt (using only generated images). www.invicti.com/blog/securit...
invicti.com
System prompt exposure: how AI image generators may leak sensitive instructions
Recraft's image generation service uses a unique architecture combining an LLM (Claude) with a diffusion model. Learn what led to the discovery that carefully crafted prompts could expose the system's...
010
harisec @harisec.bsky.social · 29/10/2024
I wrote a blog post about analyzing WordPress hack access logs with #NotebookLM www.invicti.com/blog/securit...
invicti.com
Analyzing WordPress Hack Access Logs With NotebookLM
Learn how to analyze WordPress hack access logs using Google's NotebookLM, featuring a real-world case study of detecting and investigating a CVE-2023-6961 exploit in the WP Meta SEO plugin through in...
040