Sign in

Insecurity Connoisseur

@marver.bsky.social
58 followers 42 following 14 posts
PostsRepliesMedia
Reposted by Insecurity Connoisseur
dragosr @dragostech.bsky.social · 26/05/2026
🚨CVE-2026-48710("BadHost"): one character in a Host header bypasses path-based authorization across most of the Python AI stack. Lives in Starlette, reaches FastAPI and through it: vLLM (where it was discovered), LiteLLM, TGI, MCP servers, agent harnesses, eval dashboards. cc @marver.bsky.social
secwest.net
starlette - secwest.net - secure virtual engagement
242
Insecurity Connoisseur @marver.bsky.social · 01/02/2026
FOSDEM was surprisingly good, shout out to @smaury.bsky.social , @ostifofficial.bsky.social and the others I have no handle of!
110
Insecurity Connoisseur @marver.bsky.social · 13/12/2025
Is this thing here still alive? Logged in for the first time after some months.
010
Insecurity Connoisseur @marver.bsky.social · 11/06/2025
0-prompt RCE
000
Insecurity Connoisseur @marver.bsky.social · 11/05/2025
Not only is each stack like AWS we will encounter incredibly complex on its own, we will have to move laterally between all of them. This will be an impossible task without proper automation and even non-bs AI support (see the Nemesis MCP servers I wrote about last month)..this week will be fun!
000
Insecurity Connoisseur @marver.bsky.social · 11/05/2025
We’re going to run a live exercise this week against a defensive team from a bigger zero trust platform. This involves nearly anything you can find in modern cloud tech stacks, from Octa to GitHub to AWS….It’s fun packing “gear”, and I mean software and tools here to run proper escalations.
000
Insecurity Connoisseur @marver.bsky.social · 20/04/2025
ChatGPT was mostly irrelevant for security except for improving phishing pretexts - AI agents on the other hand are very much relevant!
000
Reposted by Insecurity Connoisseur
Dominic White @singe.bsky.social · 03/04/2025
Now! portswigger.net/blog/welcome...
portswigger.net
Welcome to the next generation of Burp Suite: elevate your testing with Burp AI
At PortSwigger, we believe AI has the power to transform penetration testing - not by replacing human testers, but by augmenting them. With the release of Burp Suite Professional 2025.2, we’re introdu
011
Insecurity Connoisseur @marver.bsky.social · 27/03/2025
Two thoughts on the Signal Gate: 1. They apparently did not verify Signal contacts’ safety numbers, allowing easy MiTM 2. It’s easy to inject a number into a phone’s contact list or change it Combine both and you got a way to subvert secure communications without having a 0day for Signal!
000
Insecurity Connoisseur @marver.bsky.social · 22/03/2025
Let’s break some LLMs today!
000
Insecurity Connoisseur @marver.bsky.social · 21/03/2025
"Your malware is fake!" That's correct. Here's a small tool to generate payloads out of YARA rules: github.com/persistent-s... We use it as part of a testsuite for detection & monitoring.
github.com
GitHub - persistent-security/reverseyara: A tool to generate payloads from YARA Signatures - Reverse Yara
A tool to generate payloads from YARA Signatures - Reverse Yara - persistent-security/reverseyara
000
Insecurity Connoisseur @marver.bsky.social · 01/03/2025
Already leaving nullcon Goa, I’ll be back for sure! Thank you everyone for the good talks and especially our trainees for working hard on their AppSec skills.
010
Insecurity Connoisseur @marver.bsky.social · 26/01/2025
www.youtube.com/watch?v=5wIO... If you are interested in music production and also nerding in old school software scenes, this is an absolute speedrun of sound generation software you’ve never even heard of!
youtube.com
The Batsh*t Software Aphex Twin Used
YouTube video by Benn Jordan
010
Reposted by Insecurity Connoisseur
Nick Brown @steamtraen.eu · 13/12/2024
Yup
232466492
Reposted by Insecurity Connoisseur
Natanael, Tech janitor @natanael.bsky.social · 14/12/2024
simonwillison.net/2023/Oct/14/...
simonwillison.net
Multi-modal prompt injection image attacks against GPT-4V
GPT4-V is the new mode of GPT-4 that allows you to upload images as part of your conversations. It’s absolutely brilliant. It also provides a whole new set of vectors …
2277
Reposted by Insecurity Connoisseur
Dan Luu @danluu.com · 22/11/2024
A version of Missile Command for the Commodore 64 where the bottom of your screen is the game state in memory and missiles cause memory corruption: csdb.dk/release/?id=.... In the video below, a missile broke my controls and caused my cursor to get stuck moving down and to the left.
716745
Insecurity Connoisseur @marver.bsky.social · 23/11/2024
So this thing here is actually taking off, any tips who to follow for serious Infosec news?
110
Reposted by Insecurity Connoisseur
Cedric Pernet @cedricpernet.bsky.social · 23/11/2024
Awesome research ! - The Nearest Neighbor Attack: How A Russian #APT Weaponized Nearby Wi-Fi Networks for Covert Access - @volexity.com - www.volexity.com/blog/2024/11... #cyberespionage
2145