Javvad Malik
j4vv4d.com
Javvad Malik
@j4vv4d.com
320 followers 160 following 220 posts
The unholy alliance between information security and cynicism wrapped up in storytelling and videos. www.JavvadMalik.com Sole founder of Host Unknown
Posts Media Videos Starter Packs
A belated thank you very much! But at my age, you're probably going to expect a laggy response!
This is an important article highlighting the difference between AI and other injection vulnerabilities.

"..like saying that my house cat and a 650 pound wild tiger are the same because they’re both felines."
api.cyfluencer.com/s/what-s-the...
What’s the Difference Between AI Prompt Injection and XSS Vulnerabilities? - Noma Security
The ForcedLeak AI agent vulnerability raises the question, "What is the difference between AI prompt injection and XXS vulnerabilities?"
api.cyfluencer.com
Red teaming of AI Agents will become an increasingly important discussion point in the near future. As we move towards having more agents pretty much everywhere (whether we want it or not) the gap between human agent interaction being exploited more.
cybersec.pillar.security/s/agentic-ai...
Agentic AI Red Teaming Playbook
Go beyond model scores and blind fuzzing, test your agentic systems against real-world risks.
cybersec.pillar.security
L'OreSecure: Because your data’s worth it
I damn near started hyperventilating watching that!!! Cahoonas of steel!!!
Reposted by Javvad Malik
Don't forget our Call for Papers (also Rookies and Workshops) is still open!
Have you got something original and interesting to share, but need somewhere to do it?
➡️ #BSidesLDN2025

More information and to submit your proposal: cfp.bsides.london/bsides-londo...

#Security #BSides #London
🤣🤣🤣🤣
You've allowed yourself to be sucked into the world of fake Zebra news!!!! 😂

I only trust reliable sources like, "Horsesarethebest dot com" or "Neigh for Zebras dot org"
Zebra's are like horses from Temu... there, I said it! :P
Yeah, we're quite spoilt here that we can fall forwards and end up in a different country in Europe. Usually for less than the cost of a monthly SaaS subscription :)

It's also quite nice when most people are off during August. Even if you're not off, everyone else is - so peaceful! :D
You sold it so well... and for £28 return... it almost feels like a no-brainer!
Nice, balanced piece. It shows where AI can help in pen testing and the bits that still need human expertise. Worth a read if you’re looking for a grounded view of “AI as co-pilot, human as pilot” rather than hype.

api.cyfluencer.com/s/will-ai-re...
Will AI replace human pen testers?
Read more to understand the strengths and limitations of AI pen testing compared to human pen testing expertise.
api.cyfluencer.com
Reposted by Javvad Malik
Good news: some of Bluesky’s worst scolds have gathered together in the replies to this great joke so that you can block them all at once.
wow, all it took was one week of restricted access to porn.
An interesting piece on MFA downgrade attacks. The concept is quite straightforward. When users have multiple authentication methods available (say, a passkey and an SMS code), attackers can manipulate the login process to only show the weaker option.

go.j4vv4d.com/0Qv100
How attackers are getting around phishing-resistant auth
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
go.j4vv4d.com
I sometimes kind of miss the old days when the whole community was in one place on Twitter. But then again, I do enjoy not being on social media as much too.
Reposted by Javvad Malik
US woman jailed for 8yrs for stealing identities to give North Koreans IT jobs. Christina Chapman admitted to stealing the identities of 68 US citizens, then running a laptop farm from her home to help North Koreans work for 300 separate companies.
www.bbc.co.uk/news/article...
Nice knowing you B!