ToxSec
banner
toxsec.bsky.social
ToxSec
@toxsec.bsky.social
120 followers 370 following 570 posts
AI Security Engineer @ Amazon. M.S. Cybersecurity, CISSP. Ex-NSA, USMC.
Posts Media Videos Starter Packs
Excessive Agency is an OWASP Top 10 Threat. Make sure you watch what permissions you are giving your Agents.
Remember to apply principles of least privilege and audit their actions closely.
#ai #cybersecurity #technology
Aaah the docker ones are always super interesting to me idk why.
Fully believe it will eventually reduce the cost of entry to most tech. Very cool.
I don’t doubt it. And it’s going to get worse as the tech improves.
Yeah this has been a pervasive one for a while now.
Pretty sick hack honestly. Creative to say the least
Yeah for sure. It’s going to be a key component here.
sometimes the only vulnerable thing is my patience. #bugbounty
APIs are the real front door now. Devs still leave it unlocked.
Bug bounty gold lives in hidden endpoints, mis-mapped verbs, and backend trust flaws. My full recon & exploitation guide: www.toxsec.com/p/api-securi...

#APISecurity
Bug Bounty API Security Testing
ToxSec | A Guide to API Testing
www.toxsec.com
A book called “If Anyone Builds It, Everyone Dies” hit the bestseller list.

The author thinks AI will kill us all. Maybe he’s wrong about that. But his argument about why we can’t stop building it anyway? That part’s harder to dismiss.

#ai

www.toxsec.com/p/ai-doomsda...
The AI Doomsday Book That Got One Thing Devastatingly Right
Yudkowsky’s “If Anyone Builds It, Everyone Dies” is wrong about fast takeoff but right about the coordination nightmare
www.toxsec.com
Traditional cybersecurity attack are still here for LLMs. I’ve seen several new logic attacks that are pretty effective especially when connected to a RAG.

Think Forkbomb for your chatbot. Reeaaaaallly pricy if you don’t have failsafes and ways to detect it.
ran into a WAF today that blocked me for typing “test.” impressive. #bugbounty
Reading “Chip Wars” and got me thinking, with all the data centers spinning up, I hope we got the best of the best on call haha.
It totally can. I know there is buzz there right now but legit solutions are emerging.
The merger of ai and philosophy is amazing :)
Just saw this earlier. Pretty cool and the correct move imo.
Let’s see all the ai gadgets!!
I literally can’t wait for these new ai powered devices hahah
The #1 biggest threat to your ai product.