harisec
@harisec.bsky.social
2.3K followers
750 following
34 posts
Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp
Posts
Media
Videos
Starter Packs
Pinned
harisec
@harisec.bsky.social
· Nov 26
harisec
@harisec.bsky.social
· Dec 12
Scaling Laws – O1 Pro Architecture, Reasoning Training Infrastructure, Orion and Claude 3.5 Opus “Failures”
There has been an increasing amount of fear, uncertainty and doubt (FUD) regarding AI Scaling laws. A cavalcade of part-time AI industry prognosticators have latched on to any bearish narrative the…
semianalysis.com
Reposted by harisec
RyotaK
@ryotak.net
· Dec 7
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc.
A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
flatt.tech
Reposted by harisec
ϻг_ϻε
@steven.srcincite.io
· Dec 6
Remote Code Execution with Spring Boot 3.4.0 Properties | Snyk
this article introduces two methods for leveraging Logback configuration to achieve Remote Code Execution (RCE) in Spring Boot applications. These techniques are effective on the latest version of Spr...
snyk.io
harisec
@harisec.bsky.social
· Nov 30
DeepSeek AI: From Prompt Injection To Account Takeover · Embrace The Red
This post discusses how I found and responsibly disclosed a Cross Site Scripting in DeepSeek and it was possible to trigger it via Prompt Injection to achieve complete account takeover. The issue was ...
embracethered.com
harisec
@harisec.bsky.social
· Nov 29
Reposted by harisec
Jeremy Howard
@howard.fm
· Nov 28
harisec
@harisec.bsky.social
· Nov 28
Reposted by harisec
Jeremy Howard
@howard.fm
· Nov 28
Reposted by harisec
harisec
@harisec.bsky.social
· Nov 28
harisec
@harisec.bsky.social
· Nov 27
harisec
@harisec.bsky.social
· Nov 26
harisec
@harisec.bsky.social
· Nov 26