mbg
@mbrg0.bsky.social
Breaking AI. Building @zenitysec, lead @owaspnocode, columnist @DarkReading
join us tmrw! its going to be .. well .. we've got something for everybody!
blackhat[.]com/us-25/briefings/schedule/index.html#ai-enterprise-compromise---0click-exploit-methods-46442
blackhat[.]com/us-25/briefings/schedule/index.html#ai-enterprise-compromise---0click-exploit-methods-46442
August 5, 2025 at 7:02 PM
join us tmrw! its going to be .. well .. we've got something for everybody!
blackhat[.]com/us-25/briefings/schedule/index.html#ai-enterprise-compromise---0click-exploit-methods-46442
blackhat[.]com/us-25/briefings/schedule/index.html#ai-enterprise-compromise---0click-exploit-methods-46442
Reposted by mbg
You missed one thing in your (excellent) analysis: the attacker was clever enough to pull this off (and it is amazingly done), but still wasn't able to solve for Amazon Q CLI's dogshit ergonomics.
July 25, 2025 at 1:01 AM
You missed one thing in your (excellent) analysis: the attacker was clever enough to pull this off (and it is amazingly done), but still wasn't able to solve for Amazon Q CLI's dogshit ergonomics.
this could have been much worse
bsky.app/profile/mbrg...
bsky.app/profile/mbrg...
After several hours of GitHub dorking on the Amazon Q infection we have:
- hacker's user and intent
- downloader
- prompt payload
- evasion techniques
- timeline from july 13 thru was mitigation and cover
big open questions: how did lkmanka58 gain initial access? is this the only user involved?
- hacker's user and intent
- downloader
- prompt payload
- evasion techniques
- timeline from july 13 thru was mitigation and cover
big open questions: how did lkmanka58 gain initial access? is this the only user involved?
July 24, 2025 at 11:31 PM
this could have been much worse
bsky.app/profile/mbrg...
bsky.app/profile/mbrg...
down the rabbit hole
www.mbgsec.com/posts/2025-0...
www.mbgsec.com/posts/2025-0...
July 24, 2025 at 1:35 PM
down the rabbit hole
www.mbgsec.com/posts/2025-0...
www.mbgsec.com/posts/2025-0...
here we go www.blackhat.com/us-25/briefi...
Black Hat
Black Hat
www.blackhat.com
May 12, 2025 at 11:04 PM
here we go www.blackhat.com/us-25/briefi...