Posts by neurovagrant@masto.deoan.org
(DIR) Post #APxcmWlCWgzbddnKG8 by neurovagrant@masto.deoan.org
0 likes, 0 repeats
Some introductory information: I'm a security operations engineer in the cybersecurity space, a lovingly hungry reader (nonfiction, speculative fiction, and horror especially), a sometimes-writer when I have the brainspace for it.I love crows, spooky things, democracy, and coffee.I'm at times depressed, or anxious, and diagnosed autistic so I talk about neurodivergence too.
(DIR) Post #AYxtcwwq5HlY3PBxoW by neurovagrant@masto.deoan.org
0 likes, 0 repeats
Hello friends, I've seen the below image come up a few times elsewhere and am going to expound a little! While the hyperlinks in the image display correctly, those aren't actually the addresses of those sites! Instead, they're the Internationalized Domain Name replacements - examples of what are called IDN Homograph Attacks.It's incredibly hard to include all characters from all active alphabets in the mechanisms that resolve domain names - so currently that letter set is restricted, and instead uses a translation system called Punycode to move between a visual URL with the correct characters and a domain name your computer can actually resolve to a website. So while neurovagrant[.]com is fine either way, nӘ̃urovagrant[.]com isn't! The actually domain would be xn--nurovagrant-rkg322d[.]com.Notice that xn-- ! That's what tells browsers and other software that it's an IDN domain, and to try and translate it.Attackers use this to their benefit. So:xn--mcrosoft-security-teams-1ec[.]com can appear in your email, on your twitter feed, in other places visually as: mícrosoft-security-teams[.]comYou may think you're signing in to check your retirement at vanguarɗ[.]com but it's actually sent you to xn--vanguar-4cd[.]comA link that appears as vḙnmo[.]com actually sends you to the website xn--vnmo-q64a[.]com They even target kids! Take a look at xn--rblox-jua[.]com - which looks like röblox[.]com in most settings. Note the diacritical mark above the first o.If anything looks off, there's a reason. Always view links with skepticism, don't click on things unnecessarily, and always sign into the sites you use by going to the domain name you know. Stay frosty out there, friends.#cybersecurity #infosec #StayFrosty
(DIR) Post #AreW8XxhKFBaDFH4Vc by neurovagrant@masto.deoan.org
0 likes, 0 repeats
"What radicalized you?"When they DRM'd coffee.
(DIR) Post #B47eWfRDmm1bf6VPZQ by neurovagrant@masto.deoan.org
1 likes, 2 repeats
When I started in security, one of the prevailing attitudes was "The weakest link in the chain will always be the human."I would like to thank every LLM provider and startup for changing this paradigm by introducing a much weaker link in the chain.
(DIR) Post #B4baGwT28Io8llOgOu by neurovagrant@masto.deoan.org
0 likes, 1 repeats
i love that we went from "zero trust" as a fundamental buzzword to "trust autonomous nondeterministic agents everywhere in your stack"
(DIR) Post #B4rUNPXLTWX1T7TSj2 by neurovagrant@masto.deoan.org
0 likes, 0 repeats
RE: https://mastodon.social/@adamndsmith/116328215860941572The perfect merger of "Go to the cloud," they said, "It'll be fine," they said,and"AI is going great"has happened, @VissRT: https://mastodon.social/users/adamndsmith/statuses/116328215860941572
(DIR) Post #B4vW00E0OZHmqTEXs8 by neurovagrant@masto.deoan.org
1 likes, 0 repeats
RE: https://social.lansky.name/@hn50/116341899721749250oh jesus tapdancing christRT: https://social.lansky.name/users/hn50/statuses/116341899721749250
(DIR) Post #B4vW00Q3fkvXRqsAeu by neurovagrant@masto.deoan.org
1 likes, 0 repeats
i know i'm an AI skeptic, but i did not expect "virally popular agent does no authentication checks before escalating system privileges"
(DIR) Post #B4vW07OtiT9r6HNqK0 by neurovagrant@masto.deoan.org
1 likes, 0 repeats
thing is, this is likely to cause many downstream enterprise breaches, even in enterprises that actively ban openclaw. unauthorized instances, or instances that allow a threat actor to pivot from private hardware to work hardware. pure negligence, rolling OpenClaw out in the way they did, both the devs and all the hosting companies that saw profit in providing easy-install packages.
(DIR) Post #B4vW08wFzvR7s1zzxQ by neurovagrant@masto.deoan.org
1 likes, 0 repeats
the other fun part?even if you don't set up an exposed instanceeven if you require authif any entity you pair openclaw with gets compromised, regardless of its permissions level, it can escalate to admin and pwn you
(DIR) Post #B5zy9F2qHkSWZ2Yr68 by neurovagrant@masto.deoan.org
1 likes, 0 repeats
A brave new world: we experienced our first EDR detection due to LLM activity today. The sanctioned coding assistant, operated by a linux subject matter expert, was writing files to /tmp/ and loaded a DLL, causing a low-confidence machine learning hit and notifying SecOps. Upon investigation the activity was tracked back to the coding assistant doing unexpected things in especially dumb ways. Be ye wary of the clankers.
(DIR) Post #B6tYq3qaYTSRh75qEa by neurovagrant@masto.deoan.org
1 likes, 0 repeats
I'm just a SecOps and Threats guy, not selling a damn thing, so whenever you talk about AI "democratizing" capabilities to the average enterprise employee, I want you to keep in mind for me that short of herculean new spends and deliberate frameworks, you're democratizing some software capabilities but without the development, QA, monitoring, and responsibility offload. We've been working with the concept of Third Party Risk Management for years and are barely in its infancy - yet even so, none of the lessons TPRM has taught us so far have been natively incorporated into AI products, and especially not executive or board mandates demanding employees increase AI use or agentic deployment.Simply put, none of the forethought or structure that real software development requires, little of the centralized administration or visibility for defenders to work with, but all of the consequences. Whenever someone in your presence starts talking about how employees should script Gems or Projects or Skills or gizzards or whatever the customized agentic buzzword of the day is, and give it trusted access to their email or calendar or, god forbid, customer data, remember that it has precisely zero of the attention and accountability that Third Party Risk Management involves. And TPRM is a critical path.
(DIR) Post #B7KJC98EGfyegJZq9g by neurovagrant@masto.deoan.org
0 likes, 0 repeats
RE: https://infosec.exchange/@ifin/116732602137426733Ad blocking is a security measure, given the failure of ad platforms to keep malicious actors out. Like any defense, it works best in layers - consider adding this on the DNS level as well.If that sounds daunting? It's not, especially with off-the-shelf services like NextDNS*, which also have a good amount of adaptability.(*I have no connections to NextDNS other than as a happy customer.)RT: https://infosec.exchange/ap/users/115741367687413652/statuses/116732602137426733
(DIR) Post #B7KJCLBVSJjG3xCcvg by neurovagrant@masto.deoan.org
0 likes, 0 repeats
I'd be remiss if I didn't mention this - NextDNS also makes @pgl 's blocklist available, and I highly recommend it. He's constantly working on more resources and services to protect folks, and you should pay keen attention to anything he's doin'!