- Hive Five
- Posts
- š Hive Five 135 - The A.I. Dilemma
š Hive Five 135 - The A.I. Dilemma
Hi friends,
Greetings from the hive!
I was shocked to hear that Kris Nova suddenly passed away. I didnāt know her well, but I knew of her, and would occasionally tune into her streams.
My condolences go out to her family and friends. What stood out to me, besides her brilliance, was her love for community and relentless drive. She made things better.
Iām afraid to live, but Iām glad she did. Showing us the way.
RIP.
Letās take this week by swarm!
š The Beeās Knees
The A.I. Dilemma, March 9, 2023. Tristan Harris and Aza Raskin discuss how existing A.I. capabilities already pose catastrophic risks to a functional society, how A.I. companies are caught in a race to deploy as quickly as possible without adequate safety measures, and what it would mean to upgrade our institutions to a post-A.I. YOUTUBE
SAMLjacking a poisoned tenant. A demo combining two new SaaS attack techniques to make a simple, but effective attack chain. PUSHSECURITY
How Daniel Miessler went from a $350K FTE to $700K+ doing his own thing. And so could you. DANIELMIESSLER
DEFCON 31 Recon Village talks are up and ready for you to consume. YOUTUBE
Zero Touch Pwn: Abusing Zoomās Zero Touch Provisioning for Remote Attacks on Desk Phones. SYSS
Which Beeās Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
ļøšŖ Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
š„ Buzzworthy
ā Changelog
Noir v0.4.0 now supports Swagger analysis. When Swagger documents are detected in the target source code, the tool analyzes those files to identify and extract endpoints. GITHUB
šØ News
AI-Powered Fuzzing: Breaking the Bug Hunting Barrier. Using LLMs is a promising new way to scale security improvements across the over 1,000 projects currently fuzzed by OSS-Fuzz and to remove barriers to future projects adopting fuzzing. GOOGLEBLOG
Researcher says they were behind iPhone popups at Def Con. TECHCRUNCH
š Celebrate
š° Career
The Pivot with Jane Frankland: Women In Cyber and IN Security Movement. Jane is a tech entrepreneur, book author, international speaker, and passionate womenās change agent. YOUTUBE
2023 Roadmap To Your First Cybersecurity Job. YOUTUBE
From Mid to Senior: Time Management and Prioritization. Stepping up the ladder from a mid-level developer to a senior role can feel like entering a whole new universe. IVANNOVAK
Former Google recruiterās No. 1 resume red flag: āThereās zero chance youāre going to move forwardā. There are various donāts to keep in mind: Donāt misspell words. Donāt go over two pages. Donāt write a list of vague skills without providing proof youāve actually accrued them. CNBC
ā”ļø Community
Idea Amplification: Be a Hype Man For Your Friends. Rez0 explains the benefits of hyping up your friendsā ideas. REZ0
The Critical Thinking podcast want to know what youād like to see next. Let them know! TWITTER
Non-tech related things that hackers nerd out about. Haklukeās ones are: backpacks, flashlights, jazz, trumpet, minimalism, and camping. TWITTER
BugBountyHQ is a year older. Happy belated birthday! TWITTER
Rodolfo has been suffering from severe mental health issues. He asks for support by sharing his work and tool, KNOXSS. TWITTER
š° Read
Spring WebFlux ā CVE-2023-34034 Write-Up and Proof-of-Concept. Spring Securityās newly released versions contain a fix for a broken access control vulnerability. JFROG
Knocking on the Front Door (client side desync attack on Azure CDN). A few months ago, Jeti embarked on a security bug hunt within the scope of a private program available through the Intigriti platform. JETI
Michael shares some automation pitfalls and success in bug bounty. TWITTER
How Nagli earned 5-figure bounties from sensitive links, sent via email, that were leaked without any user interaction. TWITTER
Justin explains how skilled hackers find complex and creative bugs using chains of gadgets. TWITTER
š Support
Enjoy reading the Hive Five? You can treat me to a coffee!
You can also share the newsletter with your friends.
š” Tips
Random Robbie on leveraging the wayback machine browser extension. TWITTER
Hackers share the little things theyāve picked up along the way that stand out. TWITTER
Learn more about these TruffleHog commands: Git vs Filesystem. TRUFFLESECURITY
Join Louis as he introduces the power of tabletop exercises in enhancing your application security and team dynamics. YOUTUBE
šÆ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@DfirDiva | DFIR Diva | Jr IR Analyst trying to learn all the things | DFIR Blog for Beginners | Founder @GetYourStart.
@i_bo0om | Bo0oM | Web application security researcher@sploitus_com.
@sobedominik | Dominik Sobe | Indie Hacker and Surfer tweeting about bootstrapping SaaS. Sharing my lessons. Currently turning Notion Docs āÆ professional Help Center @HelpkitHQ.
@Rhynorater | Justin Gardner | Christian | Full-time Bug Bounty Hunter | 2x HackerOne MVH | Host of @ctbbpodcast | English, ę„ę¬čŖ | ā„ļø @mariahchan_ ā„ļø.
@flaviocopes | flavio.
š Productivity
How to Give Yourself Time to Think. Whether itās for a few hours, a few days, or a full week, everyone needs dedicated time to reflect. BESIDE
Write about what you learn. It pushes you to understand topics better. ADDYOSMANI
Adam on the value of automated checkins to keep a company (or person) focused, and working on the right things. TWITTER
TIL that if you hold down CTRL in Windows, the process list in Task Manager freezes so you can select rows without them jumping around. TWITTER
Obsidianās composability of templates will speed up your workflow. TWITTER
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. Itās my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
š Technology
Makefile Tutorial by Example. Chase built this guide because they could never quite wrap my head around Makefiles ā me neither! MAKEFILETUTORIAL
dnakov/little-rat is a small chrome extension to monitor other extensionsā network calls. GITHUB
dillionverma/llm.report is an open-source logging and analytics platform for OpenAI Introduction. GITHUB
Why there arenāt more women in STEM. Comms Specialist and STEM/Space Influencer Alexandra shares her story. REDDIT
The Problem with Linus Tech Tips: Accuracy, Ethics, & Responsibility. This video covers our serious concerns regarding the data accuracy of Linus Media Group, including Linus Tech Tips, ShortCircuit, and TechQuickie. YOUTUBE
š§ Wisdom
āIf you have only one leg to a stool, itās easy to kick out.ā ā Dr. Gurner
Justin reminds us of the bigger picture: āwhen youāre learning bug bounty, failing is a small W.ā ā I agree, and would apply that to all areas of life. TWITTER
Steph on creating: āWhen you have conviction that something should exist in the world, donāt let too many voices dilute that vision.ā TWITTER
Learning to be okay with not doing bug bounty full-time is something Jason had to learn. TWITTER
š Cross-pollination
An 800 square feet garden in San Franciscoās Mission District. Planning started in 2015 and we finally planted in January 2017. ZACHKLEIN
RetroFlix is a project archiving public domain films, TV shows and cartoons. RETROFLIX
Halli talks about why he creates, obsessively, at Kinference in NYC. TWITTER
Danny Postma, a prolific solopreneur, shares lessons learned over the years ā I liked this one: āBuilding a successful business is 95% marketing, 5% everything else.ā TWITTER
š Fact
āUp until 2010, it was illegal to keep beehives in New York City. Chicago, however, has a city-owned beehive on the roof of City Hall.ā
This bee fact is brought to you by The Beekeeperās Bible: Bees, Honey, Recipes & Other Home Uses.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- ā¢ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- ā¢ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- ā¢ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- ā¢ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- ā¢ Deep DISCOUNTS on paid content.
- ā¢ Experience continuously added NEW BENEFITS.