- Hive Five
- Posts
- π Hive Five 155 - Adversarial Machine Learning
π Hive Five 155 - Adversarial Machine Learning
Hi friends,
Greetings from the hive!
I hope youβre doing awesome. Thank you for all the well wishes. Iβm feeling significantly better again.
As Iβve mentioned several issues ago, Iβm in the process of moving the Hive Five to a new home. So, stay tuned.
My 2024 goal is to create for myself. As Rick Rubin puts it, approach things as a diary entry.
Let's take this week by swarm!
π The Bee's Knees
OTW's 2024 Roadmap to become a Master Hacker. YOUTUBE | Top 10 Hacking Tools to Learn
Best Technical Content from Year 1 of the CTBB Podcast. Watch these highlights of some of the best technical moments from the past year. YOUTUBE
NIST released a 106 page long AI Security publication. It's aptly named Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations. NIST
A disclosed report of a Yelp ATO via XSS + Cookie Bridge. TWITTER
Panic!! At the YAML. An overview of SnakeYAML deserialization vulnerabilities (CVE-2022-1471) - how it works, why it works, and what it affects. GREYNOISE
Which Bee's Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
οΈπͺ Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
π₯ Buzzworthy
β Changelog
DOMPurify 3.0.8 is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. GITHUB
π Celebrate
π° Career
Opportunity: Steve's team is hiring two experienced pentesters soon. You must live in the USA and it's 100% remote. TWITTER
Caitlin shares what an average week of a SOC Lead in a larger 24x7x365 SOC looks like. TWITTER
From $14/hr at Best Buy to 269k/yr Overseas Cybersecurity Analyst ft David. YOUTUBE
Opportunity: Technical Product Marketing Leader at Oxide. OXIDE
β‘οΈ Community
People share which hacker they've learned the most from. TWITTER
Intigriti interviewed leorac, a part-time hacker and full-time software engineer from Italy. YOUTUBE
Daniel (Curl maintainer) shares his bad experiences with security researchers that use AI to report fake bugs. He would like to ban these reporters from further communication, and states that these kinds of reports will become more common over time. HAXX
Taelur writes her first HTB write-up on Broker w/o Metasploit, an easy-level Linux machine that utilizes CVE-2023-46604. She even includes a remediation section. TAELURALEXIS
π° Read
Bitwarden Heist: How to Break into Password Vaults without Using Passwords. Sometimes, making particular security design decisions can have unexpected consequences. REDTEAM-PENTESTING
metatrapd is a canary service for cloud metadata end-points. Quietly monitors and alerts on attempts to access the cloud metadata service. GITHUB
Identity-Aware Proxy Misconfiguration, a Google Cloud Vulnerability. First, you need to know what Identity-Aware Proxy (IAP) is and how it works. IAP is a Google Cloud Platform service which helps to control access to apps deployed on cloud and only lets the requests through if they come from a user you authorize. MEDIUM
Bypassing Asymmetric Client Side Encryption Without Private Key. With the help of the PyCript burp suite extension, we can make manual and automated pentesting or bug bounty much easier on applications with client-side encryption. INFOSECWRITEUPS
GitLab's 2023 bug bounty year in review. Each year, their Application Security team recaps the highlights from the GitLab Bug Bounty Program. GITLAB
π‘ Tips
π― Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@almroot | Fredrik N. Almroth | Co-Founder & Security Researcher at @detectify. I code things to hack stuff.
@ADITYASHENDE17 | Aditya Shende | Bugcrowd Top 100 | Bounty Hunter | Trainer | Admin @HackersMarathi | @uniofeastanglia MS Cyber Security.
@codecancare | todayisnew | May you be well on your side of the screen.
@fransrosen | Frans RosΓ©n | Dev/Security/Founder at @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
@xnyhps | Thijs Alkemade | Security researcher @ Computest @sector7_nl. Master of Pwn @ Pwn2Own 2021 & 2022.
π Productivity
The Terminal Sunday allows you to start each new terminal session with a thought-provoking reminder of the time you have to make the most of your life. GITHUB
Zero to IDE with LazyVim β I used this video, among other ones, to redo my neovim config. YOUTUBE
Joel shares 2 iphone shortcut automations for winding down using black and white colors. TWITTER
How to Plan 2024 in 24 Minutes with Jesse Itzler β If you're not familiar with Jesse, you're in for a ride. Enjoy! YOUTUBE
Sam's 2023 End of Year Review: Finance, Fitness, Family, Fun. He looks back on some of the highlights and lowlights of his 2023 β I dig these categories, the 4 Fs. THEANTIMBA
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π Technology
Is 2024 finally the time to learn go? Bashbunni shows you how. YOUTUBE
Do we think of git commits as diffs, snapshots, or histories? Julia breaks it down. JVNS
Simon rounds up and highlights the stuff we figured out about AI in 2023. It was the breakthrough year for Large Language Models (LLMs). SIMONWILLISON
NotebookLM is an experimental AI-first notebook by Google. It's the Copilot for Google Docs. NOTEBOOKLM
π§ Wisdom
Peter reminding us that our path is not set in stone: "if you don't like the script of your life, rip out those pages... your life is the pen, not the paper." TWITTER
Dr. Julie on facing your fears: "Those who confront the Dragon get the Gold." TWITTER
Non-obvious lessons from Shaan on becoming a creator or building an audience. Here's one: You want to be "known well", not "well known". TWITTER
Ray on doing more of what you're already doing: "[...] Because you might not just be breaking the rules. You might be rewriting them. " TWITTER
Throttle Therapy is a video series in which Accidental CISO talks about mental health and burnout in the ranks Information Security and Cybersecurity professionals. YOUTUBE
π Cross-pollination
A primer on bee decline in the USA and what we can do about it. TWITTER
This one made me chuckle, business talk translated. TWITTER
Toastmasters International 2015 World Champion, Mohammed Qahtani, on "The Power of Words". YOUTUBE
Alex Hormozi shares his diet β More than anything, I like real people and actionable resources. YOUTUBE
π€² Quote
"If you learn something the hard way, share your findings with others. You have blazed a new trail; now you must mark it for your fellow travelers. Sharing knowledge is an unreasonably effective way of helping others."
β Nicolas Bouliane
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- β’ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- β’ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- β’ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- β’ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- β’ Deep DISCOUNTS on paid content.
- β’ Experience continuously added NEW BENEFITS.