- Hive Five
- Posts
- π Hive Five 178 - Slow Down To Achieve More
π Hive Five 178 - Slow Down To Achieve More
What if we use AI to think more instead of less, AI Engineer World's Fair 2024, How To Reinvent Your Life In 4 Months, and more...
Hi friends,
Greetings from the hive!
Slow down to achieve more. Sounds counterintuitive, right? But it works.
The Navy SEALs have a saying: 'Slow is smooth, and smooth is fast.' It's not just for combat. It's for life.
When you slow down, you see more. You think clearer. You make fewer mistakes. And fewer mistakes mean less backtracking, less fixing, less wasted time.
It's like compound interest for your actions. Small, deliberate steps add up. They compound. Before you know it, you're way ahead of where you'd be if you were always rushing.
I'm trying to live this way. Slowing down. Being more deliberate. Doing things not just for some future payoff, but because the doing itself is worthwhile.
It's not easy. Our world screams 'Faster! Now!' But I'm learning that sometimes, the best way to speed up is to slow down.
Let's take this week by swarm!
π The Bee's Knees
Execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities work in Ruby projects. MORE
AI has taken over major tech companies, making humans rely on machines to think. But what if we use AI to think more instead of less? MORE
Full-time bug hunter Alex Chapman, known for his high criticality findings, shares his insights and secrets. MORE
AI Engineer World's Fair 2024 keynotes and CodeGen track, showcasing the latest advancements in AI engineering. Features talks on Open Challenges for AI Engineering, Llamafile: bringing AI to the masses with fast CPU, and much more. MORE | SCHEDULE
Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models. Google Project Zero hopes that in the future, this can close some of the blind spots of current automated vulnerability discovery approaches, and enable automated detection of "unfuzzable" vulnerabilities. MORE
With a modest contribution of just $8.25 per month, youβre not only helping keep Hive Five going, but you're also getting access to a private Discord community, the complete Hive Archive, exclusive & bonus content, and a range of other benefits.
Hive Five is a weekly newsletter with the best of technology and security, thoughtfully curated, read by thousands of hackers. Do you have a product or service to promote? Find out more about advertising in Hive Five.
Table of Contents
π° Updates
π― My work
Let me tell you about one of my #defcon29 stories. It revolves around @seclilc.
I met her at the @ine booth. Meeting her was so fun, she didnβt realize it was me at first.
Fast forward to the closing ceremony. I was sitting alone and @seclilc invited me to sit with her.
β The Notorious B.E.E. π (@securibee)
8:56 PM β’ Aug 9, 2021
β Changelog
Nuclei Templates v9.9.0 introduces new Kubernetes Cluster Security templates, enabling automated security reviews and custom security checks, with results shared on the PDCP Cloud. MORE
The commit 1.2.0 of RetireJS/retire-site-scanner adds support for detecting the use of known bad CDNs. MORE
sw33tlie's updated ffuf fork now supports additional fuzzing techniques, including absolute URI fuzzing, invalid HTTP methods, no header canonization, invalid URL encoding chars, and invalid HTTP headers. MORE
π News
Polyfill.io is a convenient service that automatically provides front-end polyfills, however it's been compromised. MORE
Simian Security provides specialist penetration testing and security assessments to help organizations identify and address vulnerabilities. MORE
PortSwigger, the company behind the Burp Suite security tools, raises $112M. MORE
The latest creation of prolific indie maker Pieter Levels: A live ranking of airlines by how much luggage they are losing. MORE
πΌ Work
π° Career
Find out what those who've left the Software Engineering world transition into. MORE
What do GenZ software engineers really think? They discuss values, what frustrates them about working in tech, and what they think of older colleagues. MORE
Job hunting tips: apply for LinkedIn jobs with few applicants, hybrid/onsite roles in other cities, and recently posted roles to increase visibility. MORE
Kyle Pursell, Shopify's Head of Growth Optimization, discusses strategies for scaling upmarket, the power of product-led growth, and the importance of cross-functional collaboration in growth initiatives. MORE
Shenetworks offers career guidance and answers tech job-related questions. MORE
π Productivity
The video discusses 4 productivity hacks the creator uses to stay productive while traveling, including high-altitude book writing and high-intensity workouts. MORE
Slow down to achieve more. Ali shares the 3 key principles that Cal Newport talks about in his new book Slow Productivity. MORE
To write like Ryan Holiday, focus on consistent productivity (16 books, daily newsletter), has 1.7 million YouTube subscribers, and runs his own creative agency. MORE
Ice is a powerful menu bar manager for macOS. MORE
How Steve Huynh (YouTuber, principal engineer, productivity junkie) started 5 Successful Side Projects Without Burning Out. MORE
π Community
π Celebrate
NahamSec started streaming live recon again! It'll be on YouTube soon. MORE
β‘οΈ Community
Alethe is the hitchHACKERs Guide to DEFCON, offering help with questions about the event, venue, and accommodations. MORE
Zseano underwent emergency surgery and is recovering well. Send him love! MORE
STΓK discusses the rich history and variety of Scandinavian saunas, from traditional steam and dry saunas to modern styles like crystal, herb, and infrared. He plans to experience the diverse range of sauna types. MORE
Adam shares a plant-based pre-workout meal. MORE
π I love to cook (and eat), so delicious recipes are always welcomed.
π Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@inhibitor181 | Cosmin | Bug bounty hunter.
@TJ_Null | Tony | Blue Teamer in Disguise | SANS Netwars Champion. Former community manager and founder of the Offsec community for @offsectraining.
@monicalent | Monica Lent | Dev founder | Courses & Community.
@synackodes | Elle Romanoff. The llama loving threat hunter| Black Widow of AppSec | Pro nap taker | Plant-based | A Cybermaiden who likes coding, motorsport, legos & sneakers.
@hdmoore | HD Moore | He/Him | Chairman & Founding CTO of runZero (formerly Rumble Network Discovery) | Black Lives Matter.
β¬οΈ Level up
π° Read
Artifactory, a popular software repository manager, was found to be vulnerable to a Zip Slip attack. MORE
DevOps, once a promising concept, has fallen victim to the hype cycle, leaving many feeling exhausted and disillusioned. MORE
Mark Dowd, founder of Aziumuth Security and co-author of "The Art of Software Security Assessment", discusses the market for zero-day vulnerabilities and how mitigations affect monetizing offensive security work. MORE
Why nested deserialization is harmful: Magento XXE (CVE-2024-34102). It's estimated that there are over 140,000 instances of Magento running as of late 2023. MORE
"We desperately need a return to basics ideology that encourages teams to stop designing with the expectation that endless growth is the only possible outcome of every product launch."
Paul Graham's essays are aggregated and compiled into one complete collection for your reading pleasure. MORE
π I'm uploading this to my Kindle as we speak!
π‘ Tips
When investing, Pieter's point is to diversify across companies, industries, countries, brokers, banks, and personal assets to mitigate risk. MORE
Success in bug bounty or hacking requires passion, dedication, and willingness to sacrifice. MORE
Attackers may exploit language models' vulnerabilities by injecting prompts that lead to blind XSS attacks. MORE
Explore this path to start earning in bug bounty. MORE
π§ Wisdom
How to take the high road. When someone provokes you, itβs easy to react without thinking. Learn to slow down and respond in ways youβll be proud of. MORE
Razors are rules of thumb that simplify decision-making. Here are 16 essential Razors everyone should know. MORE
Failure should not be viewed as a negative, especially in entrepreneurial circles. Instead, it should be seen as a learning experience to improve and grow. MORE
Plutchik's Wheel of Emotions provides a logical framework to understand and explore feelings, with a comprehensive emotions list. This is an interactive version. MORE
Pharrell advises the Gallery of Maurice creator to not take feedback personally, but instead observe it and address the issue: "Don't take it personal. Take note, and take care of it." MORE
π Resources
This repository provides an overview of free and commercial training and certifications related to secure software development. MORE
Comprehensive study notes covering various web hacking techniques, including information gathering, vulnerability analysis, and exploitation. MORE
Cts played with Blue Water in the GoogleCTF. Here are their challenge writeups. MORE
π Quote
"Don't take it personal. Take note, and take care of it."
π Explore
π§° Tools
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
Mihari is a framework for continuous OSINT-based threat hunting that provides a built-in web app for monitoring alerts. MORE
PackageSpy is a versatile command-line tool designed to simplify the process of searching for secrets within packages on popular package managers using Gitleaks. MORE
YetiHunter is a tool created by Permiso Security to query Snowflake environments for signs of compromise, leveraging indicators from Permiso and the community. MORE
mise is a polyglot tool version manager that replaces tools like asdf, nvm, pyenv, rbenv, etc. MORE
GQLSpection is a CLI tool and Python library for parsing GraphQL introspection queries and generating automatic queries. MORE
π₯ Watch
Great leaders approach hard conversations with empathy, transparency, and a focus on problem-solving, not blame. MORE
Join Dan and Marcello as they discuss and demonstrate the latest vulnerabilities from Protect AI's June report, with exclusive segments to enhance your hacking skills. MORE
This tutorial demonstrates how to conduct person of interest investigations using Maltego, starting with names and pivoting to personal identifiers to uncover digital footprints of public figures. MORE
Recon is the first step in hacking large corporations, involving gathering information about the target organization. MORE
The Web Dev Challenge participants have 30 minutes to plan and 3 hours to build an AI-powered app that's not another f%*#ing chatbot. MORE
π΅ Listen
How To Reinvent Your Life In 4 Months (Full Step-By-Step Process) by Cal Newport. MORE
Business Tricks From Gamblers, Pickup Artists, & Feynman. MORE
5 Business Ideas To Start Today With $0 ft. Shark Tank's Sabri Suby. MORE
Financing the Deep Life with Noah Kagan. One of the most common strategies for achieving a powerful ideal lifestyle vision is to leverage entrepreneurial activities to find a stable source of income that allows autonomy and flexibility. MORE
π Technology
Micro-features that improve the quality of life of any blog or website. MORE
98.css is a CSS library that helps create Windows-like interfaces. MORE
Pikimov is a web-based motion design and video editing platform that allows users to create and edit videos with ease. MORE
This paper establishes a taxonomy of 58 text-only prompting techniques and 40 techniques for other modalities, providing a comprehensive understanding of prompting for generative AI systems. MORE
π Interesting
Find out what you can build with Flipdiscs. They are a display type that uses electromagnetic pulses to flip small discs between two colors. This technology, despite being over 50 years old, remains largely unchanged. MORE
How many countries are there? Does the UN's official list of 195 include them all? MORE
Arun used 500 drones for his wedding speech, a highlight of his life. MORE
"Fight Inc: Inside the UFC" offers unprecedented access to UFC CEO Dana White and his team, while also delving into the stories of the promotion's biggest stars. MORE
The video discusses the reverse engineering of the original Age of Empires game to understand its AI system. MORE
Until next week, take care of yourself and each other,
Bee π
Enjoy the newsletter? Please forward it to a pal. It only takes 16 seconds. Making this one took 16 hours.
New round here? Join the newsletter (it's free).
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.