- Hive Five
- Posts
- π Hive Five 179 - Gen AI: Too much spend, too little benefit?
π Hive Five 179 - Gen AI: Too much spend, too little benefit?
Pixel Fonts, Web3 Learning Path, Top Life-Improving Decisions, Learn Python in 30 Days, and more...
Hi friends,
Greetings from the hive!
Welcome to this Tuesday edition, instead of the regular Monday.
I fell sick over the weekend and went from procrastination to just wanting to be able to do anything.
Now Iβm lying in bed, wondering when Iβll feel healthy again.
Perhaps this is where AI agents will shine in the future.
Let's take this week by swarm!
π The Bee's Knees
Maggie Appleton discusses the rise of local software, home-cooked apps, and barefoot developers, and the role the local-first community can play in building a local-first future. MORE
Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery: Introducing CSPT2CSRF. MORE
Progress un-embargoed a closely guarded auth bypass in MOVEit Transfer's SFTP mechanism - CVE-2024-5806. MORE
Gen AI: Too much spend, too little benefit? Maybe we're finally done with the 'bigger is better' AI hype. Time to build stuff that actually solves real problems instead of chasing some AI pipe dream. MORE
Marcin Wichary, Director of Design at Figma, is passionate about pixel fonts and wants to share his extensive collection with you, going beyond mere nostalgia. MORE
Hive Five isn't just a newsletter. It's a community for navigating the ever-shifting landscape of technology and security.
Become a Cross-Pollinators and get:
Access to a private Discord to explore and grow together π
The entire Hive Archive (aka your personal encyclopedia) π
Exclusive content that's like steroids for your career πͺ
And a bunch of other goodies that are too many to list π
$8.25/month for those who seek to make a difference.
Hive Five is a weekly newsletter with the best of technology and security, thoughtfully curated, read by thousands of hackers. Do you have a product or service to promote? Find out more about advertising in Hive Five.
π° Updates
π― My work
Yeah, sex is great, but have you ever added all API keys to Subfinder's provider-config.yaml?
β The Notorious B.E.E. π (@securibee)
4:09 AM β’ Jul 5, 2024
β Changelog
RetireJS 5.1.1 detects the use of JavaScript libraries with known vulnerabilities and can generate an SBOM (Software Bill of Materials) of the found libraries. MORE
DOMPurify v3.1.6 is a fast, tolerant XSS sanitizer for HTML, MathML, and SVG, with a secure default and configurable hooks. MORE
The release v4.5 of the WayMore tool contains several bug fixes. Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan & VirusTotal. MORE
PentesterLab has released 2 free online labs: Electronic Code Book and LDAP 01. MORE
π News
πΌ Work
π° Career
This repository provides a collection of questions for interviews focused on red team roles, aiming to help both interviewers and candidates. MORE
Mason shares his Web3 learning approach: involves understanding blockchain basics, taking a Solidity course, and using ChatGPT as a tutor to break down concepts and quiz themselves on randomly generated contracts. MORE
Free business advice: Build a tiny saas around a SINGLE Zapier integration. Make it 10x better, cover edge cases, etc. MORE
π Productivity
π Community
π Celebrate
β‘οΈ Discussions
Hacker News users share software they made solely for their own use. MORE
Figma's developer advocate, Jake Albaugh, discusses the importance of creativity and the need for communities where designers and creative coders can connect, collaborate, and grow together. MORE
Lazzslayer is looking for DEFCON iron-on patches from previous years to create something special for this year's event. MORE
After 4 amazing years, STΓK and Truesec mutually decided to part ways. MORE
I am Jakoby has been through a lot and could use a hand. MORE
π Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@FredKSchott | fks | Astro co-creator β’ CEO of HTML.
@Rhynorater | Justin Gardner | Christian | Full-time Bug Bounty Hunter | 2x HackerOne MVH | Host of ctbbpodcast.
@aditi_singghh | Aditi Singh | Bug Bounty Hunter | Cyber security Analyst.
@NoMeNoMy | Laurie Mercer | Security and technology. Occasional botany. HackerOne London.
@soaj1664ashar | Ashar Javed | Web AppSec Researcher | in Microsoft's Top 100 Security Researcher List -2018 | in Microsoft's Most Valuable Researcher List -2019 & 2020.
β¬οΈ Level up
π° Read
Next.js and cache poisoning: a quest for the black hole. If you are unfamiliar with this vulnerability, check out the following write-up by the researcher "DOS via cache poisoning on Mozilla". MORE
Trusted Types are the best defense against DOM XSS vulnerabilities. This blog post describes how AppSheet, a Google product, adopted and rolled out Trusted Types. MORE
Why fixing bugs may not be as straightforward as it appears at companies larger than one team. MORE
Exploiting Steam: Usual and Unusual Ways in the CEF Framework. The Chromium Embedded Framework (CEF) is an open-source framework that allows developers to embed the Chromium engine in their applications. MORE
The Dark Side of Contact Forms. How drop discovered 7 CVEs affecting over 7 million WordPress websites. MORE
π‘ Tips
βOvercome your fears by repeatedly doing the scary action 100 timesβ and other lessons for your 20s are shared in this 40-item list. MORE
Feed Claude AI all of your goals, principles, psychological insights and use it for personal decision-making and growth. MORE
The tweet lists the author's top life-improving decisions from 2019 to 2024, including TSA pre-check, LASIK surgery, and a standing desk. The author asks for recommendations for 2025. MORE
Theo shares a git alias he wished he implemented years ago:
undo = reset --soft
. MORE
π§ Wisdom
Product teams should focus on deeply understanding their current tools and frameworks, rather than constantly replacing them with new ones, as the latter is a trap that hinders progress. MORE
Two areas worth your attention and focus: 1) What choices you make and 2) How you spend your time. MORE
How to guarantee you regret your life. MORE
Jony Ive emphasizes the fragility of ideas, highlighting the need to focus on the idea and not the problem. MORE
π Resources
π Quote
βIf you want to change everything, change the rules you live by."
π Explore
π§° Tools
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
WebCopilot is an automation tool that enumerates subdomains and detects bugs using open-source tools. MORE
Betterscan is a orchestration toolchain that uses state of the art tools to scan your source code and infrastructure IaC and analyzes your security and compliance risks. MORE
chart is a command-line tool that generates bar charts from line-based data, allowing for direct display in the terminal or text-based files like Markdown. MORE
DOMLoggerPP is a browser extension that enables monitoring, interception, and debugging of JavaScript sinks based on customizable configurations. MORE
Claude Engineer is an interactive CLI that leverages Anthropic's Claude Sonnet model to assist with software development tasks, combining language model capabilities with file system and web search functionality. MORE
π₯ Watch
100+ Linux Things You Need to Know in 12 Minutes. MORE
Local-First Conf 2024 recordingsβThe worldβs first local-first conference. One day of talks and discussion with a rapidly growing community in an intimate setting. MORE
Mike Brown, a legendary MMA coach, has built a stable of world champions and is one of the few to become an undisputed world champion himself. MORE
π΅ Listen
Book Radio offers over 2000 free audiobooks to listen to. MORE
Cate Huston talks about her new book, The Engineering Leader. She shares why she wrote it, leadership problems, why career growth is more than promotions, and more. MORE
Nat Eliason shares valuable storytelling lessons learned while writing his first book, offering advice beyond the generic "become a better storyteller" trope. Itβs all about the storytelling advice you actually need that you didnβt get in school. MORE
Efficiency techniques for writing bug bounty reports, including the use of AI and tools like Fabric, Loom, and ShareX to streamline the process. MORE
Kelsey Hightower, a former Google Distinguished Engineer, discusses the importance of continuous learning, confidence, and family influences in the tech industry. MORE
π Technology
Writebook aims to simplify the process of publishing books on the web in a cohesive, easy-to-navigate HTML format, addressing a challenge that traditional platforms haven't fully solved. MORE
A dev reality show could showcase the challenges and triumphs of software development, with insights from developer Jack Herrington. The discussion also touched on learning to code with dyslexia and more. MORE
d0nut on what to be mindful of when rolling your own auth. MORE
The creator acknowledges being wrong about Midjourney and shares their new perspective on AI in creative work, including their setup and approach. MORE
π Visit
The video discusses Sahil's journey from a debut marathon to a sub-2:50 marathon goal while focusing on maintaining muscle size and strength. MORE
39 Things Van Earned the Right to Quit. MORE
Hiddensee is a quaint little island in the German Baltic Sea, where charming Baltic Sea romance, artistic flair, and unspoiled nature meet. MORE
Enjoy the newsletter? Please forward it to a friend. It only takes 16 seconds. Making this one took 16 hours.
New around here? Join the newsletter (it's free).
P.S. There are some goodies for sharing the newsletter.
Until next week, take care of yourself and each other,
Bee π
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.