- Hive Five
- Posts
- ๐ Hive Five 198 - Do Hard Things
๐ Hive Five 198 - Do Hard Things
Fresh from the Colorado mountains ๐๏ธ From a LAN-party optimized house to AI-driven data patterns, PHP security hardening & bug bounty success stories. Plus NeovimConf returns & Anthropic is hiring!
Hi friends,
Greetings from the hive!
I hope youโre doing well. I'm still enjoying Colorado with the fam.
Weโve been doing a lot of hiking. Just look at this majestic scenery.
Let's take this week by swarm!
๐ The Bee's Knees
The home of Kenton and Jade isn't your typical house, they built their house for LAN parties! They even detail how they did it. MORE
Predictable Patterns & PII Leakages: Using AI to mass leak data. While LLMs don't replace human intuition and experience, they can: Quickly identify patterns in large datasets, Generate comprehensive test cases, Suggest implementation patterns, and Accelerate hypothesis testing. MORE
"When stuck, verbalize your assumptions. Sometimes just explaining the problem to someone else reveals the solution."
The power of automation and collaboration in bug bounty. Tess's career in bug bounty began while working at a phone repair store, sparking a deep fascination with breaking and tinkering that led him to the world of security research and automation. MORE
Do hard things. Casey Neistat on the importance of choosing to tackle difficult challenges in life, even when they are not enjoyable, as they can lead to positive outcomes such as personal growth, improved health, and achieving specific goals. MORE
Upcoming hardening in PHP: Arnaud Le Blanc and Julien Voisin took on to improve PHP's security. MORE
"I find it fascinating that people are putting so much efforts optimizing exploitation techniques, yet ~nobody bothers fixing them, even if it only takes a couple of lines of code and 20 minutes."
Brought to you by โ
Hive Store
Hacking life, code, and culture - tech streetwear & merch for rebels making tech human again. Shop hats, tees & mugs with messages about AI, privacy & digital rights. Making the web ours again.
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
๐ฐ Updates
๐ฏ My work
I redid my About page. Iโm not 100% pleased with it yet, but weโre getting there. MORE
I created a new social media image to share quotes from the newsletter:
๐ฐ News
โ Changelog
DOMPurify 3.2.0 Added type declarations, thanks @reduckted , @philmayfield, @aloisklink, @ssi02014 and others + Fixed a minor issue with the handling of hooks, thanks @kevin-mizu. MORE
๐ผ Work
๐ฐ Career
Anthropic is hiring a Brand Communications Manager. In this role, you'll help ensure Claudeโand by extension Anthropicโcontinue to show up in ways that are both technically sophisticated and culturally resonant. MORE
A new initiative to find open source projects in need of help, including project details, tech stacks, and contribution areas. MORE
How to ship projects at big tech companies. Shipping successfully is about building leadership trust and anticipating problems, not just writing code. Stay flexible near launch, plan for the worst, and ship with courage. MORE
๐ Productivity
Effortlessly convert Spotify links to your preferred streaming service. MORE
Cal Newport's "Deep Work" examines the importance of focused, distraction-free work in an age of constant connectivity. Enrico provides strategies for increasing one's capacity for deep work and quantifying its impact. MORE
Linear engineers Michael Hadley and Kristin Boyer share best practices, workflows, and tips for improving engineering efficiency and streamlining the development process. MORE
The Morgen app for Obsidian is the best AI planner, offering powerful features to streamline your workflow. MORE
How to find (and use) your superpowers: Define your best version, use your ace cards, and follow your success system. Show up and be more you. MORE
๐ Community
๐ Celebrate
Team "DoS and Dont's" (@sw33tLie, @godiego_, and @bsysop) won @Bugcrowd 's Carnival of ChAIos competition. Congrats! MORE
@endingwithali celebrated her one-year anniversary of hosting ThreatWire. Woot! MORE
@cybersecmeg celebrated her one-year anniversary working at CrowdStrike and shares some advice. Let's go! MORE
Eugene Lim aka @spaceraccoonsec is publishing a book: From Day Zero to Zero Day. So cool! MORE
โก๏ธ Timeline
"Like many, Iโm dismayed and truly scared for whatโs going to happen to the United States as we usher a dictator into office."
Over the last week, more than a million people have joined Bluesky and, more importantly, people who already had accounts there started actively using it again, to the point where it felt like the most energetic move away from Twitter since Elon Musk took over. MORE
๐ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@rohk_infosec | Kevin | Staff application security engineer at @Okta.
@liran_tal | Liran Tal | 2022 GitHub Star | 2022 OpenJS Pathfinder award for Security.
@nullenc0de | Paul Seekamp | I spend a significant amount of time reading security stuff.
@BenWilsonTweets | Ben Wilson | Creator and host of @HTTOTW .
@santi_lopezz99 | Santiago Lopez | 1# Millon Dollar hacker on @Hacker0x01 .
๐ Level up
๐ฐ Read
Release-Drafter To google/accompanist Compromise. This scenario emphasizes the importance of using third-party GitHub Actions by SHA instead of mutable tags. MORE
Rapid7 analysis of Fortinet's published advisory for CVE-2024-47575, a missing authentication vulnerability affecting FortiManager and FortiManager Cloud devices. MORE
CVE-2024โ50340: Remote Access to Symfony Profiler via Injected Arguments. MORE
Michael Zhmailo, a penetration testing expert, discusses his team's frequent encounters with Internet Information Services (IIS) and shares insights on leaving backdoors in it. MORE
Reproducing CVE-2024-10979: A Step-by-Step Guide. MORE
๐ก Tips
Think Outside the Perimeter: Bug Hunting in Google Cloud's VPC Service Controls. MORE
"VPC-SC allows you to create isolation perimeters around your cloud environment and forms a shield around your most valuable cloud resources."
๐ง Wisdom
"When you are favored by God. You are also favored by the devil."
Employee experience = Customer experience. At Stripe, any employee can easily file a bug or nit by emailing a screenshot or video, and a LLM creates a ticket and routes it to the proper team. This simple approach has led to a 6-fold increase in bugs filed, resulting in thousands of fixes this year. MORE
The CEO of Anthropic and Sam Altman foresee artificial general intelligence (AGI) arriving within the next few years. Daniel encourages you to prepare by knowing your life mission, goals, and core sentence, and begin building your TELOS file. MORE
"Telos is an open-sourced framework for creating Deep Context about things that matter to humans."
Jason Fried: "The amount of work you get done in a day means nothing. The kind of work you get done in a day means everything." MORE
๐ Resources
A set of scripts to simplify the process of setting up and maintaining a Burp Collaborator Server in a Docker environment, using a LetsEncrypt wildcard certificate. MORE
Anatomy of an LLM RCE. As large language models grow more capable, the risks of security vulnerabilities also escalate dramatically. MORE
The ability of AI chatbots like Claude to visually process PDFs, including charts and diagrams, represents a significant breakthrough for researchers. This development unlocks new possibilities for data analysis and knowledge discovery across a wide range of fields. MORE
#1 AI Red-Teaming and AI Safety: Learn AI Security from creator of HackAPrompt, the Largest AI Safety competition ever run (backed by OpenAI & ScaleAI). MORE
๐ Explore
๐งฐ Tools
A tool that streamlines video note-taking and bookmarking, allowing users to organize their thoughts, loop and highlight important sections, and effortlessly revisit and share their notes. MORE
Reaper by Ghost Security is a modern, lightweight, and deadly effective open-source application security testing frameworkโengineered by humans and primed for AI. MORE
A CLI application that automatically prepares Android APK files for HTTPS inspection. MORE
URLFinder is a high-speed, passive URL discovery tool designed to simplify and accelerate web asset discovery, ideal for penetration testers, security researchers, and developers looking to gather URLs without active scanning. MORE
PoisonTap, a creation of Samy Kamkar, is a Raspberry Pi Zero and Node.js tool that siphons cookies, exposes internal routers, and installs web backdoors on locked computers. MORE
๐ฅ Watch
The documentary "Before Macintosh: The Apple Lisa" offers a fascinating look into the computer that really changed the way we used personal computers; it started the modern personal computer revolution. MORE
@0xtib3rius explains some "safe" OR-based SQL injections which can be used to exploit databases without risking false positives or damage to the data stored within. MORE
@_ZwinK University v2: Hacking Tesla!? He covers: approaching a target after sub-domain recon, what to look for and why, and more. MORE
I watched a crazy documentary over the weekend called Mister Organ. Journalist David Farrier (Tickled & Dark Tourist) is drawn into a game of cat and mouse with a mysterious individual. Delving deeper he unearths a trail of court cases, royal bloodlines and ruined lives, in this true story of psychological warfare. MORE
๐ต Listen
The Man Who Went To War With Anonymous - And Lost. MORE
Scott Hanselman and Mark Russinovich discuss the philosophies and quirks of programming languages, debating the merits of small languages like Erlang versus giants like JavaScript, and whether modern languages have improved upon their predecessors. MORE
Find out how prompt engineering, a tool for non-technical experts to solve complex problems with AI, is evolving into something new and more powerful. MORE
A conversation with Jason Haddix field CISO of Flare on how they detect stolen credentials on dark web forums and on founding Arcanum to provide red team training, particularly focused on AI-enabled offensive security. MORE
Ali and Serena, discuss tech-focused AITA (Am I The Asshole) stories from Reddit, offering their commentary and insights. MORE
Get $200 to try DigitalOcean โ the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
๐ Technology
"Every time a cryptographer has talked about PGP, itโs been to complain about how bad it is and opine that people shouldnโt be using it."
When Google first expanded Maps to India, many streets lacked names, rendering directions useless. UX researchers and designers set out to solve this problem, leveraging local knowledge to map the nameless streets. MORE
How to add Supabase to your bolt.new app in 6 minutes. It covers setting up a Supabase project, user authentication, and storing and syncing data. MORE
Anthropic has added a prompt improver to their console, allowing users to refine prompts and receive optimized versions. MORE
๐ Interesting
Between 2009 and 2012, Apple's iPhones and iPod Touches included a 'Send to YouTube' feature that allowed users to directly upload videos from the Photos app, leading to many 'IMG_XXXX' videos on YouTube. MORE
A large-scale analysis of 73,921 movies from the last 80 years on how often, when and maybe even why that happens MORE
"A title drop is when a character in a movie says the title of the movie they're in."
Hand-picked selection of more than 900 public domain images from our collection, all carefully enhanced to make beautiful prints. MORE
๐ญ Quote
"One never notices what has been done; one can only see what remains to be done."
๐ Learned something?
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five โ
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee ๐
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.