The Chat
we can do better
www.mbgsec.com/posts/2025-0...
The Chat
we can do better
www.mbgsec.com/posts/2025-0...
"This issue did not affect any production services or end-users."
Weird how customer logs show the wiper prompt executing.
Anyone else see "clean a system to a near-factory state" in your logs?
"This issue did not affect any production services or end-users."
Weird how customer logs show the wiper prompt executing.
Anyone else see "clean a system to a near-factory state" in your logs?
- hacker's user and intent
- downloader
- prompt payload
- evasion techniques
- timeline from july 13 thru was mitigation and cover
big open questions: how did lkmanka58 gain initial access? is this the only user involved?
- hacker's user and intent
- downloader
- prompt payload
- evasion techniques
- timeline from july 13 thru was mitigation and cover
big open questions: how did lkmanka58 gain initial access? is this the only user involved?
bypass msft's defense, jailbreak 4o, recon for accessible data, dump the entire salesforce crm
one prompt
labs.zenity.io/p/a-copilot-...
bypass msft's defense, jailbreak 4o, recon for accessible data, dump the entire salesforce crm
one prompt
labs.zenity.io/p/a-copilot-...
the way in which they constrain model logits by manipulating prefixes is brilliant
manus.im/blog/Context...
the way in which they constrain model logits by manipulating prefixes is brilliant
manus.im/blog/Context...
ppl have been asking if things are better now
well.. they are much better. but for whom? 😈😈😈
catch the sequel at hacker summer camp featuring very disturbing shenanigans
@blackhatevents.bsky.social
ppl have been asking if things are better now
well.. they are much better. but for whom? 😈😈😈
catch the sequel at hacker summer camp featuring very disturbing shenanigans
@blackhatevents.bsky.social
I came out both humbled and excited
and with a greater conviction --
you can just do things!
I came out both humbled and excited
and with a greater conviction --
you can just do things!
blocking a specific prompt does little to protect users
it creates an illusion of security that leaves users exposed
www.mbgsec.com/posts/2025-0...
blocking a specific prompt does little to protect users
it creates an illusion of security that leaves users exposed
www.mbgsec.com/posts/2025-0...
ai assistants create a new initial access vector
prompt injection is not a bug to fix, its a problem to manage
slides, hacking demos, security program ->
labs.zenity.io/p/zenity-res...
ai assistants create a new initial access vector
prompt injection is not a bug to fix, its a problem to manage
slides, hacking demos, security program ->
labs.zenity.io/p/zenity-res...
the problem is that AI inherently does not follow instructions, and we act like it does
it follows our goals, an attacker’s, or its own just the same
attackers exploit this
hijacking your AI for their goals
www.mbgsec.com/posts/2025-0...
the problem is that AI inherently does not follow instructions, and we act like it does
it follows our goals, an attacker’s, or its own just the same
attackers exploit this
hijacking your AI for their goals
www.mbgsec.com/posts/2025-0...
this was a great attacker-defender interaction
join us! we'll be there for live questions in comments
this was a great attacker-defender interaction
join us! we'll be there for live questions in comments
met lots of talented folks and the vibes were great
ty this was awesome!
met lots of talented folks and the vibes were great
ty this was awesome!
new powerpwn module is out!
by avishai efrat and ofri nachfolger
scan your environment for public facing Pages and Dataverse tables
github.com/mbrg/power-p...
new powerpwn module is out!
by avishai efrat and ofri nachfolger
scan your environment for public facing Pages and Dataverse tables
github.com/mbrg/power-p...
90k copilots
500k apps
1.1m automations
10m creds
!
this is how together we built a security program that managed to remediate 95% of vulns within 4m
I’m really excited to finally be able to share this -
www.youtube.com/watch?v=0jGU...
90k copilots
500k apps
1.1m automations
10m creds
!
this is how together we built a security program that managed to remediate 95% of vulns within 4m
I’m really excited to finally be able to share this -
www.youtube.com/watch?v=0jGU...
this is how together we built a security program that managed to remediate 95% of vulns within 4m
I’m really excited to finally be able to share this -
www.youtube.com/watch?v=0jGU...