Stefano Di Paola(@WisecWisec) 's Twitter Profileg
Stefano Di Paola

@WisecWisec

CTO & Chief Scientist of IMQ MindedSecurity. (Web) Application Security consultant, researcher and enthusiast. I love lateral thinking.

ID:102612201

linkhttp://blog.mindedsecurity.com calendar_today07-01-2010 07:53:11

4,3K Tweets

5,8K Followers

416 Following

Gareth Heyes \u2028(@garethheyes) 's Twitter Profile Photo

Shazzer will now highlight the differences in behaviour between browsers. If one does something different it will be highlighted in red.

shazzer.co.uk/vectors/661643…

Shazzer will now highlight the differences in behaviour between browsers. If one does something different it will be highlighted in red. shazzer.co.uk/vectors/661643…
account_circle
Alex Matrosov(@matrosov) 's Twitter Profile Photo

A free scanner to detect signs of the XZ backdoor implantation has been released!
👇
x.com/binarly_io/sta…

account_circle
Include Security(@IncludeSecurity) 's Twitter Profile Photo

We released our new semgrep rules today. Given the recent news about executive orders from the Whitehouse, we thought it would be important to flag all of the code that doesn't meet federal standards.

Memory Safety is serious stuff today:
github.com/IncludeSecurit…

account_circle
All The Right Movies(@ATRightMovies) 's Twitter Profile Photo

THE MATRIX was released 25 years ago today. Acclaimed as both one of the great science fiction movies and a groundbreaking action film, the behind-the-scenes story will have you questioning reality…

1/44

THE MATRIX was released 25 years ago today. Acclaimed as both one of the great science fiction movies and a groundbreaking action film, the behind-the-scenes story will have you questioning reality… 1/44
account_circle
PentesterLab(@PentesterLab) 's Twitter Profile Photo

We would like to welcome our new team member: Jia Tan!

Jia will work on a set of challenges for our 'Supply Chain' badge!!

account_circle
vx-underground(@vxunderground) 's Twitter Profile Photo

We made a post congratulating and praising Andres Freund (Tech) for his discovery of the xz backdoor

Dorks immediately started freaking out

>i WouLd hAvE cAuGhT ThiS
>i dO bEnChMarkS liKe tHiS tOO

How about you be happy for someone? Not everything is an attack on your ego 😤😤

account_circle
Thomas Roccia 🤘(@fr0gger_) 's Twitter Profile Photo

🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)!

I hope it helps to make sense of the information out there. Please treat the information 'as is' while the analysis…

🤯 The level of sophistication of the XZ attack is very impressive! I tried to make sense of the analysis in a single page (which was quite complicated)! I hope it helps to make sense of the information out there. Please treat the information 'as is' while the analysis…
account_circle
Juliano Rizzo(@julianor) 's Twitter Profile Photo

🚨 Urgent: I need the help of the and (graphy) community. A policy I designed and helped implement has led to a serious situation. Some affected users are becoming increasingly 😱agitated, and I've even received threats demanding a solution.🧵👇 (FLT rewards) 1/

account_circle
Dave Aitel(@daveaitel) 's Twitter Profile Photo

One thing LLMs have taught people is that any input is part of the program itself. And small variations in input can make vast changes in the output of a program.

account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

New blog post is out! Extracting the SecOC keys used for securing the CAN Bus on the 2021+ RAV4 Prime. icanhack.nl/blog/secoc-key…

Research started all the way in 2022, but took many evenings of reverse engineering to get code execution.

PoC: github.com/I-CAN-hack/sec…

New blog post is out! Extracting the SecOC keys used for securing the CAN Bus on the 2021+ RAV4 Prime. icanhack.nl/blog/secoc-key… Research started all the way in 2022, but took many evenings of reverse engineering to get code execution. PoC: github.com/I-CAN-hack/sec…
account_circle
Jordan Mechner(@jmechner) 's Twitter Profile Photo

My 40 years of Prince of Persia™ adventures started in 1985 with an Apple II, a videotape camera, and my brother David in pajama pants in our high school parking lot.
From my graphic novel 'REPLAY: Memoir of an Uprooted Family' - now in English jordanmechner.com/en/books/repla…

My 40 years of @princeofpersia adventures started in 1985 with an Apple II, a videotape camera, and my brother David in pajama pants in our high school parking lot. From my graphic novel 'REPLAY: Memoir of an Uprooted Family' - now in English jordanmechner.com/en/books/repla…
account_circle
Ange(@angealbertini) 's Twitter Profile Photo

Magika - fast file identification via deep learning. Open-source and used internally at Google.
Assessed by yours truly.
opensource.googleblog.com/2024/02/magika…

account_circle
Sheel Mohnot(@pitdesi) 's Twitter Profile Photo

An HK-based employee of a multinational firm wired out $25M after attending a video call where all employees were deepfaked, including the CFO.

He first got an email which was suspicious but then was reassured on the video call with his “coworkers.”

An HK-based employee of a multinational firm wired out $25M after attending a video call where all employees were deepfaked, including the CFO. He first got an email which was suspicious but then was reassured on the video call with his “coworkers.”
account_circle