Stefan Kraxberger
@skraxberger
cyber security & data privacy enthusiast, nature lover #cybersecurity, #infosec
ID: 25474934
https://www.secinto.com 20-03-2009 07:17:09
1,1K Tweet
545 Takipçi
3,3K Takip Edilen
New: we proved it could be done. I used an AI replica of my voice to break into my bank account. The AI tricked the bank into thinking it was talking to me. Could access my balances, transactions, etc. Shatters the idea that voice biometrics are foolproof vice.com/en/article/dy7…
.Jorgo Ananiadis 🪠 posted an assessment of the lacking HTTP security headers on xplain.sh - using it as tellsign for the poor security posture of #Xplain as a whole. x.com/JorgoA/status/… Let's look at this in detail - a 🧵.
We've just published 'Smashing the state machine: the true potential of web race conditions' by James Kettle! Dive in to arm yourself with novel techniques & tooling, and help reshape this attack class: portswigger.net/research/smash…
🚨NEW: Urging all organizations to review this guidance & take steps to reduce your risk to this widespread vulnerability.🙏Huge Thanks to The Boeing Company for providing key info for this advisory--a terrific example of operational collaboration in action: go.dhs.gov/oHd.
🧐 Recently, we found a GitHub vulnerability exposing private data. 😱 Now, a similar issue in Microsoft Azure DevOps (ADO) might be even worse. 🔓 Commits in Private Forks are actually Public! More details 👉 trufflesecurity.com/blog/you-can-a…