
Permiso Security Randall
@permisorandall
@permisosecurity
@p0Labs Cloud Threat Research: permiso.io/p0-labs
Open-Source CloudSec Tools: github.com/Permiso-io-too…
ID: 1674861355986481153
https://www.linkedin.com/in/randallhettinger/ 30-06-2023 19:24:45
500 Tweet
226 Takipçi
740 Takip Edilen


Last week I created Permiso Podcaster (automatic video podcast generator) and shared a sample. In this video I walk you through how I built it! - Pulls data from Permiso Security MCP - Claude 3.5 writes a 2-host script - ElevenLabs generates audio - Runway clips FFMPEG



After yesterdays test on the Permiso Security MCP, I tried a bunch more basic prompt injection techniques by embedding names and tags in AWS resources with instructions. All available models in Cursor handled this super well. Though I have a bunch more ideas to try!






As threat actors pursue LLMJacking more (as Permiso Security found), I’m curious when we’ll see them abusing customer service/customer facing apps. Stealing cloud credentials and using them is hard. Why not just jailbreak LLMs used in web apps for your nefarious purposes?





Thanks to Marco Lancini for including Bleon Proko's recent blog post on how #AWS Managed Active Directory security vulnerabilities can lead to RBCD attacks in the latest edition of CloudSecList ! cloudseclist.com/issues/issue-2…

There is a 60% chance that my good friend Nathan would be excited about Taylor Swift 's "The Life of a Showgirl" announcement:




