DevTestSecOps
146 subscribers
506 photos
33 videos
37 files
719 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
DevTestSecOps
#AI #security https://www.anthropic.com/glasswing
> One of the vulnerabilities Claude found, the company said, was a 27-year-old bug in OpenBSD, an open-source operating system that was designed to be difficult to hack. Many internet routers and secure firewalls incorporate OpenBSD’s technology. Another was a longstanding issue in a piece of popular video software that automated testing tools had scanned five million times, without finding any problems.

“This model is good at finding vulnerabilities that would be well understood and findable by security researchers,” Mr. Graham said. “At the same time, it has found vulnerabilities, and in some cases crafted exploits, sophisticated enough that they were both missed by literally decades of security researchers, as well as all the automated tools designed to find them.”


https://www.nytimes.com/2026/04/07/technology/anthropic-claims-its-new-ai-model-mythos-is-a-cybersecurity-reckoning.html
🔥2🤯2
😁6👏3
22👏2
Forwarded from Мам, я DPO
Oopsie 🤷🏼‍♀️💫
🔥2😁2🤯2
Forwarded from Мам, я DPO
👏2👌21
👏4🤣2🥰1
😁6👌2🤝1
😈3🤯2👻21
#Windows #BitLocker #security

The process is dead simple: grab any USB stick, get write access to the "System Volume Information," and copy into it the "FsTx" folder and its contents. Shift+click Restart to get Windows to the recovery environment, but then switch to holding down the Control key and don't let go. The machine will reboot, and without asking any questions or showing any menus, will drop you in an elevated command line with full access to the formerly Bitlocked drive, without asking for any keys.


https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor
👏2👨‍💻2🔥1
😁2💯1💔1
Forwarded from Мам, я DPO
In a post on X, Jeff Cross, co-founder of Narwhal Technologies, the company behind nx.dev, said, "this incident highlights that there need to be deeper, more fundamental changes to how we and other maintainers need to think about securing developer tooling and open source distribution."

"We're also beginning conversations with other high-profile open source maintainers about how we can work together on some of the deeper structural problems around software supply chain security. A lot of the assumptions the ecosystem has operated under for years no longer hold."

In recent months, TeamPCP has rapidly gained notoriety for large-scale software supply chain attacks, specifically going after widely-used open-source projects and security-adjacent tools that developers rely on.


Якби ж тільки була якась спеціальна професія, яка там щороку каже, що не можна ставити шо попало на робочу техніку

https://thehackernews.com/2026/05/github-internal-repositories-breached.html?m=1
🔥2😁2👌2