Leadership

Vulnerabilities found with AI, oh my!

Ok, so the world is currently obsessed with AI (at least the digital world…) and with the latest Apple update releases we can see that LLMs have been used to help people find bugs! This is great news, finding bugs is better than not finding them!

The funny thing however is the obsession with CVE counts…. this is, honestly not a very useful metric to a defending org.. and I’ll try and explain why!

Read more “Vulnerabilities found with AI, oh my!”
Threat Intel

Bleeding Out

When you compromise a firewall you have lots of options in terms of next steps, from using the VPN, changing configurations, creating backdoors or perhaps using the firewall to PCAP. In this post I’m going to explore the ‘Fortibleed’ campaign. I have to note, we can see in honeypot logs this TA did not seem to limit themselves to Fortinet exploitation, however the area of analysis has a heavy Fortinet element. You will see they deployed a capture and analysis platform. Treat everything with a pinch of salt because I’m using a mad probability based machine (LLM) to support me for this!

Read more “Bleeding Out”
Threat Intel

Fortibleed

In the ‘world of Mythos’ and other such overhyped AI buzz words…. the fundamentals of digital security still apply. Don’t get me wrong, I think LLMs are great, as a digital defender, I’ve been using LLMs relatively for a long time now (from offence to defence to general CTI/Research) so I’m not a hater, they are like an Iron Man suit! But we still need our Tony Stark and Pepper Potts!

It’s very easy in a world full of complexity to oversimplify, it’s very easy to focus on one class of threat and ignore another. Zero days sound cool, when mass exploration occurs, it’s a real problem, but for the day to day in an org, authentication attacks (identity plane) are the number one thing you will likely be seeing (if you look at our logs… you have logs right???)

Read more “Fortibleed”
AI

one step closer to Skynet?

Yesterday I ran a pentest against an RDP server, the process was ok but not amazing, I had to provide more help than I would have liked, resource consumption and the idea it should keep going…. wasn’t great. The process and output wasn’t terrible at all but it didn’t blow me away.

So today I wanted to see if Claude could take on as simple active directory lab! Now let’s be clear, there were I think one or two updates to the Claude client in that time! The Claude UI even changed look and feel! So I span up an AD lab I had made a while ago and got to work!

Read more “one step closer to Skynet?”