Davide Guerri

92 Followers
82 Following
198 Posts
Cybersecurity, ex-Meta current Google. Aiming to die young as late as possible. Also, too old for $𝚝𝚑𝚒𝚜 shit.
Hacking since 1983.
GPG0692AD3F13A5016A3ACF72454D97F757E8074EC8
Bloghttps://dguerri.github.io/random-tech-stuff
Githubhttps://github.com/dguerri
Keybasehttps://dguerri.keybase.pub/proofs/mastodon.html
LinkedInhttps://www.linkedin.com/in/dguerri
Redditu/guerri

Seems reasonable: "Our findings reveal that the standalone LLM introduces nearly 9x more new vulnerabilities than developers, with many of these exhibiting unique patterns not found in developers'code. Agentic workflows also generate a significant number of vulnerabilities, particularly when granting LLMs more autonomy, potentially increasing the likelihood of misinterpreting project context or task requirements. We find that vulnerabilities are more likely to occur in LLM patches associated with a higher number of files, more lines of generated code, and GitHub issues that lack specific code snippets or information about the expected code behavior and steps to reproduce"

https://www.semanticscholar.org/paper/Are-AI-Generated-Fixes-Secure-Analyzing-LLM-and-on-Sajadi-Damevski/235c52bdef09f6fec47a17fcdbc072ff6a5bd275?utm_source=alert_email&utm_content=LibraryFolder&utm_campaign=AlertEmails_WEEKLY&utm_term=LibraryFolder&email_index=0-0-0&utm_medium=59735069

If you need to identify #malware quickly, give #malcat a try: its Kesakode code identification is fast and can even work offline!

More info: https://doc.malcat.fr/analysis/kesakode.html

A reminder, the Fediverse cost money.

Yes, it is free for YOU to use, but your local administrator pays for domain registration, web hosting, storage space, CDN, and of course, bandwidth.

The busier and more active your Fedi site, the most it cost.

If you are able, consider reaching out to your admin, and asking how you can help. Even small contributions add up and make a difference.

#Fediverse #Fedi #ActivityPub #Mastodon #Misskey

Ever wanted to mount locally the filesystem of a running remote/local docker container?

Check out Dockerfuse https://github.com/dguerri/dockerfuse

Dockerfuse can mount any filesystem of Linux x64 and arm64 containers, including distroless containers and containers with no shell installed.

GitHub - dguerri/dockerfuse: Interact with filesystem in deployed Docker containers, via FUSE

Interact with filesystem in deployed Docker containers, via FUSE - dguerri/dockerfuse

GitHub
This is the mental image I get when someone introduces themselves as a SOC analyst
TIL: Some surprising code execution sources in bash

“Generative A.I. appeals to people who think they can express themselves in a medium without actually working in that medium. But the creators of traditional novels, paintings, and films are drawn to those art forms because they see the unique expressive potential that each medium affords. It is their eagerness to take full advantage of those potentialities that makes their work satisfying, whether as entertainment or as art.”

https://www.newyorker.com/culture/the-weekend-essay/why-ai-isnt-going-to-make-art

Why A.I. Isn’t Going to Make Art

Ted Chiang on how artificial intelligence still isn’t as intelligent as it is perceived to be and how its profound limitations should temper our fears about it replacing real art-making.

The New Yorker

Predicting CVSS Vectors with text embeddings and random forests

Check out my new blog post on using AI to solve a cybersecurity problem.

This post explores how AI can help with delays in NIST's assessment of new CVEs.

https://dguerri.github.io/random-tech-stuff/2024/08/13/cvss-vectors-with-embeddings-and-random-forests.html

Cvss Vectors With Embeddings And Random Forests

Predicting CVSS Vectors with text embeddings and random forests

Random Tech Stuff
Grammarly, by default, uses the text you type or paste into its app and website to train its AI. This feature is turned on by default, but it can be turned off. The company hides this information under the name "Product Improvement." Go to settings > privacy and turn it off. Or simple cancel delete the Grammarly from your phone. Another greedy company. I know some doctors and biz people use this app to check typos and grammar. All such sensitive information is now given to AI #privacy