liam o 🦆

@liamo
1.2K Followers
431 Following
456 Posts

🔐💻 & 🦆 ~ Infosec and Ducks ~ Slándáil faisnéise agus lachain

🧔🏻‍♂️ ~ he/him ~ sé/é

Naarm, Wurundjeri land

Foghlaimeoir Gaeilge. Labhair #Gaeilge liom!

Pronoun/Forainmhe/sé

Australian #linguistics researchers, there's work to do

CC @lingthusiasm

What a name for that first political party 🙃
Easy to choose who to preference dead last
#AusPol
Whoa. It all makes sense now 😲
Every time I walk past this street I feel like there's a chance I'll turn down it, but it kinda depends on where I'm at at the time
It's nice that Apple does AI processing on the user-controlled endpoint, and an interesting side-effect of this is that the prompts used can be read.
However the "do not hallucinate / make up information" prompts show a fundamental misunderstanding about how AI models work and will be mostly ineffective. Models don't "know" what information is factual vs hallucinated.
https://www.theverge.com/2024/8/5/24213861/apple-intelligence-instructions-macos-15-1-sequoia-beta
‘You are a helpful mail assistant,’ and other Apple Intelligence instructions

Here are some of the prompts that Apple Intelligence is using to guide AI models in the macOS 15.1 Sequoia developer beta.

The Verge
I love that OWASP ZAP maintains a "naughty and nice" list of commercial companies that use ZAP and who contributes back to the project (financially or by code commits) and who doesn't.
It's disappointing but not surprising to see how long the "naughty" list is
https://www.zaproxy.org/third-party-services/
ZAP – Third Party Products and Services

Third Party Products and Services which use or integrate with ZAP.

I am going to perform wireless attacks to steal data, but i'm going to conduct them at some of the most surveilled locations in Australia, and in different city's airports so the activities can be linked to my travel. I am also going to conduct the attacks on planes while in flight, which will limit the number of potential suspects to passengers. I am a genius cybercriminal and I will never be caught 🧠

https://www.news.com.au/travel/travel-updates/incidents/man-charged-with-evil-twin-wifi-scam-at-airports-and-on-flights/news-story/a6143f56b0b060f34003bb6968e92588

Optus broke access controls securing their site.
... and found the problem themselves
... and fixed it
... but didn't fix the broken access control on the API.
then a year later it was exploited to dump 9.5M user's data.
Big oof 😣

Source: https://comcourts.gov.au/file/Federal/P/VID429/2024/3981938/event/31836639/document/2300547

Are you a female student in your final year or final semester of a cybersecurity course at an Australian university or TAFE, and an Australian citizen or permanent resident?
If so, you are eligible to apply for the Katie Duczmal Memorial Scholarship of $10,000
Details and how to apply can be found here: https://cybercx.com.au/careers/katie-duczmal-memorial-scholarship/
Please boost this for reach if it may apply to any of your followers!
Katie Duczmal Memorial Scholarship

The Katie Duczmal Memorial Scholarship aims to support female students who have an interest in a cyber security career and are commencing or continuing their cyber security education at an Australian university or TAFE.

CyberCX
Good news everyone - being able to access other user's data without authorisation is not a cyber security issue!
#qantas