Dino's Avatar

Dino

@dinodunn.bsky.social

Security Engineer with a caffeine and book addiction

32 Followers  |  68 Following  |  24 Posts  |  Joined: 07.11.2024  |  1.8746

Latest posts by dinodunn.bsky.social on Bluesky

Preview
AI Red-Teaming Design: Threat Models and Tools | Center for Security and Emerging Technology Red-teaming is a popular evaluation methodology for AI systems, but it is still severely lacking in theoretical grounding and technical best practices. This blog introduces the concept of threat model...

cset.georgetown.edu/article/ai-r... - Great article on Ai Red teaming #Cybersecurity #AI #AIsecurity

27.10.2025 15:34 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
State of Exploitation - A look Into The 1H-2025 Vulnerability Exploitation & Threat Activity | Blog | VulnCheck A Look into the Last 6-months of Vulnerability Exploitationโ€ฆ January-June 2025

www.vulncheck.com/blog/state-o... some great threat intel from Vulncheck

31.07.2025 14:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
The Everyday American Who Hustled for North Korea The Journal. ยท Episode

open.spotify.com/episode/1fEa... - North Korean's inflitrating US companies for cash is pretty big news right now and also pretty fascinating. This story is about one of the folks who manage a north Korean laptop farm and its pretty interesting.

#Cybersecurity #Laptopfarm

04.06.2025 14:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

www.hackthelogs.com/mainpage.html Another great resource for Detection Engineers and anyone working with SIEM's

#Cybersecurity

03.06.2025 16:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cross-Site Scripting (XSS) Cheat Sheet - 2025 Edition | Web Security Academy Interactive cross-site scripting (XSS) cheat sheet for 2025, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors.

Really cool one for anyone in Appsec or red team awesome XSS cheat sheet from PortSwigger.

portswigger.net/web-security...

#Cybersecurity #Cheatsheet #Appsec

03.06.2025 16:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

hopefully they do better than the City of Columbus did during their ransomware incident last year.

28.05.2025 20:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Top CVE Trends & Expert Vulnerability Insights Stay ahead with the latest insights on trending vulnerabilities. Discover today's top 10 CVEs on social media. Get free and expert commentary from Intruder

cvemon.intruder.io - Great tool for any folks in Vulnerability Management. Helpful to see whats going on in CVE's.

#VulnManagement #cybersecurity

28.05.2025 20:29 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI Red Teamer Job Role Path | HTB Academy The AI Red Teamer Job Role Path, in collaboration with Google, trains cybersecurity professionals to assess, exploit, and secure AI systems. Covering prompt...

academy.hackthebox.com/path/preview... - Killer resource for anyone in Cybersecurity looking to level up their skills on AI security!

#AIsecurity #cybersecurity #redTeam

28.05.2025 20:28 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
ะŸั€ะฐะฒะพะฒะพะน ัƒะณะพะปะพะบ ะพั„ะธั†ะตั€ะฐ ๐Ÿช– // ะกะบะฐะฝะดะฐะป ะฒ ะ’ะพะตะฝะฝะพ-ะบะพัะผะธั‡ะตัะบะพะน ะฐะบะฐะดะตะผะธะธ: ะบัƒั€ัะฐะฝั‚ ะทะฐะดะตั€ะถะฐะฝ ะทะฐ ะฒะทะปะพะผ ะทะฐั‰ะธั‰ะตะฝะฝะพะน ะธะฝั„ะพั€ะผะฐั†ะธะธ ะšัƒั€ัะฐะฝั‚ ะ’ะพะตะฝะฝะพ-ะบะพัะผะธั‡ะตัะบะพะน ะฐะบะฐะดะตะผะธะธ ะธะผะตะฝะธ ะ.ะค. ะœะพะถะฐะนัะบะพะณะพย  ั€ะฐะทั€ะฐะฑะพั‚ะฐะป ะฟั€ะพะณั€ะฐะผะผัƒ, ัะฟะพัะพะฑะฝัƒัŽ ะฒะทะปะฐะผั‹ะฒะฐั‚ัŒ ะทะฐั‰ะธั‚...

New Darwin Awards 2025 nominee:

A Russian space academy cadet created a tool to access classified data on the Russian MOD network and was selling it for only $100 on Russia's biggest classified ads portal

He was arrested by the FSB last week

t.me/voenpravoru/...

12.05.2025 21:30 โ€” ๐Ÿ‘ 9    ๐Ÿ” 5    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 0
Preview
How to Get Started with Secure Code Review Since starting my secure code review challenges in December 2023 (https://github.com/dub-flow/secure-code-review-challenges), many peopleโ€ฆ

medium.com/@dub-flow/ho... Great into for secure code review along with some resources to help folks get better at it #cybersecurity #code

14.03.2025 15:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

orange-cyberdefense.github.io/ocd-mindmaps... such a cool Active Directory min map for offensive security

#Activdirectory #cybersecurity #redteam

11.03.2025 21:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AI Red Teamer Job Role Path | HTB Academy The AI Red Teamer Job Role Path, in collaboration with Google, trains cybersecurity professionals to assess, exploit, and secure AI systems. Covering prompt...

academy.hackthebox.com/path/preview... - This is virtually free @hackthebox.bsky.social silly cube payment system makes me feel like im a kid at Chuck-E-Cheese again BUT the content is excellent and great for anyone starting from the ground up in AI red teaming #AI #infosec #Cybersecurity

05.02.2025 06:29 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Why the AI world is suddenly obsessed with a 160-year-old economics paradox The primer on Jevons paradox that you didn't know you needed.

www.npr.org/sections/pla... - This is a pretty good read on #AI. Simply put the comparison is to coal back in England in the 1800s as efficiency increased the common thought was consumption would decrease. But instead there was a rebound effect. Some are pondering if this will be the same for AI/LLM

05.02.2025 06:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Adversarial Misuse of Generative AI | Google Cloud Blog We share our findings on government-backed and information operations threat actor use of the Gemini web application.

cloud.google.com/blog/topics/... - great read from Google on Adversarial misuse of Gen AI and what they have been seeing from threat actors lately.

Too many cool take aways to fit them all in

#infosec #cybersecurity #AIsecurity

29.01.2025 15:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Ransomware.live ๐Ÿ‘€ Ransomware.live tracks ransomware groups and their activity. It was created by Julien Mousqueton, a security researcher. The website provides information on the groups' infrastructure, victims, and payment demands. It also includes a live map that shows the latest ransomware attacks.

www.ransomware.live/vulns This is such a cool site if you are in CTI and not using it I think it can easily make it into your weekly checks. Beyond the great wealth of Ransomware data they just added some of @bushidotoken.net's CVE,TOOLS and TTP's matrix.

#CTI #threatintel #cybersecurity

28.01.2025 21:37 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
DeepSeek R1 Exposed: Security Flaws in Chinaโ€™s AI Model Discover the security flaws in DeepSeek R1, a Chinese AI model with advanced reasoning capabilities. KELA's analysis reveals vulnerabilities, outdated safeguards, and privacy risks, emphasizing the ne...

www.kelacyber.com/blog/deepsee... - Great read on DeepSeek security flaws. personal experience it is a little bit easier to jailbreak than others which can pose some risk. Though I do feel there is a bit of overblown hype around some aspects.

#cybersecurit #AI #llm

28.01.2025 21:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Public Buckets by GrayhatWarfare

buckets.grayhatwarfare.com - This is a pretty neat search engine for open/public/misconfigured buckets both S3 and any other S3 similar cloud product (Digital Ocean, Azure Blob, Google Drive etc.)

#cybersecurity #CloudSecurity #security #infosec

05.12.2024 21:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - lkarlslund/nifo: Nuke It From Orbit - remove AV/EDR with physical access Nuke It From Orbit - remove AV/EDR with physical access - lkarlslund/nifo

github.com/lkarlslund/n... - Nuke it from orbit is a pretty neat concept of removing AV/EDR when you have physical access to a machine might be fun to play around with but also use with care ๐Ÿ˜

02.12.2024 23:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Humble Tech Book Bundle: Hacking 2024 by No Starch Level up your hacking and skills with this tech bundle from No Starch. Learn to protect yourself and others! Pay what you want & support charity!

www.humblebundle.com/books/hackin... - Killer bundle of books for $20 from humble bundle evading EDR and windows security internals such a good deal for anyone in Cybersecurity.

#cybersecuriry #infosec #Hacking

02.12.2024 20:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Elastic releases the Detection Engineering Behavior Maturity Model โ€” Elastic Security Labs Using this maturity model, security teams can make structured, measurable, and iteritive improvements to their detection engineering teams..

www.elastic.co/security-lab... - great read on maturity model for Detection Engineering.

#infosec #cybersecurity #cyber #Detection

29.11.2024 20:50 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Streamlit

juniverse.securitybreak.io - Some pretty useful Jupyter Notebooks for infosec IOC extractor, threat intel summarization and more.

#infosec #cybersecurity #python #LLM

29.11.2024 16:20 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
mr. burns from the simpsons is making a funny face and says `` excellent '' . ALT: mr. burns from the simpsons is making a funny face and says `` excellent '' .

excellent ill play around with it

22.11.2024 22:51 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
AMSI Bypass Methods Microsoft has developed AMSI (Antimalware Scan Interface) as a method to defend against common malware execution and protect the end user. By default windows defender interacts with the AMSI API toโ€ฆ

pentestlaboratories.com/2021/05/17/a... - awesome write up on various AMSI bypass methods

#cybersecurity #redteaming #infosec

21.11.2024 20:29 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
GitHub - WithSecureLabs/cloud-security-vm: Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments Ansible/Vagrant/Packer files to create a virtual machine with the tooling needed to perform cloud security assessments - WithSecureLabs/cloud-security-vm

github.com/WithSecureLa... - Pretty neat new Cloud security Virtual machine with allot of great pre installed tools.

#cloudsecurity #cybersecurity #redteaming #security

14.11.2024 15:29 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
GitHub - pasquini-dario/project_mantis Contribute to pasquini-dario/project_mantis development by creating an account on GitHub.

github.com/pasquini-dar...

Pretty awesome concept for defense against offensive AI agents. Conceptually it is a honey pot that leads the AI agent to indirect prompt injection. Very cool for anyone interested in #AIsecurity

#llmsecurity #cybersecurity

08.11.2024 15:47 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@dinodunn is following 19 prominent accounts