<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    
    <title>Threlfall hax</title>
    
    
    <description>threfll_hax - trying to contribute.</description>
    
    <link>https://5stars217.github.io/</link>
    <atom:link href="https://5stars217.github.io/feed.xml" rel="self" type="application/rss+xml" />
    
    
      <item>
        <title>Adversaries sometimes compute gradients. Other times, they rob you.</title>
        <description>
          Build your adversary flywheel. - 
          Adversaries sometimes compute gradients. Bottom line up front: You want to know where the defender has less visibility, and exploit that? Build an adversary flywheel. The next phase of asymmetric adversarial engagements against apex defenders requires you to understand the defensive flywheel, and use data science to rapidly pivot the...
        </description>
        <pubDate>Tue, 23 Apr 2024 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2024-04-23-adversaries-sometimes-compute-gradients/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2024-04-23-adversaries-sometimes-compute-gradients/</guid>
      </item>
    
      <item>
        <title>What enables malicious models?</title>
        <description>
          It's not just about the malicious models, to create a practical attack path, you need more ducks in a row. - 
          Practicalities of Malicious Models Background This is about how I felt reading a couple of recent pieces about discovering malicious models on Huggingface. There’s been a steady increase in the amount of posts raising awareness of malicious models, which is cool. It’s also been fun seeing some of my payloads...
        </description>
        <pubDate>Mon, 04 Mar 2024 00:00:00 -0500</pubDate>
        <link>https://5stars217.github.io/2024-03-04-what-enables-malicious-models/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2024-03-04-what-enables-malicious-models/</guid>
      </item>
    
      <item>
        <title>Introducing the Offsec ML Playbook v0.1</title>
        <description>
          Enabling Red Teams to quickly leverage TTPs on ML infrastructure - 
          Offsec ML Playbook A database of offensive ML TTP’s, broken down by supply chain attacks, offensive ML techniques and adversarial ML. The playbook aims to simplify the decision making process of targetting ML in an organization. Want to poison an LLM’s ground truths? We can do that. Want to put...
        </description>
        <pubDate>Thu, 26 Oct 2023 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2023-10-26-introducing-offsec-ml-framework/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2023-10-26-introducing-offsec-ml-framework/</guid>
      </item>
    
      <item>
        <title>Using KServe to deploy malicious models</title>
        <description>
          Weaponizing MLops for red teams and bounty hunters - 
          This post builds upon my prior research into what red teams can do with ML environments. Now we look at using other components of common ML pipelines in our attacks as either pre or post exploitation targets. Table of Contents Table of Contents Introduction What is kserve? What is important...
        </description>
        <pubDate>Wed, 25 Oct 2023 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2023-10-25-using-KServe-to-deploy-malicious-models/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2023-10-25-using-KServe-to-deploy-malicious-models/</guid>
      </item>
    
      <item>
        <title>Model Confusion - Weaponizing ML models for red teams and bounty hunters</title>
        <description>
          How I hacked a bunch of companies via machine learning attacks. - 
          This post accompanies my DEFCON31 AI Village talk - “You sound confused, anyways… Thanks for the jewels”. Table of Contents Table of Contents Introduction Why would you want to do this? TLDR Hugging Face? How Does it Work? ML Ops Pipelines Why Target ML Environments? What I Like About Huggingface...
        </description>
        <pubDate>Tue, 08 Aug 2023 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2023-08-08-red-teaming-with-ml-models/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2023-08-08-red-teaming-with-ml-models/</guid>
      </item>
    
      <item>
        <title>On Malicious Models</title>
        <description>
          A traditional attack vector applied to AI/ML Models - 
          Background New tech, old risks As a security researcher, I’m excited at the new ground to cover; the attacks that are possible, like adversarial ML attacks against algorithms and data, and the twists on old ones we get to explore. We all know that when we source software from places...
        </description>
        <pubDate>Thu, 30 Mar 2023 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2023-03-30-on-malicious-models/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2023-03-30-on-malicious-models/</guid>
      </item>
    
      <item>
        <title>Langchain &amp; Prompt Plumbing</title>
        <description>
          One of the coolest things in programming I've seen. Legos for AI. - 
          Background After reading about Langchain on a collaborative blog at work, I decided to check it out some. Like most of us, a blocker to my deeper usage of AI in my workflows is that it doesn’t know about my private data sources, like my Obsidian Wiki, Github Repos, Google...
        </description>
        <pubDate>Thu, 30 Mar 2023 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2023-03-30-Langchain-Intro/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2023-03-30-Langchain-Intro/</guid>
      </item>
    
      <item>
        <title>Unusual Behaviors in Solidity and the EVM through a cross-bridge lens.</title>
        <description>
          Behaviors and interactions that can lead to security issues when dealing with multiple smart contract languages. - 
          Background Solidity is a high-level language used in the creation of Ethereum smart contracts, compiling to Ethereum Virtual Machine(EVM) Bytecode. It looks a little like Javascript, and was heavily influenced by C++, Python and of course Javascript. It is not the only language that can be used for creating smart...
        </description>
        <pubDate>Tue, 08 Feb 2022 00:00:00 -0500</pubDate>
        <link>https://5stars217.github.io/2022-02-08-cross-bridge-security/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2022-02-08-cross-bridge-security/</guid>
      </item>
    
      <item>
        <title>My Favourite Dep Malware PureScript NPM Installer</title>
        <description>
          A tale of a really cool piece of malware you probably haven't heard of - 
          Background In July 2019, code was added to an upstream of the purescript npm installer which sabotaged the completion of the installation process in a particularly interesting way. The subterfuge was particularly difficult to uncover &amp;amp; debug, taking 5 days for some of the most talented and skilled npmjs devs...
        </description>
        <pubDate>Wed, 11 Aug 2021 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2021-08-11-my_favourite_dep_malware/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2021-08-11-my_favourite_dep_malware/</guid>
      </item>
    
      <item>
        <title>Metadata Analysis of php-src backdoor attempt</title>
        <description>
          Investigating future model detection mechanisms for open source project repositories - 
          Background This work follows on from my prior metadata analysis which provides justification for this type of analysis. The PHP project recently discovered that attackers were able to gain access to its main Git server and upload two malicious commits, one of which contained a backdoor. Thankfully, the backdoor was...
        </description>
        <pubDate>Mon, 10 May 2021 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2021-05-10-metadata-analysis-php-attempted-backdoor/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2021-05-10-metadata-analysis-php-attempted-backdoor/</guid>
      </item>
    
      <item>
        <title>Metadata Analysis of flatmap dependency supply chain attack</title>
        <description>
          Investigating future model detection mechanisms for open source project repositories - 
          There’s been hundreds of software dependency supply chain attacks exploiting a range of vectors in the past, with great effect. The July 2020 paper by Marc Ohm et al describes that on average a malicious package is available for 209 days. (𝑚𝑖𝑛=−1,𝑚𝑎𝑥=1,216,𝜎=258,𝑥̃ =67) so naturally, any method to reduce this...
        </description>
        <pubDate>Mon, 03 May 2021 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2021-05-03-metadata-analysis-flatmap/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2021-05-03-metadata-analysis-flatmap/</guid>
      </item>
    
      <item>
        <title>Enterprise Threat Hunting for Dependency Confusion &amp; Typosquatting</title>
        <description>
          The fundamentals once again determine the ease of enterprise response. - 
          This collection of advice is aimed to improve the detection of dependency confusion and typo-squatting attacks at enterprise, where response to such a thing can be tricky due to scale or fragmentation. Agenda Background The problem Additional problems Solutions Tips, tricks, tools for threat hunters and red teams background Package...
        </description>
        <pubDate>Sat, 01 May 2021 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2021-05-01-Ent_threat_hunting_typos_confusion/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2021-05-01-Ent_threat_hunting_typos_confusion/</guid>
      </item>
    
      <item>
        <title>The CEO of SolarWinds (and former CEO of Pulse Secure) is clearly a victim of witchcraft.</title>
        <description>
          Has there ever been such compelling evidence of the existence of magic? - 
          Over the years I have conducted numerous physical and personal security assessments for businesses and executives. Part of that assessment has always included a sweep for hex bags and other physical curses. Using this knowledge, I must state that the CEO at the center of two of the most serious...
        </description>
        <pubDate>Thu, 22 Apr 2021 00:00:00 -0400</pubDate>
        <link>https://5stars217.github.io/2021-04-22-solarwinds_ceo_magic/</link>
        <guid isPermaLink="true">https://5stars217.github.io/2021-04-22-solarwinds_ceo_magic/</guid>
      </item>
    
  </channel>
</rss>
