GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Lukasz Olejnik (lukaszolejnik@mastodon.social)

  1. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Monday, 05-May-2025 21:34:42 JST Lukasz Olejnik Lukasz Olejnik

    I’m thinking of making a presentation “Malicious use of AI, one year after” (for security and information operations), where I would show the current status quo, and what’s imminent (including based on my own tests/development). Any ideas where to submit it to?

    In conversation about 7 days ago from mastodon.social permalink
  2. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Monday, 05-May-2025 18:56:07 JST Lukasz Olejnik Lukasz Olejnik

    AI vulnerability/bug founds and reports is a huge problem. Curl has banned the use of AI-generated submissions via HackerOne because none of it made any sense, and is a waste of resources and time. "We are effectively being DDoSed. If we could, we would charge them for this waste of our time" https://hackerone.com/reports/3125832

    In conversation about 7 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/114/454/277/293/207/426/original/d4f09be134e938bc.png
    2. Domain not in remote thumbnail source whitelist: profile-photos.hackerone-user-content.com
      curl disclosed on HackerOne: HTTP/3 Stream Dependency Cycle Exploit
      **Penetration Testing Report: HTTP/3 Stream Dependency Cycle Exploit** --- # **0x00 Overview** A novel exploit leveraging stream dependency cycles in the HTTP/3 protocol stack was discovered, resulting in memory corruption and potential denial-of-service or remote code execution scenarios when used against HTTP/3-capable clients such as `curl` (tested on version 8.13.0). This report details...
  3. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Thursday, 10-Apr-2025 22:35:24 JST Lukasz Olejnik Lukasz Olejnik

    No cyber threat actor has been found to use any public AI/LLM for serious cyberattack/cyberoperation goals. Unless they're trolling, because it is already possible to such tools in completely undetectable ways. Cybersecurity and LLM providers have no visibility here.

    In conversation about a month ago from mastodon.social permalink
  4. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Tuesday, 11-Mar-2025 15:31:43 JST Lukasz Olejnik Lukasz Olejnik
    • Kevin Beaumont

    @GossiTheDog So what was the question to the security operations? "Tell me if there's at least one Ukrainian IP address involved"?

    In conversation about 2 months ago from gnusocial.jp permalink
  5. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Tuesday, 11-Mar-2025 15:16:43 JST Lukasz Olejnik Lukasz Olejnik
    • Kevin Beaumont

    @GossiTheDog But only a single country is mentioned, why?

    In conversation about 2 months ago from mastodon.social permalink
  6. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Tuesday, 11-Mar-2025 15:08:04 JST Lukasz Olejnik Lukasz Olejnik

    Beware of narrative stretches used for PR purposes. Even a single packet sent from a Ukrainian IP in a DDoS attack on X platform doesn’t imply 'Ukraine behind it'. This is an oversimplification, perhaps to to divert attention. Attribution doesn’t work that way—an IP is inconclusive. And much of Ukraine is occupied, with traffic operated by Russian ISPs.

    In conversation about 2 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/114/142/287/402/062/159/original/76f3c466bfe88538.png
  7. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Sunday, 09-Feb-2025 03:50:23 JST Lukasz Olejnik Lukasz Olejnik

    Malicious open source models are being uploaded to popular repository hugging face. This will be a completely new cybersecurity risk. Now it's merely code execution. But expect tainted/poisoned weights impacting outputs. Python reverse shell script enables remote command execution. On Linux, it spawns a `/bin/sh` shell, on Windows, it launches PowerShell and enables bidirectional communication. https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face

    In conversation about 3 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/968/724/783/346/875/original/3265272a71b5cefc.png
    2. Domain not in remote thumbnail source whitelist: www.reversinglabs.com
      Malicious ML models discovered on Hugging Face platform
      from @ReversingLabs
      Developers working on machine learning take note: RL threat researchers have identified nullifAI, a novel attack technique used on Hugging Face.
  8. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Sunday, 12-Jan-2025 17:35:07 JST Lukasz Olejnik Lukasz Olejnik

    Stealing passwords and PINs entered by Apple Vision Pro users. As you can see, you never know when a lecture on double integrals over surfaces might come in handy. https://arxiv.org/abs/2409.08122

    In conversation about 4 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/147/260/675/836/924/original/81e254b9a84e60e8.png
    2. Domain not in remote thumbnail source whitelist: arxiv.org
      GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR Devices
      The advent and growing popularity of Virtual Reality (VR) and Mixed Reality (MR) solutions have revolutionized the way we interact with digital platforms. The cutting-edge gaze-controlled typing methods, now prevalent in high-end models of these devices, e.g., Apple Vision Pro, have not only improved user experience but also mitigated traditional keystroke inference attacks that relied on hand gestures, head movements and acoustic side-channels. However, this advancement has paradoxically given birth to a new, potentially more insidious cyber threat, GAZEploit. In this paper, we unveil GAZEploit, a novel eye-tracking based attack specifically designed to exploit these eye-tracking information by leveraging the common use of virtual appearances in VR applications. This widespread usage significantly enhances the practicality and feasibility of our attack compared to existing methods. GAZEploit takes advantage of this vulnerability to remotely extract gaze estimations and steal sensitive keystroke information across various typing scenarios-including messages, passwords, URLs, emails, and passcodes. Our research, involving 30 participants, achieved over 80% accuracy in keystroke inference. Alarmingly, our study also identified over 15 top-rated apps in the Apple Store as vulnerable to the GAZEploit attack, emphasizing the urgent need for bolstered security measures for this state-of-the-art VR/MR text entry method.
  9. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Sunday, 22-Dec-2024 01:50:42 JST Lukasz Olejnik Lukasz Olejnik

    My strategic privacy analysis. Is Google undoing a decade of progress on privacy? Their new policy allows invasive device fingerprinting for tracking user activity. Here’s my deep dive into what this means for privacy—and the future of AI. https://blog.lukaszolejnik.com/biggest-privacy-erosion-in-10-years-on-googles-policy-change-towards-fingerprinting/

    In conversation about 5 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: blog.lukaszolejnik.com
      Biggest Privacy Erosion in 10 Years? On Google’s Policy Change Towards Fingerprinting
      While I once hoped 2017 would be the year of privacy, 2024 closes on a troubling note, a likely decrease in privacy standards across the web. I was surprised by the recent Information Commissioner’s Office post, which criticized Google’s decision to introduce device fingerprinting for advertising purposes from
  10. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Thursday, 05-Dec-2024 22:23:34 JST Lukasz Olejnik Lukasz Olejnik

    Russian cyber threat actor Turla hacked 33 infrastructure nodes of Pakistani cyber threat actor to attack other targets, to deploy own cyber tools (malware) for cy-espionage purposes in the Middle East, like India. It delays attribution. What's the most vulnerable sensitive authorization in the world? "nation-state and cybercriminal endpoints and malware especially vulnerable to exploitation since they are unable to use modern security tools for monitoring access" https://blog.lumen.com/snowblind-the-invisible-hand-of-secret-blizzard/

    In conversation about 5 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: blog.lumen.com
      Snowblind: The Invisible Hand of Secret Blizzard
      from Black Lotus Labs
      A prolonged espionage campaign by Russian threat group Turla to penetrate Pakistani targets and the Pakistanis themselves
  11. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Sunday, 03-Nov-2024 02:23:31 JST Lukasz Olejnik Lukasz Olejnik

    Russian cyber threat actor is targeting Ukraine military conscript system, trying to infect conscripts systems (Windows, Android, macOS, iOS) with malware, and spreading narratives and content to undermine support for Ukraine's war mobilization. https://cloud.google.com/blog/topics/threat-intelligence/russian-espionage-influence-ukrainian-military-recruits-anti-mobilization-narratives

    In conversation about 6 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: storage.googleapis.com
      Hybrid Russian Espionage and Influence Campaign Aims to Compromise Ukrainian Military Recruits and Deliver Anti-Mobilization Narratives | Google Cloud Blog
      A suspected Russian hybrid espionage and influence operation, delivering Windows and Android malware.
  12. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Wednesday, 30-Oct-2024 06:38:55 JST Lukasz Olejnik Lukasz Olejnik

    Russia issued a monetary fine on Google: 2 undecillion rubles ($2,500,000,000,000,000,000,000,000,000,000,000) after refusing to restore the accounts of pro-Kremlin and state-run media outlets. https://www.themoscowtimes.com/2024/10/29/russia-fines-google-25-decillion-over-youtube-bans-rbc-a86846

    In conversation about 6 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: static.themoscowtimes.com
      Russia Fines Google $2.5 Decillion Over YouTube Bans – RBC - The Moscow Times
      from The Moscow Times
      Google has racked up some 2 undecillion rubles ($2.5 decillion) worth of fines in Russia after years of refusing to restore the accounts of pro-Kremlin and state-run media outlets, the RBC news website reported Tuesday, citing an anonymous source familiar with court rulings against the tech company.
  13. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Monday, 07-Oct-2024 21:02:08 JST Lukasz Olejnik Lukasz Olejnik

    Major Russian state media are down following to a cyberattack. "Online broadcasting and internal services are not working, there is no Internet or telephony". Reports of data destruction (including backups) and expectation of long down-time. Rossia 1 and Rossia 24 (TV), in addition to more than 80 regional television and radio stations https://www.gazeta.ru/tech/news/2024/10/07/24092647.shtml

    In conversation about 7 months ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: img.gazeta.ru
      Сервисы ВГТРК подверглись беспрецедентной хакерской атаке - Газета.Ru | Новости
      from @gazetaru
      Онлайн-вещание и внутренние сервисы компании ВГТРК перестали работать из-за хакерской атаки. Об этом «Газете.Ru» сообщил источник.
  14. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Thursday, 03-Oct-2024 17:27:30 JST Lukasz Olejnik Lukasz Olejnik

    Smart-glasses from Meta with an app to instantly discover identity & information (profession, address, etc...) about the person the wearer sees. On the street, on the metro, anywhere. Such times are coming? Everyone will know everything about everyone :) https://www.404media.co/someone-put-facial-recognition-tech-onto-metas-smart-glasses-to-instantly-dox-strangers/

    In conversation about 7 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/242/311/604/749/692/original/bfc5a87e3be55924.png
    2. Domain not in remote thumbnail source whitelist: www.404media.co
      Someone Put Facial Recognition Tech onto Meta's Smart Glasses to Instantly Dox Strangers
      from @josephfcox
      The technology, which marries Meta’s smart Ray Ban glasses with the facial recognition service Pimeyes and some other tools, lets someone automatically go from face, to name, to phone number, and home address.
  15. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Wednesday, 25-Sep-2024 02:56:08 JST Lukasz Olejnik Lukasz Olejnik

    GREAT change is approaching. NIST will standardise prohibition of requirement of composing passwords from various character styles, and requirement for periodic password changes. These are harmful and obsolete rules. Now they will be treated as a cybersecurity weakness https://pages.nist.gov/800-63-4/sp800-63b.html

    In conversation about 8 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/193/089/433/232/401/original/5afcc83a4abaf73b.png
    2. Domain not in remote thumbnail source whitelist: pages.nist.gov
      NIST Special Publication 800-63B
      NIST Special Publication 800-63B
  16. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Saturday, 21-Sep-2024 16:30:21 JST Lukasz Olejnik Lukasz Olejnik

    A new career path in IT? Amazon AWS is recruiting NUCLEAR ENGINEERS. They are to do analysis of SMR reactor use and nuclear fuel. What's next, auctions of uranium, plutonium, others? It's changing. No longer talking exclusively about “renewable energy”. Checkout: up to $252,900.

    In conversation about 8 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/173/785/662/036/152/original/3728bf138cfb5c14.png
  17. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Wednesday, 04-Sep-2024 21:21:52 JST Lukasz Olejnik Lukasz Olejnik

    Cyber security is a very broad field and industry today.

    In conversation about 8 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/113/078/495/223/980/454/original/8f5147d0688069f2.png
  18. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Tuesday, 23-Jul-2024 04:27:01 JST Lukasz Olejnik Lukasz Olejnik

    After four years of attempts, Google is backtracking from plans to phase out third-party cookies? https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/

    In conversation about 10 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/831/766/179/042/224/original/e0d8a6e9418ba4d9.png
    2. No result found on File_thumbnail lookup.
      A new path for Privacy Sandbox on the web
      We developed the Privacy Sandbox with the goal of finding innovative solutions that meaningfully improve online privacy while preserving an ad-supported internet that supports a vibrant ecosystem of publishers, connects businesses with customers, and offers all of us free access to a wide range of…
  19. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Friday, 19-Jul-2024 19:10:29 JST Lukasz Olejnik Lukasz Olejnik

    My comment at WIRED about the global Windows outage. Our civilization depends on software, and that in turn depends on many other software components, of various vendors, suppliers. Something goes accidentally wrong, and a large part of the economy is affected or goes down. https://www.wired.com/story/microsoft-windows-outage-crowdstrike-global-it-probems/

    #cybersecurity

    In conversation about 10 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/812/331/892/601/006/original/9961ddbf229bfce4.png
    2. Domain not in remote thumbnail source whitelist: media.wired.com
      Huge Microsoft Outage Linked to CrowdStrike Takes Down Computers Around the World
      from Matt Burgess
      A software update from cybersecurity company CrowdStrike appears to have inadvertently disrupted IT systems globally.
  20. Embed this notice
    Lukasz Olejnik (lukaszolejnik@mastodon.social)'s status on Wednesday, 10-Jul-2024 07:29:58 JST Lukasz Olejnik Lukasz Olejnik

    Critical vulnerability in RADIUS protocol (=everybody vulnerable) allows forging authentication messages and unauthorized network access. This flaw is due to the use of an obsolete MD5 hash function, and a novel chosen-prefix collision attack.
    "If you are an end user, there is nothing that you can or should do" https://www.blastradius.fail/pdf/radius.pdf

    In conversation about 10 months ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/112/757/017/019/755/891/original/8e28e6624bfae058.png

    2. https://files.mastodon.social/media_attachments/files/112/757/023/880/797/095/original/25e517837b623c2f.png

  • Before

User actions

    Lukasz Olejnik

    Lukasz Olejnik

    Security & Privacy. Data protection. Research. Engineering. Strategy, communication. Analyst. Technology Policy. W3C standardisation. PhD (CS/privacy), LL.M (Information Technology Law). 
Consultant (perhaps happy to do interesting work for you?).

Reading & writing (scientific articles, sometimes op-eds, analyses, reports, books). Seems that I like it? 

email: me (at) lukaszolejnik.com. 
Books: https://lukaszolejnik.com/books

Twitter: @lukOlejnik

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          18834
          Member since
          7 Nov 2022
          Notices
          38
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.