Galera, quem não me segue no linkedin aí, cola lá

https://www.linkedin.com/in/bruno-menozzi

Vou voltar a postar mais vagas de appsec e offensive security que tenho visto
Eu confesso que ainda nunca usei esse conceito, mesmo ja tendo postado aqui e sei que é a nova hype

Alguem ai ja testou na pratica o graph?

https://x.com/0xcodez/status/2079165300625330317?s=46
Salve! Eai, qual sua atual profissão hoje? Tá no grupo desde quando?
“Acabou que tivemos que usar um modelo chines pra ajudar na investigacao por que os modelos famosinhos se recusaram a investigar o incidente por que nao sabiam diferenciar entre um ataque real e um esforco legitimo de respostas a incidente”

Que comedia kkkk
Pra quem não sabe, além de pentest, eu sou apaixonado em appsec pq consigo ficar no dia a dia perto dos desenvolvedores, vendo as tecnologias novas que estão surgindo, a crescente adoção das IAs, os code-reviews etc
https://www.youtube.com/watch?v=R5Eca_H7mxA

Highlights:

- Opened with a full audit of Crocs, socks, and Birkenstock ownership across all four of us, this is a running bit now and I have accepted my fate as the guy with two Crocs and six Birkenstocks

- ASPM consolidation, Gartner smashed dashboards and scanners into one category and now every vendor is one bolted onto the other, my take is it only works when it cuts noise and gives execs one place to look without a meeting

- Risk management versus vulnerability management, we still don't agree on the vocabulary as an industry, VulnOps came up because of course it did

- Malicious packages versus vulnerable packages get treated like the same problem and they're not, one's a mistake and one's a bomb someone shipped you on purpose

- My running frustration that AppSec is quietly becoming the SOC, we're the ones getting the 2am call on a compromised npm package because the SOC has zero visibility past the OS

- New OWASP Top 10 pitches, mine is developer endpoint risk, Kurt threw out critical infrastructure and autonomous vehicles, fair, we have one for boats

- Closed on the Mythos and Fable export sanctions as the biggest AppSec story of Q2, less about the models and more about everything that spun out of it
O que eu mais tenho visto as pessoas falando e concordo é: o que mais importa hoje em dia não é tu codar, ter o melhor código etc, é tu saber system design.
Bruno Menozzi (Zeroc00I)
É isso. A mesma opinião que compartilho aqui sobre os modelos de IA: O quanto os modelos que precisam implementar guardrails por pressão governamental etc tendem a ficar pra trás do que os pesquisadores de segurança precisam It’s becoming obvious that relying…
A cheaper model in a good harness beats a frontier model in a generic one. On top of that, deterministic orchestration gives us confidence we actually covered the whole codebase, when you just ask Codex for vulns, you can never be sure it looked everywhere.


Sacada muito interessante. Aqui fala que se tu tiver usando um dos modelos mais baratos mas com um harness bom, supera um modelo bom com harness ruim
É isso. A mesma opinião que compartilho aqui sobre os modelos de IA: O quanto os modelos que precisam implementar guardrails por pressão governamental etc tendem a ficar pra trás do que os pesquisadores de segurança precisam

It’s becoming obvious that relying on frontier models is getting to be risky business. Either the model gets export controlled, or it gets nerfed with hidden guardrails. The second one is the more annoying problem for defensive cybersecurity work. When a model like Fable outright blocks anything security-related, that’s at least transparent, because we know upfront it doesn’t work for cybersecurity. The real problem is hidden guardrails, a frontier model quietly stops working for a use case and we can’t tell why, and sometimes an older version performs better than the new one (more on that later in the blog).

https://www.hacktron.ai/blog/open-weight-models-vs-frontier-models
Back to Top