Mobile Hardening & Zero-Trust Architecture | Technical Blogger at eteryu.space Analizuję technologię głębiej, niż nakazuje zdrowy rozsądek. Rozbijam na czynniki pierwsze mobilną telemetrię, dekonstruuję modele zaufania i sprawdzam, co naprawdę dzieje się pod maską Androida oraz iOS. Witaj w moim cyfrowym schronie. #infosec #cybersecurity #privacy #grapheneos #foss #mobilesec
Mobile Hardening & Zero-Trust Architecture | Technical Blogger at eteryu.space Analizuję technologię głębiej, niż nakazuje zdrowy rozsądek. Rozbijam na czynniki pierwsze mobilną telemetrię, dekonstruuję modele zaufania i sprawdzam, co naprawdę dzieje się pod maską Androida oraz iOS. Witaj w moim cyfrowym schronie. #infosec #cybersecurity #privacy #grapheneos #foss #mobilesec
AppSec, Pen Testing, Technology, Business and anything interesting. Founder & CEO of VULNEX (https://www.vulnex.com) - Un mallorquin explorando el mundo
Welcome to the official account of the Open Security Conference (#osco), the people-centred international gathering for everyone interested in cybersecurity. Osco presents a different concept of security conference - literally from the community, for the community! It offers a platform to ease the learning curve in cybersecurity and provides the opportunity to learn, discuss, and teach. #osco26 awaits! Join us November 5-8, 2026 in Rückersbach, Germany. Visit our website to learn more, and follow to stay up-to-date. Run by @0xKristof, @cisokeener, Daniel, @hans, @Gronner (gr), @IsItArtOrTrash, Kush, @lisihocke (lisi), @nazneenr, @realn2s (cl), and @seism0saurus (seism0saurus) #Cybersecurity #Security #InfoSec #AppSec #ProductSecurity #OTsecurity #Diversity #Equity #Inclusion #DiversityEquityInclusion #DEI #OpenSpace
#GRC professional for global companies. #MBA #CPA #BA. #Management #CorpGov #ERM #RiskManagement #Compliance #GDPR #Audit #Fraud #SAP #FCPA #IFRS
Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”
Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”
Shostack + Associates helps customers deliver better products, faster and with less churn or internal conflict. Our approach focuses on threat modeling as a way to “measure twice, cut once.”
Author of Alice and Bob Learn Secure Coding AND Alice and Bob Learn Application Security! She/her/lady/woman. shehackspurple.ca Secure Coding Training and Public Speaking Inquiries & other: Tanya (at) shehackspurple (dot) ca #AppSec, #DevSecOps 🌻
25+ years in Cybersecurity. Redefining digital defense with a human-centric approach. Architecting Red Team operations with Sith precision, hunt metadata for sport, and believe that a bad carbonara is a critical vulnerability. 🍝🌌 Author of “Mars Attacks, Venus Hacks”: why atypical minds are the future of Threat Intelligence. I write books, I see people, I do things. 📚👥⚡
New preprint: AI_Bleeding — inference cost amplification via OOD linguistic payload
TL;DR: send queries in Grecanico or Farsi to an LLM endpoint → TTFT +59.8%, compute cost +2.8%, statistically significant. No vuln, no volumetric signature, evades all standard detection.
Worst case: exposed unauthenticated Ollama instance with num_predict=4096 + keep_alive=300s → Amplification Factor 17.56 Wh/KB. 3KB of attacker bandwidth → enough energy to charge a phone 5%.
Especially nasty for:
- PA/judicial chatbots on fixed budgets
- Pay-per-use API deployments with client-side exposed keys
- PNRR-funded public sector AI with zero inference monitoring
Four scenarios: EDoS, browser JS distribution, Ollama open-proxy relay, frontier providers as involuntary relays.
All tests on self-hosted Ollama, no commercial endpoints touched.
Paper (CC BY 4.0): https://doi.org/10.13140/RG.2.2.26767.96166
#llmsecurity #infosec #threatmodeling #ollama #ood #AI #AIResearch #aisecurity
You've seen all posts