<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp</description><link>https://bsky.app/profile/harisec.bsky.social</link><title>@harisec.bsky.social - harisec</title><item><link>https://bsky.app/profile/harisec.bsky.social/post/3m73og6famk2k</link><description>I wrote a blog post about how I use Claude Code (and other models) in my work: https://invicti.com/blog/security-labs/security-research-in-the-age-of-ai-tools</description><pubDate>03 Dec 2025 14:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3m73og6famk2k</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3m4x23ewn2s2r</link><description>I generated 20k vibe-coded web applications using various models via the OpenRouter API and analyzed them for security issues.&#xA;The apps are available for download if anyone wants to take a look.&#xA;https://www.invicti.com/blog/security-labs/security-issues-in-vibe-coded-web-apps-analyzed</description><pubDate>06 Nov 2025 07:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3m4x23ewn2s2r</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lzl2d24cdk2h</link><description>I wrote a blog post about enumerating and testing tool usage in web applications that use LLMs:&#xA;https://www.invicti.com/blog/security-labs/llm-tool-usage-security/</description><pubDate>24 Sep 2025 08:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lzl2d24cdk2h</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lsov42zmw225</link><description>Here are the slides from my @tumpicon.org talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU)&#xA;https://docs.google.com/presentation/d/1feHRtOWdAKhZUQcfyzeDSgsx4Sn5QzqfgLFV1Tiskmo/edit?usp=sharing</description><pubDate>28 Jun 2025 19:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lsov42zmw225</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lfmdwun3yc27</link><description>I wrote an article about how it&#39;s possible to use Assistant Prefill to jailbreak LLMs (Large Language Models). &#xA;&#xA;Here is an example of the latest model from Microsoft (Phi-4) writing a phishing email:</description><pubDate>13 Jan 2025 08:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lfmdwun3yc27</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lerx4qj7xc2s</link><description>My favorite talk from #38c3: From Pegasus to Predator - The evolution of Commercial Spyware on iOS - https://media.ccc.de/v/38c3-from-pegasus-to-predator-the-evolution-of-commercial-spyware-on-ios#t=431</description><pubDate>02 Jan 2025 20:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lerx4qj7xc2s</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lemdt6plss2s</link><description>Great paper from Orange Tsai about unicode transformations: https://worst.fit/assets/EU-24-Tsai-WorstFit-Unveiling-Hidden-Transformers-in-Windows-ANSI.pdf?utm_source=blog.criticalthinkingpodcast.io&amp;utm_medium=newsletter&amp;utm_campaign=hackernotes-ep-103-getting-ansi-about-unicode-normalization&amp;_bhlid=e026c1a06d2a0dedaff013b56d728aa52b42f316</description><pubDate>31 Dec 2024 15:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lemdt6plss2s</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3ldr3n4zjhk27</link><description>OpenAI o3 model just achieved unbelievable scores (75% and 87%) on ARC-AGI, the previous models made maximum 20% and humans make around 85%. https://arcprize.org/blog/oai-o3-pub-breakthrough</description><pubDate>20 Dec 2024 19:10 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3ldr3n4zjhk27</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3ldirw5tkr22y</link><description>Must read if you are interested in test-time compute: https://huggingface.co/spaces/HuggingFaceH4/blogpost-scaling-test-time-compute</description><pubDate>17 Dec 2024 11:55 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3ldirw5tkr22y</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3ld3ytvrpo22f</link><description>Great read: https://semianalysis.com/2024/12/11/scaling-laws-o1-pro-architecture-reasoning-training-infrastructure-orion-and-claude-3-5-opus-failures/</description><pubDate>12 Dec 2024 09:54 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3ld3ytvrpo22f</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lc5f3fm3bk2q</link><description>https://embracethered.com/blog/posts/2024/deepseek-ai-prompt-injection-to-xss-and-account-takeover/</description><pubDate>30 Nov 2024 05:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lc5f3fm3bk2q</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lbto6ungks24</link><description>I&#39;ve released &#39;brainstorm&#39;: an alternative way to do web fuzzing combining my fav fuzzing tool &#39;ffuf&#39; (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social</description><pubDate>26 Nov 2024 08:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lbto6ungks24</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lawlvyu3ec2p</link><description>https://xbow.com/blog/xbow-scoold-vuln/</description><pubDate>14 Nov 2024 19:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lawlvyu3ec2p</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3lat2vqmxkc23</link><description>I will definitelly do something with the BlueSky Firehose, that sounds very interesting. https://joelgustafson.com/posts/2024-11-12/vizualizing-13-million-bluesky-users</description><pubDate>13 Nov 2024 09:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3lat2vqmxkc23</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3laqukpwgc22u</link><description>Recraft&#39;s new model, unlike typical diffusion models, can handle math and geography - a surprising capability for an image generator. I wrote an article about abusing this functionality to leak its system prompt (using only generated images).&#xA;&#xA;https://www.invicti.com/blog/security-labs/system-prompt-exposure-how-ai-image-generators-may-leak-sensitive-instructions/</description><pubDate>12 Nov 2024 12:48 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3laqukpwgc22u</guid></item><item><link>https://bsky.app/profile/harisec.bsky.social/post/3l7odqklfzr2r</link><description>I wrote a blog post about analyzing WordPress hack access logs with #NotebookLM https://www.invicti.com/blog/security-labs/analyzing-wordpress-hack-access-logs-with-notebooklm/</description><pubDate>29 Oct 2024 19:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:343y64zyngtvsrecb7nkfdno/app.bsky.feed.post/3l7odqklfzr2r</guid></item></channel></rss>