Dino's Avatar

Dino

@dinodunn

Security Engineer with a caffeine and book addiction

47
Followers
74
Following
45
Posts
07.11.2024
Joined
Posts Following

Latest posts by Dino @dinodunn

Preview
GitHub - Mojo8898/aliasr: Aliasr is a modern, feature-rich TUI launcher for penetration testing commands inspired by Arsenal, but with significantly improved functionality. Aliasr is a modern, feature-rich TUI launcher for penetration testing commands inspired by Arsenal, but with significantly improved functionality. - Mojo8898/aliasr

github.com/Mojo8898/ali... - very cool #redteam tool, handy when your syntax is maybe a little off or you just want an improved chance of staying ahead. either way very cool to play around with for CTF

#cyber #cybersecurity

20.01.2026 21:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Why is Everyone So Wrong About AI Water Use??
Why is Everyone So Wrong About AI Water Use?? YouTube video by Hank Green

www.youtube.com/watch?v=H_c6... Solid watch for any folks interested in AI water useage. It is pretty interesting how you could get an honest answer that is both insanely big and insanely small and it just matters how the person crunched the numbers.

#AI #LLM

15.01.2026 22:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How to operationalize the OWASP LLM top 10 and (actually) secure GenAI apps Deploying LLMs without chaos means treating the OWASP LLM Top 10 like an engineering spec. Learn how to turn each risk into real controls, harden pipelines, and secure GenAI apps.

www.hackthebox.com/blog/operati... - Solid read on operationalizing OWASP security recommendations.

#Cybersecurity #AIsecurity

14.01.2026 16:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
0. AI Security Overview – AI Exchange Comprehensive guidance and alignment on how to protect AI against security threats - by professionals, for professionals.

owaspai.org/docs/ai_secu... Some solid AI security resource from the OWASP AI exchange.

#cybersecurity #OWASP #AI #AIsecurity #LLM

14.01.2026 15:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - Maldev-Academy/DumpBrowserSecrets: Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern... Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers ...

github.com/Maldev-Acade... - Really cool tool for any Red teamers looking to dump browser credentials. Take a look and thank the folks over at Mal Dev academy.

#cybersecurity #redteam #offensivesecurity

14.01.2026 00:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Arcanum PI Taxonomy - Prompt Injection Attack Classification

arcanum-sec.github.io/arc_pi_taxon... - Cool tool from Arcanum security building out different prompt injection classifications and some fun ideas if you are looking to test for some things.

12.01.2026 23:16 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
πŸ¦• STE.GG

www.ste.gg - Awesome new tool from the folks at BT6! if you have any quick and dirty stego needs

#cybersecurity #cyber

12.01.2026 16:23 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
IBM AI ('Bob') Downloads and Executes Malware IBM's AI coding agent 'Bob' has been found vulnerable to downloading and executing malware without human approval through command validation bypasses exploited using indirect prompt injection.

www.promptarmor.com/resources/ib... - This is a pretty great write up on AI agent running ransomware keep a good eye on your agents

#AIsecurity #LLMsecurit #cybersecurity #ai

09.01.2026 17:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
LeakHub

leakhub.ai - pretty neat new site from Pliney the hacker for leaked AI system prompts

#AI #LLM #cybersecurity

08.01.2026 17:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
OWASP Top 10 LLM Security Risks with Mitigation OWASP Top 10 LLM Security Risks: An interactive diagram maps each risk, attack path, and concrete mitigation you can explore to secure AI systems in production

www.paloaltonetworks.com/resources/in... This is a pretty awesome Infographic from @paloaltonetworks.com on OWASP top 10 for LLM security risks. #LLM #AI #Security #Cyber

17.12.2025 18:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It be like that.... more than sometimes. #cybersecurity #Redteam #EDR

17.12.2025 18:35 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

It be like that.... more than sometimes. #cybersecurity #Redteam #EDR

17.12.2025 18:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AI Privacy Course | HTB Academy This module explores privacy attacks against machine learning models and the differential privacy defenses that protect models from such attacks.

academy.hackthebox.com/course/previ... Some really interesting courses dropping from HTB on AI privacy and defense today!

#LLM #privacy #AI

09.12.2025 20:28 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
How We Caught Lazarus's IT Workers Scheme Live on Camera See how Lazarus Group's IT workers scheme was exposed on a live camera using real-time monitoring inside ANY.RUN’s sandbox.

any.run/cybersecurit... THIS is such a cool analysis inside the Lazarus groups operations #cyber #cybersecurity #malware

04.12.2025 23:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Humble Tech Book Bundle: Hacking by No Starch Turn your curiosity about computer hacking into a fast-paced, proven, and practical career with the latest Humble Tech Book Bundle!

There’s a new Humble book bundle featuring a set of No Starch Press books on Hacking. For a limited time, pay what you want AND support EFF’s fight for privacy and free speech online! www.humblebundle.com/books/hacki...

04.12.2025 23:00 πŸ‘ 53 πŸ” 23 πŸ’¬ 0 πŸ“Œ 1
Post image

It will only be weird for like a year that every new ransomware discovery gets tagged as "Satoru Gojo" #cybersecuirty #meme

04.12.2025 15:39 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Threat Watch: Spotting Kerberoasting from a blue team perspective | Learn with HTB
Threat Watch: Spotting Kerberoasting from a blue team perspective | Learn with HTB YouTube video by Hack The Box

www.youtube.com/watch?v=pRij... - This was a really really good break down on Kerberoasting for Blue Teams highly recommend to any folks looking to understand how to triage a Kerberoasting attack.

#cybersecurity

21.11.2025 18:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
OffSec’s Exploit Database Archive The GHDB is an index of search queries (we call them dorks) used to find publicly available information, intended for pentesters and security researchers.

www.exploit-db.com/google-hacki... Kind of neat I didn't know Offsec kept a database of useful google dorks

#cybersecurity #OSINT

21.11.2025 16:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

Man these @groktr.bsky.social upgrades are sick clearly not kissing ass at all #ai #llm #memes

20.11.2025 19:12 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - Pennyw0rth/NetExec-Lab: Lab used for workshop and CTF Lab used for workshop and CTF. Contribute to Pennyw0rth/NetExec-Lab development by creating an account on GitHub.

github.com/Pennyw0rth/N... I feel a netexec theme today apparently. This is a netexec lab you can build to play around with Active directory. may be worth a shot if you are practicing for OSCP or just want to level up AD #ActiveDirectory #RedTeam #Netexec

13.11.2025 17:35 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Home Dominate Active Directory with PowerShell. . Contribute to The-Viper-One/PsMapExec development by creating an account on GitHub.

github.com/The-Viper-On... Pretty cool tool if you are doing red teaming from a windows host. Great to add in for Commando VM from Mandiant #redteam #cyber #tool Basically it is crackmap/netexec just built in Powershell.

13.11.2025 16:56 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Practical SOC Analyst Professional (PSAP) Certification - TCM Security Enhance your SOC Analyst skills by earning the Practical SOC Analyst Professional (PSAP) certification. Includes training and one free retake!

@tcmsecurity.bsky.social just dropped their new SOC200 course great for anyone looking to build labs and get better at incident response and threat hunting.

certifications.tcm-sec.com/psap/?utm_so...

07.11.2025 18:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
AI Red-Teaming Design: Threat Models and Tools | Center for Security and Emerging Technology Red-teaming is a popular evaluation methodology for AI systems, but it is still severely lacking in theoretical grounding and technical best practices. This blog introduces the concept of threat model...

cset.georgetown.edu/article/ai-r... - Great article on Ai Red teaming #Cybersecurity #AI #AIsecurity

27.10.2025 15:34 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
State of Exploitation - A look Into The 1H-2025 Vulnerability Exploitation & Threat Activity | Blog | VulnCheck A Look into the Last 6-months of Vulnerability Exploitation… January-June 2025

www.vulncheck.com/blog/state-o... some great threat intel from Vulncheck

31.07.2025 14:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Everyday American Who Hustled for North Korea The Journal. Β· Episode

open.spotify.com/episode/1fEa... - North Korean's inflitrating US companies for cash is pretty big news right now and also pretty fascinating. This story is about one of the folks who manage a north Korean laptop farm and its pretty interesting.

#Cybersecurity #Laptopfarm

04.06.2025 14:48 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

www.hackthelogs.com/mainpage.html Another great resource for Detection Engineers and anyone working with SIEM's

#Cybersecurity

03.06.2025 16:48 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Cross-Site Scripting (XSS) Cheat Sheet - 2025 Edition | Web Security Academy Interactive cross-site scripting (XSS) cheat sheet for 2025, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors.

Really cool one for anyone in Appsec or red team awesome XSS cheat sheet from PortSwigger.

portswigger.net/web-security...

#Cybersecurity #Cheatsheet #Appsec

03.06.2025 16:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

hopefully they do better than the City of Columbus did during their ransomware incident last year.

28.05.2025 20:36 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Top CVE Trends & Expert Vulnerability Insights Stay ahead with the latest insights on trending vulnerabilities. Discover today's top 10 CVEs on social media. Get free and expert commentary from Intruder

cvemon.intruder.io - Great tool for any folks in Vulnerability Management. Helpful to see whats going on in CVE's.

#VulnManagement #cybersecurity

28.05.2025 20:29 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
AI Red Teamer Job Role Path | HTB Academy The AI Red Teamer Job Role Path, in collaboration with Google, trains cybersecurity professionals to assess, exploit, and secure AI systems. Covering prompt...

academy.hackthebox.com/path/preview... - Killer resource for anyone in Cybersecurity looking to level up their skills on AI security!

#AIsecurity #cybersecurity #redTeam

28.05.2025 20:28 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0