PacSec jp Profile
PacSec jp

@PacSecjp

Followers
2K
Following
0
Statuses
2K

PacSec is a cutting edge international security conference held in Tokyo as a series with CanSecWest, EU-SecWest & BA-Con.

Tokyo
Joined August 2009
Don't wanna be here? Send us removal request.
@PacSecjp
PacSec jp
9 months
RT @dragosr: It seemed appropriate for a talk on LLMs to generate my slides and images live during the presentation using a conversation wi…
0
8
0
@PacSecjp
PacSec jp
9 months
RT @dragosr: What I'm going to be talking about in Copenhagen at the Honeynet Annual Workshop are some key security challenges associated w…
0
1
0
@PacSecjp
PacSec jp
9 months
RT @0x4D31: the @ProjectHoneynet conference is happening now in copenhagen! it’s our first event since the pandemic. kicking off with @drag
0
5
0
@PacSecjp
PacSec jp
9 months
(ΦωΦ+)ホホゥ....
@dragosr
dragosr
9 months
It seemed appropriate for a talk on LLMs to generate my slides and images live during the presentation using a conversation with GPT-4o. The prompt to generate the points was about 25 pages of long form text to frame the content. It worked. :-)
0
0
0
@PacSecjp
PacSec jp
9 months
(ΦωΦ)フフフ…
@dragosr
dragosr
9 months
I just posted my list of citations from my HoneyNet Project LLM Attack and Defense talk at If you want to catch up with what is happening in LLM security research, here is a reading list of 100 research papers to summarize with your favorite LLM.
0
0
0
@PacSecjp
PacSec jp
10 months
(ΦωΦ)フフフ… check out details.
@dragosr
dragosr
10 months
We are still proceeding with our plans for the PURPLE TEST - Red Team LLM vs Blue LLM Team Competition. Delayed, but we have the contest infrastructure nearly operational, and about a dozen teams have enlisted to compete on both the blue and red side, so far, I expect more by the time we get it running smoothly. We are running the first test sessions on-line. More news will be posted as available.
0
2
0
@PacSecjp
PacSec jp
10 months
(ΦωΦ)フフフ… at Briefings day on 27May2024, Copenhagen Denmark.
@dragosr
dragosr
10 months
I'm going to be giving a presentation on Red-Teaming LLMs at the Honeynet Project annual workshop conference in Denmark on May 27-29. Hope to see you there with all the other folks comparing notes about threats.
0
1
0
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference Day2 starting, many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) get on LLM Purple Test!
@dragosr
dragosr
1 year
CanSecWest 2024 Presentation: Electric Vehicle Chargers: Observations from Pwn2Own Automotive 2024 by Jonathan Andersson, Trend Micro Research Labs (And a reminder that we are giving a 20% discount to automotive industry participants. Contact: info@secwest.net)
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ get on LLM Purple Test at #CanSecWest 2024 conference Day2 starting, many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc)
@dragosr
dragosr
1 year
Awesome! The folks at Google have joined our CanSecWest 2024 LLM Purple Test competition, and our prize pool is now up to $10K for defenders and attackers, thanks to sponsors from IOActive, Microsoft, Trend Micro, and Absolute. Pilot run on-line soon.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
∠( ˙-˙ )/ #CanSecWest 2024 is on. get on to LLM Purple Test competition! conference starting today, many AI/ML & EV security talks in 2024 agenda
@dragosr
dragosr
1 year
Awesome! The folks at Google have joined our CanSecWest 2024 LLM Purple Test competition, and our prize pool is now up to $10K for defenders and attackers, thanks to sponsors from IOActive, Microsoft, Trend Micro, and Absolute. Pilot run on-line soon.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on!
@dragosr
dragosr
1 year
CanSecWest 2024 Presentation: The Cat is Out of the Bag: Regulating AI in Canada Anna Manley - Manley Law Inc. / ACTI The Artificial Intelligence and Data Act (Bill C-27) is in the first reading stage in Parliament. The legislation purports to regulate AI as part of sweeping reforms related to technology in Canada. Will this regulation change the application of AI to cybersecurity? Are there loopholes? Is it too early for regulation? Will regulation go too far or not far enough? How we attempt to regulate AI tells us much about how we view emerging technologies from both philosophical and practical perspectives. She’ll review the legal landscape of AI in Canada and discuss our attempts to regulate emerging technologies in the broader social and political context of who we are and where we’re going.
Tweet media one
0
0
1
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) get on LLM Purple Test!
@dragosr
dragosr
1 year
Awesome! The folks at Google have joined our CanSecWest 2024 LLM Purple Test competition, and our prize pool is now up to $10K for defenders and attackers, thanks to sponsors from IOActive, Microsoft, Trend Micro, and Absolute. Pilot run on-line soon.
Tweet media one
1
0
1
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on!
@dragosr
dragosr
1 year
CanSecWest 2024 Presentation: Electric Vehicle Chargers: Observations from Pwn2Own Automotive 2024 by Jonathan Andersson, Trend Micro Research Labs (And a reminder that we are giving a 20% discount to automotive industry participants. Contact: info@secwest.net)
Tweet media one
1
0
0
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on!
@dragosr
dragosr
1 year
Apropos of Automotive Security. Ironically, it's one of the focus areas of our presentations this year at CanSecWest. CanSecWest 2024 Presentation: Death By A Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains Linfeng Xiao The intersection of new energy vehicles, intelligent networking, and traditional automotive manufacturing has significantly blurred the lines between cybersecurity and physical security. As vehicles become increasingly connected, the paradigm of threats has shifted from physical attacks, such as those on car keys, to sophisticated cyber attacks originating from the internet. This change raises a critical question: are modern vehicles equipped to fend off such cyber threats effectively? Our research aims to demonstrate the feasibility of remotely compromising a new energy vehicle without any physical interaction. With over 11 million new energy vehicles produced and sold globally, we embarked on a black box security analysis across various models. This journey took us from an initial lack of debugging access to successfully creating exploit chains that leverage multiple vulnerabilities for vehicle theft. Our methodology highlights the intricate process of identifying and chaining together remote code execution (RCE) and privilege escalation vulnerabilities to gain unauthorized control over the vehicle. We delve into the technical specifics of discovering multiple RCE and privilege escalation vulnerabilities across different vehicle models and how these can be exploited via in-vehicle communication technologies. Our findings illustrate the potential for post-exploitation manipulation of critical vehicle components, including doors and windows, and even circumventing the Passive Entry Passive Start (PEPS) system. By expanding the attack surface for contactless assaults, we emphasize the broad implications of RCE vulnerabilities. The presentation concludes with an analysis of the current state of new energy vehicle security, offering targeted recommendations to automakers for enhancing their vehicles' resilience against cyber threats.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
(*•̀ᴗ•́*)و ̑̑ #CanSecWest 2024 conference open today, Badge counters open 10am, sessions start noon. many AI/ML & EV security talks in Agenda (speaker/timeslot may change due to VISA issuance etc) LLM Purple Test is also on!
@dragosr
dragosr
1 year
CanSecWest, 25th year. Take your chances @ RandomNewCon, or experience Vancouver's diversity, get pampered, fed well, by our experienced team (still only con with Second Breakfast), see leading edge research in our single track, and a 30m taxi to Grouse for day/night skiing or a short excursion before or after for North America's best skiing at Whistler. Your pick.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
RT @PacSecjp: ∠( ˙-˙ )/ #CanSecWest 2024 is on. sign up to LLM Purple Test competition! conference open Mar 20, man…
0
1
0
@PacSecjp
PacSec jp
11 months
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda last minutes to register > sign up to LLM Purple Test competition!
@dragosr
dragosr
1 year
CanSecWest 2024 Presentation: The Cat is Out of the Bag: Regulating AI in Canada Anna Manley - Manley Law Inc. / ACTI The Artificial Intelligence and Data Act (Bill C-27) is in the first reading stage in Parliament. The legislation purports to regulate AI as part of sweeping reforms related to technology in Canada. Will this regulation change the application of AI to cybersecurity? Are there loopholes? Is it too early for regulation? Will regulation go too far or not far enough? How we attempt to regulate AI tells us much about how we view emerging technologies from both philosophical and practical perspectives. She’ll review the legal landscape of AI in Canada and discuss our attempts to regulate emerging technologies in the broader social and political context of who we are and where we’re going.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda last minutes to register >>> sign up to LLM Purple Test competition!
@dragosr
dragosr
1 year
CanSecWest 2024 Presentation: Electric Vehicle Chargers: Observations from Pwn2Own Automotive 2024 by Jonathan Andersson, Trend Micro Research Labs (And a reminder that we are giving a 20% discount to automotive industry participants. Contact: info@secwest.net)
Tweet media one
0
0
2
@PacSecjp
PacSec jp
11 months
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda last minutes to register > sign up to LLM Purple Test competition!
@dragosr
dragosr
1 year
Apropos of Automotive Security. Ironically, it's one of the focus areas of our presentations this year at CanSecWest. CanSecWest 2024 Presentation: Death By A Thousand Cuts: Compromising Automotive Systems via Vulnerability Chains Linfeng Xiao The intersection of new energy vehicles, intelligent networking, and traditional automotive manufacturing has significantly blurred the lines between cybersecurity and physical security. As vehicles become increasingly connected, the paradigm of threats has shifted from physical attacks, such as those on car keys, to sophisticated cyber attacks originating from the internet. This change raises a critical question: are modern vehicles equipped to fend off such cyber threats effectively? Our research aims to demonstrate the feasibility of remotely compromising a new energy vehicle without any physical interaction. With over 11 million new energy vehicles produced and sold globally, we embarked on a black box security analysis across various models. This journey took us from an initial lack of debugging access to successfully creating exploit chains that leverage multiple vulnerabilities for vehicle theft. Our methodology highlights the intricate process of identifying and chaining together remote code execution (RCE) and privilege escalation vulnerabilities to gain unauthorized control over the vehicle. We delve into the technical specifics of discovering multiple RCE and privilege escalation vulnerabilities across different vehicle models and how these can be exploited via in-vehicle communication technologies. Our findings illustrate the potential for post-exploitation manipulation of critical vehicle components, including doors and windows, and even circumventing the Passive Entry Passive Start (PEPS) system. By expanding the attack surface for contactless assaults, we emphasize the broad implications of RCE vulnerabilities. The presentation concludes with an analysis of the current state of new energy vehicle security, offering targeted recommendations to automakers for enhancing their vehicles' resilience against cyber threats.
Tweet media one
0
0
0
@PacSecjp
PacSec jp
11 months
(。•̀ᴗ-)و ̑̑✧ arrived YVR? #CanSecWest 2024 conference open tomorrow Mar 20, many AI/ML & EV security talks in 2024 agenda last minutes to register >> sign up to LLM Purple Test competition!
@dragosr
dragosr
11 months
So attendees to CanSecWest this week may see some unusual sights around town, as they are currently shooting Tron 3 here. They were racing light-cycles IRL a few nights ago, and the Bentall center was transformed into ENCOM...
0
0
0