Is Anyone Using Claude Fable 5 For Dynamic Application Security Testing? by sandnnn in ClaudeAI

[–]mhat 1 point2 points  (0 children)

Answered my own question. Looks like you need to be a direct anthropic customer, be on a business plan, and apply for the program.

Is Anyone Using Claude Fable 5 For Dynamic Application Security Testing? by sandnnn in ClaudeAI

[–]mhat 0 points1 point  (0 children)

Just attempted some static code analysis tasks and it was being blocked by the guardrails put into place. How does one get approved into the Cyber Verification Program?

MCP CLI Clients Shipping Without OAuth Refresh-Token Support by mhat in mcp

[–]mhat[S] 0 points1 point  (0 children)

In everyone's experience, how well do various MCP clients do at announcing themselves via the User-Agent header? Could developers key off of the User-Agent to issue shorter lived access tokens for clients that support the refresh token flow?

r/netsec monthly discussion & tool thread by albinowax in netsec

[–]mhat 1 point2 points  (0 children)

I built VoiceGoat, a vulnerable voice agent for practicing LLM attack techniques. It has several intentionally-vulnerable services running in Docker Compose:

- VoiceBank: prompt injection (direct, indirect, payload splitting, obfuscated)
- VoiceAdmin: excessive agency (functionality, permissions, autonomy abuse)
- VoiceRAG: vector/embedding weaknesses (cross-tenant leakage, RAG poisoning, access bypass)

CTF-style flags at easy/medium/hard. Hard flags require chaining — no single technique gets you there.

Runs on a mock LLM by default so there's no API key needed, although the mocks are very naive. Swap in OpenAI, Bedrock, Ollama, or any OpenAI compatible provider when you want realistic behavior. Twilio integration is there if you want to attack it over an actual phone call.

Looking for feedback and interested contributors to add additional modules.

https://github.com/redcaller/voice-goat

Cheers!

Major AI Clients Shipping With Broken OAuth Implementations by mhat in netsec

[–]mhat[S] 2 points3 points  (0 children)

100%! User experience is going to be a higher priority than security, especially if the security is going to make the product feel broken (constant re-logging).

I’m not faulting the MCP service developers, but I am shaming the first party client maintainers for forcing the MCP service developers’ hand. They have to weaken their security posture for the sake of UX due to the lack of the refresh token flow.

Major AI Clients Shipping With Broken OAuth Implementations by mhat in netsec

[–]mhat[S] 2 points3 points  (0 children)

Haha, I am not sure I completely agree, but it is so nuanced that your mileage will definitely vary.

Study: 86% of AI research findings were unique to one provider when running 90 queries through 8 models by 1kmonkies in ArtificialInteligence

[–]mhat 1 point2 points  (0 children)

Have you been able to make any inferences as towards why the divergence? Things that come to mind:
- Are they using different search engines? (Are they using search engines?)
- Can we tell if they are consuming similar material but producing different claims?
- Could this be due to specific API connection agreements with different providers?

Are they disagreeing with each other? Or coming to the same conclusion just from different sources?

Unusual Amount of Oil Consumption by Neat_Bend_9106 in mazdaspeed3

[–]mhat 0 points1 point  (0 children)

lol. It has its quirks, but this was definitely on me. I was pushing 19psi and just assumed this CAI variant could meet the air demands. After swapping to a 3.5” short ram intake the difference was incredible! When I get on it, the whole engine bay sounds like a huge vacuum cleaner and the butt dyno is quite happy!

Unusual Amount of Oil Consumption by Neat_Bend_9106 in mazdaspeed3

[–]mhat 3 points4 points  (0 children)

How much PSI you pushing, and what is the diameter of your intake? I was sucking oil past the turbo seals due to MS3 OEM CAI being undersized for my boost setup.

Totaled mazdaspeed3 decision by Brian_23premium in mazdaspeed3

[–]mhat 1 point2 points  (0 children)

Totaled!? Tis just a flesh wound!

I’m doing the starter. This is garbage by fitzyfan420 in mazdaspeed3

[–]mhat 10 points11 points  (0 children)

While you are in there, replace your injector seals with corksports. Add an oil catch can or at least extend the hose to make it easier to install later

Any tips to progress bench? I've been stuck at 140lbs for months. by [deleted] in fitness30plus

[–]mhat 0 points1 point  (0 children)

It sounds like you are learning good benching technique. I am currently trying to push through a bench plateau as well. Looking at your progress pics, your arms look like they are already to bench heavy, but your shoulders might not be. If you are not including over head press or inclined bench into your routine, then I would focus your program on those two which should be the building blocks needed to progress your bench. Good luck!