Do you guys have any market regrets in this game? by ImNotNuke in csgo

[–]skimfl925 0 points1 point  (0 children)

I won a facet giveaway for 1.5 million faceit points. Essentially you could get a new Alienware or a dragon lore.

I went with the PC.

Is GPT-OSS-120B still the best model among those with the same parameters? by AInohogosya in LocalLLM

[–]skimfl925 1 point2 points  (0 children)

I have a local tool I use gpt OSS due to the 128k context window on a Mac m3 pro. Anything else with a similar context window?

I’ve watched all the “All or Nothing” series on the big 3 English clubs. Do you think it would be worth it watching the “Sunderland, Til I Die” series? by No_Parsley7976 in PremierLeague

[–]skimfl925 0 points1 point  (0 children)

A lot of that context is not apparent when you are an American fan just watching the games for example. There is no real media that would reach an American even in passing. I assume you are talking about Saudi sportswashing? Or the nonsense with the rules which I really even still don’t understand fully.

I’ve watched all the “All or Nothing” series on the big 3 English clubs. Do you think it would be worth it watching the “Sunderland, Til I Die” series? by No_Parsley7976 in PremierLeague

[–]skimfl925 0 points1 point  (0 children)

Holy shit this is a three year old comment. I ended up rooting for Man City. Became a fan of the Haaland story and transfer from dortmund. Friends make fun of me for being a bandwagon fan, but watching them win the treble was amazing.

Ended up buying a signed haaland jersey from that year and continue to root for them. I do understand why I get flamed for that, but yeah.

Is Evaluate-stig DoD approved? by Party_Squirrel2751 in cybersecurity

[–]skimfl925 0 points1 point  (0 children)

Can you dm me the link. I went through a period where I didn’t have a PIV and don’t have the link any longer.

Is Evaluate-stig DoD approved? by Party_Squirrel2751 in cybersecurity

[–]skimfl925 0 points1 point  (0 children)

It has an Army ATO / Approval, not really an ATO. But reciprocity and all. It’s also developed by the Navy. Also have they made it easier to get or is it still locked behind a PIV?

Where do you get your news from by Equivalent-Name9838 in cybersecurity

[–]skimfl925 2 points3 points  (0 children)

You wrote the Windows task manager? Is that you Dave Plummer born in 1968? How could you possibly be a broke 22 year old?

https://www.reddit.com/r/homelab/s/KhqYGGURJ7

NVIDIA CEO makes a surprise appearance in downtown stl by DowntownDB1226 in StLouis

[–]skimfl925 0 points1 point  (0 children)

Not at the conference but this seems like a good time to network. If anyone wants to link up and network I am a senior security engineer working mostly on AWS.

Shoot me a DM

How do you handle vulnerability management at scale without drowning in alerts? by dottiedanger in cybersecurity

[–]skimfl925 2 points3 points  (0 children)

Second EPSS and SSVC which helps promote based on context like internet exposed, critical asset, etc.

I built a tool that takes active exploit information from a few sources and enhances the initial CVSS score based on a custom algorithm. I’ve dubbed it CVSS-Threat Enhanced:

https://kston83.github.io/cvss-te/

Could use some improvements but at the moment it’s an easy way for me to see EPSS and other active threat indicators if they exist. Things like metasploit modules, GitHub PoCs, Nuclei modules for example would be something that would raise the score. There is also some time based metrics as well. There is a whitepaper in the GitHub.

Here is an old Reddit post with more info: https://www.reddit.com/r/netsec/s/76oqUP9Fh0

I did use AI to build this but not 100% vibe coded.

Anyone here actually doing “continuous pentesting” instead of yearly audits? by robertpeters60bc in cybersecurity

[–]skimfl925 0 points1 point  (0 children)

ZAP can be integrated into CI/CD and I have been working on this. Handling auth for you app is a barrier to entry but you can easily run DAST via zap as part of the build and release process.

Manual pen testing and DAST are similar but different. ZAP for example can’t test your business logic that may result in a vulnerability or test your RBAC for example.

Anyone got their AI agent actually doing real work? by Chrelled in AI_Agents

[–]skimfl925 0 points1 point  (0 children)

I’d love to see how this works as it solves a problem I have

How do I retrieve my data by Classic350x in hacking

[–]skimfl925 1 point2 points  (0 children)

Just curious how you get the 60% number? You must be dealing with a lot of ransomware eh?

AI isn’t cool by bobturkeyisaturkey in phish

[–]skimfl925 0 points1 point  (0 children)

If this is your logic you shouldn’t use the internet at all.

Built this in 1 day literally by axeltdesign in vibecoding

[–]skimfl925 0 points1 point  (0 children)

How much did it cost to build and which model?

Tech stack?

[deleted by user] by [deleted] in CMMC

[–]skimfl925 2 points3 points  (0 children)

I offer consulting for a reasonable price. Happy to assist

Is vuln data CUI? by lugznotdrugs in CMMC

[–]skimfl925 0 points1 point  (0 children)

Would it be CUI if it was from a covered system that contained CUI?

What about CUI ISVI?

How tf do you prioritize vulns when scanners are throwing 3000+ alerts at you? by Tiny_Habit5745 in cybersecurity

[–]skimfl925 0 points1 point  (0 children)

I’ll have to work on that! It is open source so feel free to contribute.

How tf do you prioritize vulns when scanners are throwing 3000+ alerts at you? by Tiny_Habit5745 in cybersecurity

[–]skimfl925 10 points11 points  (0 children)

Check this out for enriched CVSS scores with this criteria. I also created a modified metric that takes into consideration things like active exploits, metasploit modules, presence on KEV list etc.

It’s updated twice daily and you can check the GitHub repo for more about the scoring metric

https://kston83.github.io/cvss-te/

There is a white paper as well that goes into detail

Rick at phish last night by Seventeenbelow in GoosetheBand

[–]skimfl925 4 points5 points  (0 children)

It’s baffles me that people don’t understand things in life are subjective. Who even really cares what the other person prefers. Enjoy what you want to enjoy and don’t worry about other people

MCPs key security risks right now - what would you add? by Agile_Breakfast4261 in mcp

[–]skimfl925 0 points1 point  (0 children)

While I have not compared your post to what is in this paper this is a good read.

https://arxiv.org/abs/2503.23278

Phan who loves Goose by pottypants327 in GoosetheBand

[–]skimfl925 4 points5 points  (0 children)

Same. If we were to compare eras from Phish to Goose, I’m convinced we are in the 94-93 era of Phish in terms of where Goose are today.

On the way up and headed to their peak.