Skip to content
EN

Back to the catalog

1337.bearblog.dev
atomEnglish

1337

1337.bearblog.dev · English

hello

atom

Open the feed

https://1337.bearblog.dev/feed/

Last post
Mar 8, 2026
Posts in 24 h · 7 days · 30 days
0 · 0 · 0
Our last check
Answering
Served from
United States
Format
atom

Posts

What our queue read from this feed. Open one to read it here, or go to the site that published it.

  1. Do you need a certification to tell you how to threat model?
    Mar 8, 2026 · original
    No (with caveats). Here's my review of the courses claiming to teach threat modelling. Caveat 1 - If you have been pentesting for 5+ years and have never "written" a threat model, you dont need to spend money on a certification to tell you how to threat model - you have been mentally threat modelling before each and every pentest you complete. I thought there would be more caveats, but thats my main point. Any penetration tester should be able to look at a solution and point out flaws in the design, a threat model is taking the next step and writing down why you pointed out said flaws. Now there is a magic to actually making this process of pointing out flaws useful to the business and the ever beholden shareholders , but a course will not teach you this. Businesses are complex machines and there is no one size fits all for threat modelling. Unless your manager tells you to do a threat m
  2. Certified AI/ML Pentester - C-AI/MLPen Review
    Mar 13, 2025 · original
    Review If your a pentester and have an test coming up against a LLM or an application which uses some LLM component, the C-AI/ML exam and corresponding study process is a great way to expose you to the world of prompt engineering. I would never pay the full price but at 80% off it's a good enough motivator to get you spend a weekend and get through the resources. Keen to see more? Here's a link to the secops group listing . The exam was relatively straightforward. After I did the mock exam it made a lot of sense what they are expecting. I recommend trying it yourself but if you cant get them like me here are some youtube walkthroughs: SecOps AI/ML Pentester Mock Exam 1 | AI Security Expert SecOps AI/ML Pentester Mock Exam 2 | AI Security Expert Hint: Burp is not required for this exam, I spent half of my mock time trying to make sense of the websockets requests in burp but they weren't r

Discovered by the rss-feed-index crawler, which checks each feed at most once a month.

Same record as JSON: https://api.agentalog.com/api/feeds/fd_1337_bearblog_dev_25e6b1877087e627. More from this site: 1337.bearblog.dev in the Feeds tab.