Ever feel overwhelmed by the constant firehose of newly disclosed vulnerabilities? Check out my latest blog post where I outline the methodology our Threat Enablement team at Bishop Fox uses to cut through the noise:
bfx.social/3GcLIdz
Our Threat Enablement and Analysis team built a better way to cut through the noise. This is how we triage the firehose, turning chaos into action. By Senior Operator Nate Robb: bfx.social/45Ltri1
My team is hiring at @bishopfox! Come join the Adversarial Operations team for the Cosmos continuous attack surface testing platform.
bishopfox.com/jobs?gh_jid=36…
We're looking for a Senior Back-End Software Engineer with strength in Golang. Interested? Know anyone? Please RT for reach 🙏 bishopfox.com/careers/?gh_ji…
A tale of the #security perils of using URL shorteners for sensitive info in 3 parts from @_BalthazarBratt: Read how our CAST team used shortened URLs to show a client how they could be leveraged in an #attackchain leading to full compromise. hubs.la/H0KwZwV0
While newly released #CVEs & zero days demand attention, #security teams need to focus on other easily exploitable #vulnerabilities, too. These less newsworthy issues can post a real threat to organizations. CAST Operator Nate Robb (@NateRobb) explains: hubs.la/H0CDJjK0
#Symfony's secret fragments: Learn how a configuration problem leads to Remote code Execution on Symfony-based applications : ambionics.io/blog/symfony-s…
samcurry.net/hacking-apple/ - this is one of the most comprehensive writeups I have seen from the bug bounty community, awesome work by a whole crew of people hacking on apple - lots of takeaways, worth reading thoroughly
⚡️New DNS Out-of-Band vector for MSSQL Injections in SELECT statement! Can be used for completely blind #sqli.
Use fn_trace_gettable and #Burp Collaborator👍.
#ptswarmTechniques
@tifkin_ and myself are happy to announce Seatbelt 1.1.0 ! Various fixes and 10 new modules means we've passed the 100 module mark. Full changelog at github.com/GhostPack/Seat…
Since it is Hacktoberfest, releasing a new research blog on hacking GitHub actions. I had a lot of fun writing this and researching on it and it is still not over 👀
sites.google.com/securifyinc.co…
I've designed labs so you can practice numerous HTTP Host header attacks including advanced password reset poisoning, host-header SSRF, and auth bypass! portswigger.net/web-security/h…
The #TITAN Killer! First @hashcat benchmarks on the @NVIDIAGeForce#RTX 3090! This is the fastest single GPU ever benchmarked! With an incredible 1.1MH/s WPA2, 121GH/s NTLM, and 96kH/s BCRYPT. Full benchmarks posted here(credit: blazer): gist.github.com/Chick3nman/e4f…
498 Followers 1K FollowingFormerly Infamous Computer Hacker, Currently Nobody. LDS “Think not that I have come to send peace on earth: I came not to send peace, but a sword.”
473 Followers 3K Followingco-parenting https://t.co/Jjo5xOaif0, bridging intelligence to data - building model nootropics (ex-hubspot/meta)
fascinated by intelligence, artificial or natural 😉
290 Followers 3K Followingjapes and general tomfoolery | red-teaming, hard-tech, synbio, anthropological history, linguistics, theories of life, etc | hmu at ping00 at protonmail dot com
69 Followers 42 FollowingSi disfrutas de juegos como Final Fantasy, Elden Ring, Monster Hunter, WoW, Guild Wars, Ashes of Creation y muchos más, este es tu perfil.
9 Followers 319 FollowingCyber Security student passionate about securing the digital world. Constantly learning and exploring the latest trends and technologies in the field.
8K Followers 426 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
68K Followers 586 FollowingHigh Queen of the Cybers | Educator | Content Creator | UwU-Anointed Wapp King | Ex-Brit | https://t.co/04RRExvxXj (he/him) 🇺🇸 I run gameshows at DEF CON.
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
52K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
8K Followers 426 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
2K Followers 629 FollowingI'm mnz. A security researcher, penetration tester and member of the @thegooniesctf team in Australia. No logs, no crime.
PGP: 9F7D 181D 1F4A 51B2
602K Followers 9 FollowingSelect Committee to Investigate the January 6th Attack on the United States Capitol | Representative @BennieGThompson, Chairman
187K Followers 9 FollowingStatus Updates, Latest Dev Comments, Patch Details & more, direct from the Community Team!
ESRB rating: MATURE (17+) with Blood, Strong Language, and Violence
37K Followers 125 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
36K Followers 184 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
8K Followers 16 FollowingWe're the trusted source for IP address data, handling over 40 billion API requests per month for over 500,000+ companies and developers.