🛠️ A serverless command & control (C2) framework
🗓️ Leverages Google Calendar APIs, as a covert communication channel between operators and a compromised system
github.com/deriv-security…
I just published MeetC2 - A serverless command & control (C2) framework that leverages Google Calendar APIs, as a communication channel.
github.com/deriv-security…#infosec#redteam
Yesterday at DEFCON 33, we participated in the Bio Hacking Village and conducted security assessment of PET/CT imaging systems. Successfully identifying three vulnerabilities, which were responsibly reported to the vendor.
#infosec#defcon33
The next update for the Offensive Phishing Operations course will be heavily focused on HTML Smuggling and will be going up against @RandomDhiraj's awesome SmuggleShield.
We'll also be demonstrating a module that combines anti-bot capabilities with HTML smuggling.
More info:…
Never trust a favicon at face value. 👀
@RandomDhiraj demonstrates how attackers can hide malicious files inside .ico icons by exploiting their dual directory structure — allowing payloads to slip past filters in a stealth move similar to HTML smuggling.
Never trust a favicon at face value. 👀
@RandomDhiraj demonstrates how attackers can hide malicious files inside .ico icons by exploiting their dual directory structure — allowing payloads to slip past filters in a stealth move similar to HTML smuggling.
Just learned a neat way of hiding file within favicon (.ico). You can manipulate the dual directory entry structure and smuggle any file type in it. Here is a quick raw script I put together for testing.(github.com/RootUp/Persona…)
#infosec#redteam
Great research here this technique leverages Rust’s capabilities to compile to WASM for HTML smuggling (lrqa.com/en/cyber-labs/…) - Next Level Smuggling with WebAssembly. However, my extension "SmuggleShield" prevents such crafted file by default.
#infosec#redteam#blueteam
Thank you @1ns0mn1h4ck I had fun delivering the talk last week, such a great audience. I talked about my research named SVG smuggling and the open-source tool "SmuggleShield". (github.com/RootUp/Smuggle…)
#infosec
42K Followers 286 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
18 Followers 390 FollowingIIT Bombay EE 2018 भारतीय
अभियंता, Network Security, Red Team, White Hat, Backend developer, Python, Lang-chain, LLM,
Bug Bounty,
DHH, Music production 🎁
3K Followers 2K FollowingMobile/IoT/Web security; Trainer & Speaker @BlackHat/DefCon/POC/OWASP/Hackfest...; Day job as Director of Security Engineering; #OSCE #OSCP #OSWE #CCISO...
11K Followers 6K FollowingAppSec Village @DEFCON & @RSAConference
A volunteer-run, non-profit focused on education, awareness, and community. Founded by @erezyalon and @tzionit411.
42K Followers 286 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
3K Followers 2K FollowingMobile/IoT/Web security; Trainer & Speaker @BlackHat/DefCon/POC/OWASP/Hackfest...; Day job as Director of Security Engineering; #OSCE #OSCP #OSWE #CCISO...
6K Followers 664 FollowingVishal Panchani security Engineer | hall of fame from Google ,paypal , brickftp and many more. keep calm and hack the planet. Top 10 in hackerone alltime
4K Followers 1K FollowingHacker, security research architect for @Microsoft Defender.
Member of @thegooniesctf. Linux, Windows, Android, MacOS, iOS, ChromeOS, bare metal.
日本語オーケーです👌
2K Followers 672 FollowingDavid H Hoyt LLC | Targeting the Full Stack: SS7, PSTN & IP since 1994 | Security Research & Quality Assurance | https://t.co/JHgCqazAwL | https://t.co/FhOaVq61pF | https://t.co/aKNaRjnysT
67K Followers 403 Following➡️Hacker - Helper - Human ⬅️ . . . Also Author. Speaker & Scientific Hooligan! A bona fide teachable moment for hire! he/him
380 Followers 631 FollowingJust another average security guy who loves to break things | Red Team @Unit42_Intel | Adversary Simulation | My opinions are my own
687 Followers 219 FollowingCurated, cutting-edge, and hands-on technical trainings, labs, and workshops delivered by some of the most seasoned cyber security practitioners in one place.
18K Followers 837 FollowingRansomware, Online Security, and Malware. Owner, Editor in Chief of @bleepincomputer.
DM on Signal: LawrenceA.11 * https://t.co/LXVRoICs8Z
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
13K Followers 2K FollowingDatabricks' CSO - Previously: Citrix's CISO, Semmle's CSO, Google's Head of Product Security, MSFT, entrepreneur. Real Madrid supporter. All opinions my own.
4K Followers 4K FollowingPrincipal Security Researcher - Tweets and opinions are my own and not of my employer. #fuzzing #trainings #security YouTube: https://t.co/grWZKdQlqr
3K Followers 587 FollowingCyber Response Italian Supercazzola Technology Officer at @mhackeroni Inc. Writing your favourite fuzz testing tools with @aflplusplus. Security researcher.