Security Fail @TheSecurityFail
Whenever security fails you ... security.fail ::/0 Joined August 2014-
Tweets8K
-
Followers270
-
Following147
-
Likes6K
Unsafe memory handling can lead to a whole host of bugs...and security vulnerabilities! While good CI/CD can mitigate some of that, it isn't fireproof. It may be time to think about adopting a memory safe programming language. dev.to/owasp/memory-s… #developers #memorysafety
A nice polyglot entry at Revision, with complete source: Shell DOS C64 GBA GBC SNES GC NDS ZIP PDF... pouet.net/prod.php?which…
A suicide drone attacking a suicide drones factory 🔥
A suicide drone attacking a suicide drones factory 🔥
Don’t worry everyone. There’s only one backdoor and we found it, so everything’s totally ok now.
Backdoor in upstream xz/liblzma leading to ssh server compromise openwall.com/lists/oss-secu…
Get into the habit of denying meetings it’s a meeting request not a meeting mandate.
I've been reverse engineering the xz backdoor this weekend and have documented the payload format and written a proof-of-concept exploit for the RCE. The payloads are signed with an ED448 key, so I patched my own key into the backdoor for testing. :-) github.com/amlweems/xzbot
Reverse engineering by @amlweems reveals 3 flaws that allows attackers to use the backdoor without the private key, using only a captured message signed for the target host: 1. Lack of replay protection 2. Symmetric encryption with a hardcoded key, 3. Partially signed commands
Reverse engineering by @amlweems reveals 3 flaws that allows attackers to use the backdoor without the private key, using only a captured message signed for the target host: 1. Lack of replay protection 2. Symmetric encryption with a hardcoded key, 3. Partially signed commands https://t.co/oC36WlNlAw
So, the @RIGOL_Tech DP832 had the issue that when you turn it on it had a significant voltage spike (with enough power to drive a motor). Unfortunately it looks like this was not fixed on the DP932, the successor of the DP832 😐
So, the @RIGOL_Tech DP832 had the issue that when you turn it on it had a significant voltage spike (with enough power to drive a motor). Unfortunately it looks like this was not fixed on the DP932, the successor of the DP832 😐 https://t.co/oGBJAizRjN

Shuo Ding @shuo_ding1984
50 Followers 479 Following
Deine Mudder @3v1l15k
462 Followers 589 Following Satireaccount Wer mich auf schwachsinnige Listen packt wird umgehend blockiert und gemeldet!
Ali Tamoor @bealitamoor
453 Followers 1K Following Code by day, Zalmi by night! This Android dev geeks out over Babar Azam's drives & bleeds maroon & gold. Let's talk tech & the beautiful game! #PeshawarZalmi
Kimani Kevin @kevinkimani
1K Followers 7K Following Life is short, love, laugh and enjoy the little things in life......:D
CupcakeKing @CupcakeKin66990
0 Followers 19 Following Big Boi energy. Demolishing them pretty little cupcakes 🧁
Tom Gries (TOMO) @_TomGries_
59 Followers 211 Following Wirtschaftsinformatiker | seit 1992 im Internet | Trainer/Dozent für Internet Technologien und Cyber Security | mag Mathematik | @[email protected]
mikelmore @mikelmore1
5 Followers 333 Following
Christian Kahlo @ckahlo
1K Followers 705 Following Grausamer als die Nacht, heller als der Tag. #Genervt IT-Security 1998+ https://t.co/ZN9O0x2GDT #eID #FIDELIO #FIDO(2), ISACA, (ISC)² CISSP @PersoApp @cbase @VSDI_eV
Thomas Fauser @truststory_net
5 Followers 241 Following
Frank Agerholm @FrankAgerholm
51 Followers 172 Following Jugendwart im Sportverband Flensburg, Lauftrainer, Übungsleiter und OpenSource-Junky, @[email protected]
B2B Cyber Security.de @B2bCyber
2K Followers 4K Following IT-Storys, News, Meldungen, immer aktuell - IT stories, news, reports, always up to date Alle Meldungen in Deutsch und / and all news in English
Martin Rublik @martin_rublik
104 Followers 321 Following Entra ID, Identity, Cryptography and Computer Security enthusiast.
Trevor Golden @trevorgolden
909 Followers 4K Following Work: IT. Net-zero now. No timely, secure & just net-zero without nuclear.
𒀭𒉋𒂵𒈩 @gilgamehsh
13 Followers 1K Following
joey @frombeyondthere
13 Followers 1K Following
Sal 🐉 @_saal__
39 Followers 580 Following
Edwin @EdwinBarczyski
6 Followers 361 Following
Ward_V @Ward_V_
0 Followers 214 Following
Han Seoul-Oh @laughinghan
428 Followers 3K Following Let’s build tools to augment the mind, not consume it. Creator of @MathQuill. Now working on some programming language and structured editor ideas.
Hannes Kuehnemund @hakuehnemund
201 Followers 96 Following Director PAM Operations @SAP. Views expressed are mine.
nackeur @nackeur
56 Followers 4K Following
Kloudle - Cloud Secur... @Kloudleinc
655 Followers 173 Following Find & Fix 350+ Security Issues In Your Cloud using Kloudle Scanner. By @makash & @riyazwalikar
yk user 🇪🇺 @yk_user
33 Followers 572 Following An.Alphabet || still fixing stuff || course set for home, the long way round
Chief Cynicism Office... @Duncrow
752 Followers 421 Following Ottakringer, Abenteurer, Philosoph, Schatzsucher, Koch, Rotweintrinker, Zyniker, Experte für nutzloses Wissen aller Art und irgendwas mit Security.
Ma Ki @Mar_Kirch
22 Followers 163 Following
schelter87 @schelter87
152 Followers 630 Following @[email protected] #1of8 Dampfer, Podcasthöhrer, Computerkram, Irgendwas mit Gitarre und auch anderen Kram... :-) C3event: 5133 EPVPN: 5388
Lucas @ll62438859
277 Followers 2K Following
Mike @itsnotbroken
32 Followers 359 Following
Matthew Hardeman @mdhardeman
1K Followers 1K Following Software developer. Sysadmin. Into: interconnection, telephony, net engineering, comm. infra., security, snark, birds. 🦝 Also @[email protected]
Ginger Thomas @GingerT30084888
19 Followers 133 Following Christian first, conservative, love my husband and my Family.
Wazery @ialwazery
1K Followers 2K Following DevOps Engineer @ebay, @ubuntu official member, OSS contributor @KDE, opinions are my own.
User Local (@7usr7loc... @7usr7local
39 Followers 284 Following Chaot, Ideenquelle, Selbstdenker // Albern bis trocken // Analog native, early digital immigrant // Bin aus Spaß hier // RTs erfolgen ohne Ansicht der Person
SkyNet Tools @SkyNetTools
7K Followers 5K Following Providing the Latest #Infosec #News, #Tools, and #Exploits #BugBounty
Ambarish Malpani @AmbarishMalpani
1 Followers 16 Following
@[email protected] @FlorianJW
61 Followers 104 Following Moved to Mastodon, and disrespect anyone who still actively uses this shit-side.
Mike Sullivan @Free_in_Florida
30 Followers 138 Following
linuzifer @Linuzifer
52K Followers 3K Following @[email protected] https://t.co/EFBsT1HXsW https://t.co/Dl6yL2aVsW https://t.co/C0bofaQQC2
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
nixCraft 🐧 @nixcraft
386K Followers 622 Following Love Linux/Unix, open source, and programming? Into Sysadmin & DevOps? Follow us! Boost your IT career with daily new tools, apps, and humor ⤵️
CCC Updates @chaosupdates
209K Followers 195 Following Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung. @[email protected]
Troy Hunt @troyhunt
240K Followers 1K Following Creator of @haveibeenpwned. Microsoft Regional Director. Pluralsight author. Online security, technology and “The Cloud”. Australian.
briankrebs @briankrebs
333K Followers 2K Following Independent investigative journalist. Author of 'Spam Nation,' a NYT bestseller. Former Washington Post reporter. Mastodon: https://t.co/fTKNavlMwp
Filippo Valsorda @fil... @FiloSottile
46K Followers 1 Following Cryptogopher / Go crypto maintainer / @kateconger-knower / RC F'13, F2'17 / #BlackLivesMatter / he+him https://t.co/ZE4RtJ1xqD / https://t.co/qfth7zr00W / https://t.co/j1grpEm8uR
Matthew Garrett (@mjg... @mjg59
28K Followers 278 Following Not here. Fedi: @[email protected] Bsky: @mjg59.eicar-test-file.zip Signal: @mjg.59 Blog: https://t.co/CVivdtMBWe
Anthony Weems @amlweems
3K Followers 270 Following Cloud Vulnerability Research • The opinions stated here are my own, not those of my company.
Andres Freund (Tech) @AndresFreundTec
11K Followers 99 Following FWD: @[email protected] FWD: https://t.co/DcPdStYfus Postgres developer, working at Microsoft. For politics: @AndresFreundPol
fail0verflow @fail0verflow
52K Followers 10 Following
April King 🌀 @CubicleApril
19K Followers 342 Following Staff Security Engineer @ Dropbox, previously Mozilla, Twitter. mastodon @ [email protected]. Union Park District Council board member.
GitGuardian @GitGuardian
6K Followers 578 Following The end-to-end NHI security platform for enterprises. Powerful Secrets detection, remediation and NHI Governance . 🏆 #1 App on GitHub.
@disintegr8te @disintegr8te
310 Followers 669 Following IT Geek. Unapologetically Original. Political Enthusiast. Extrovert. @[email protected]
leo @leobloess
68 Followers 178 Following
Manawyrm @Manawyrm
3K Followers 793 Following electronics, old computers, networking, ham radio (she/her) https://t.co/lvWA9qZxcE https://t.co/WdWmfVBVDm
@[email protected]... @gertvdijk
3K Followers 4K Following IT dev/security/ops 🤓 — tweets in NL&EN — also combating disinfo here 🧹 — Qmoron/covidiot/malicious=block 🚫 — 🏳️🌈 but 🤷♂️ — @[email protected]
VPNpro @VPNpro
6K Followers 690 Following Team of anonymity, privacy & security professionals. Here to share #cybersecurity research, news & tips so you can make the right decisions for your #privacy.
isis agora lovecruft ... @isislovecruft
25K Followers 994 Following “the bay area’s only hacker”; “peter pan coded”; former quantum cosmologist. i might be a cryptographer but i'm not your cryptographer 🏳️⚧️🏴 forest dweller
@[email protected] @FlorianJW
61 Followers 104 Following Moved to Mastodon, and disrespect anyone who still actively uses this shit-side.
@[email protected]... @AG_KRITIS
7K Followers 157 Following unabhängige Arbeitsgruppe zur Verbesserung der IT-Sicherheit und Resilienz unserer kritischen Infrastrukturen (KRITIS)
@HonkHase.bsky.social... @HonkHase
21K Followers 4K Following 20yrs Sec @CCC, @GeraffelV @cbase @loadev @AG_KRITIS @CSCBonn, #AGND #hacking #Ethik #KRITIS #Cyberresilienz, working at @HiSolutions https://t.co/xm4yUZF1W5
Kryptos Logic @kryptoslogic
6K Followers 0 Following
MalwareTech @MalwareTechBlog
277K Followers 1 Following Not here anymore. Profiles: https://t.co/sFoOuGmYK2
Der Kryptochef @kryptochef
48 Followers 5 Following
Zensploitation @zensploitation
847 Followers 0 Following Zen && the Art of Popping Shell || Inspirational exploitation quotes by @yannayli, @yoavalon, friends and foes || DMs are open
Sven Uckermann @SvenUckermann
2K Followers 4K Following IT-Security guy with random LEGO and CYBER CYBER ideas #nerd #geek with a wild mix of german and english stuff. Eve online player. er/he
Michal Špaček @spazef0rze
10K Followers 325 Following In your web, securing your app. Hacker, webdev, speaker. Security @Shoptet, ex-@reporturi. HTTPS = How To Transfer Private Sh*. Also https://t.co/FaJemVWLCx, https://t.co/claenMAOrC.
OpenSSL announce @OpenSSLannounce
1K Followers 1 Following Unofficial OpenSSL announce mailing list feed. Run by @faker_ Mastodon: @[email protected]
Cisco BGPStream @bgpstream
15K Followers 2 Following BGPStream is a free resource for receiving alerts about BGP events. Brought to you by https://t.co/QXDqqysL0e
Bundesverband IT-Sich... @TeleTrusT_Info
1K Followers 0 Following Bundesverband IT-Sicherheit e.V. / IT Security Association Germany / https://t.co/g8o2NOT5Ja
x0rz @x0rz
96K Followers 420 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
BSI @BSI_Bund
49K Followers 394 Following Bundesamt für Sicherheit in der Informationstechnik | https://t.co/8Q82mhx69T | https://t.co/G4UCkM2Xdz
juraj somorovsky @jurajsomorovsky
2K Followers 299 Following Professor at Paderborn University / co-founder of @hackmanit. Used to break XML, now playing with TLS and crypto. Co-author of DROWN, EFAIL, and TLS-Attacker.
WPIA.club @WPIAssociation
38 Followers 5 Following WPIA is the World Privacy and Identity Association, incorporated in Austria
Maarten Boone 🇪�... @staatsgeheim
4K Followers 4K Following Security Researcher / Personeel van @Alice_en_Bob / Tweets are my own
toxicity @toxicity21
158 Followers 397 Following Metalhead, Hacker, Bastler, Magic Smoke Wizard. he/she/they Mastodon: https://t.co/IuYrX9ifiL
Martin Thielecke - mt... @mthie
2K Followers 464 Following CTO at https://t.co/oSPmfMfOm6. Pronounce it like /ˈɛm(p)ti/. The ® isn't a joke. Tweeting about nerd and programmer stuff. Fed: @[email protected] #INTJ
adam shostack @adamshostack
11K Followers 525 Following Done with Twitter. Don't expect responses. Threat Modeling: Designing for Security. Working to reduce bad security outcomes.
Jack Daniel is over t... @jack_daniel
59K Followers 3K Following Storyteller, wanderer, comic, historian, world’s oldest millennial. I used to do stuff, now I do other stuff. @[email protected]
Chris Wysopal @WeldPond
55K Followers 1K Following Hacker. Co-founder/CTO Veracode. Former L0pht security researcher. GenAI Auto-repair of vulns is the future @weld.bsky.social @[email protected]
Ryan Hurst @rmhrisk
6K Followers 3K Following Dropout. Father. I build things. Security, Cryptography, Engineering, Entrepreneurship. @peculiarventure + xMSFT + xGOOG ++. also on https://t.co/FaDXJfnZBm & Bluesky
Ryan Sleevi @sleevi_
6K Followers 601 Following I work on stuff on @Apple Cloud Services. Tweets are my own, not my employer’s. @kateconger-knower-knower. He/him @[email protected]
Feisty Duck @feistyduck
2K Followers 28 Following The place for TLS and PKI education. Publishers of Bulletproof TLS and PKI. Authors of Practical TLS and PKI training. Cryptography & Security Newsletter.
malc0de @malc0de
12K Followers 315 Following Owner of https://t.co/tokoVVgBZ1 an updated database of domains hosting malicious executables.
ShmooCon @shmoocon
27K Followers 22 Following ShmooCon 2025 is Jan 10-12. This account is used primarily to push information. Got questions? Email us at info @ https://t.co/4QO2tJpuhL
Eugene Kaspersky @e_kaspersky
182K Followers 7K Following CEO of @Kaspersky. 30+ years in #cybersecurity. Views are my own