If you have mistakenly pushed sensitive information, revert that commit and make that info unusable.
If you just remove the info with a new commit, it stays there.
removed sensitive: github.com/search?q=remov…
removed API token OR removed API key github.com/search?q=remov…
Two years ago, secret club member @floesen_ reported a remote code execution flaw affecting all source engine games. It can be triggered through a Steam invite. This has yet to be patched, and Valve is preventing us from publicly disclosing it.
Success! @alisaesage also leveraged some ASCII art in her guest-to-host escape on #Parallels Desktop. She's off to the disclosure room to detail her work. #Pwn2Own
Success! @steventseeley was able to get code execution (and a reverse shell) on #Microsoft#Exchange. He's headed off to the disclosure Zoom to dish all the details of his exploit chain. #Pwn2Own
A successful #VMware#ESXi demo at #Pwn2Own is worth $150K. @_wmliang_ had 2 unauth RCEs in ESXi patched last week. Not only does he break down the details in his latest blog, he went further & wrote a full code execution exploit for one of the bugs. bit.ly/2OgdfiK
Looking for an unauthenticated RCE in #BIND? How about one that's been around for 15 years? An anonymous researcher submitted just that to ZDI, and @_wmliang_ has a full analysis of this now patched bug. Read the details then patch. bit.ly/2ZPIGDd
The latest sudo exploit PoC seems to be architecture independent - works on aarch64 just as well
github.com/blasty/CVE-202…
Here test against Ubuntu 20.04 aarch64
(0day) ZDI-CAN-12671: @HexKitchen details this Windows kernel NULL pointer deref originally submitted by Marcin Wiązowski that can lead to DoS, and in rare cases, local privilege escalation. Read the details at bit.ly/39qQn8v
Escalating privileges through the #Linux eBPF verifier. @_wmliang_ provides the details on triggering this neat bug originally submitted to us by @Ga_ryo_. Read all about it at bit.ly/3nXOQuJ
Just published: 5 advisories in #SolarWinds, including 2 RCE bugs fixed in CVE-2020-14005, which has been publicly linked with #SunBurst. Other bugs are privilege escalation, info disclosure, and arbitrary file creation. zerodayinitiative.com/advisories/pub…
A story on how I gained RCE against Microsoft Exchange Online using CVE-2020-16875 and bypassed their patches twice over. Latest patch bypass is unpatched against on-premise deployments!
Making Clouds Rain - Remote Code Execution in Microsoft Office 365: srcincite.io/blog/2021/01/1…
It's the 1st second Tuesday of 2021, which means the latest patches from #Adobe and #Microsoft are here. Join @dustin_childs as he breaks down this release, including a 0day being exploited in Windows Defender. Read all the details at bit.ly/2K7LQxU
You have `Less Than a Week` to nominate new web hacking techniques - please submit whatever you have found new and interesting in blogs, conferences, etc. in 2020 which are not already in the list
docs.google.com/forms/d/e/1FAI…
You have `Less Than a Week` to nominate new web hacking techniques - please submit whatever you have found new and interesting in blogs, conferences, etc. in 2020 which are not already in the list
docs.google.com/forms/d/e/1FAI…
Had a blast trying to get this as well as shellcode execution to work in Nim together with @ShitSecure and @byt3bl33d3r. Initial experiments in bypassing AV/EDR are successful, even for plain meterpreter shellcode 👀
Had a blast trying to get this as well as shellcode execution to work in Nim together with @ShitSecure and @byt3bl33d3r. Initial experiments in bypassing AV/EDR are successful, even for plain meterpreter shellcode 👀
I just wrote a blog about CVE-2020-9971. Sandbox Escape and LPE to root in macOS/iOS. It's an interesting logic bug in launchd process when managing XPC Services.
xlab.tencent.com/en/2021/01/11/…
Lots of people asking how they should move their conversations to Signal today. Here's one idea, start with your existing groups by using Signal group links.
Lots of people asking how they should move their conversations to Signal today. Here's one idea, start with your existing groups by using Signal group links.
1K Followers 4K FollowingComplete ASPM providing visibility, prioritization & remediation at scale. Standardizes developer security without slowing down the business.
1K Followers 368 FollowingWe put your organisation's #Cybersecurity efforts to the test, providing you with the cybersecurity confidence you need.
Part of Shearwater Group plc.
3K Followers 1K FollowingArguably, Saint Louis' favorite Anarchist CEO. Antifascist organizer. STL DSA. Stunt sailor. No war but Glassdoor. (he/y'all)🏴🚩✊🏿✊🏼✊🏾
719 Followers 3K FollowingiOS app developer working on @HorizonHabitApp. Director of mobile engineering @Deloitte. Previously @Redbubble, @realestate_au
@[email protected]
37K Followers 2K Following20+ yrs in Infosec. Malware Influencer. I turn Malware into Art and Music. Art @MalwareArt. 4x Pwnie Nominee. 𝕍𝕏. GameDev. Autistic.
302 Followers 90 FollowingI'm a Radar/Photonics Engineer and am a CTO in a company I founded back in 2002. Obsessive hobbies are trading resource stocks, weightlifting and music.
3K Followers 518 FollowingAdvancing the Gunnison Copper Project & restarting the Johnson Camp Mine with Nuton, a Rio Tinto venture—driving sustainable copper production in Arizona.
40K Followers 978 FollowingBy EV drivers, for EV drivers. Since 2007, we’ve been making electric mobility the easy choice with the best charging experience ⚡️
220K Followers 56 FollowingChief Macro Strategist
Contrarian Macro Advisors
52 yrs on Wall Street, first as an institutional portfolio manager, then as as a macro strategist.
7K Followers 2K FollowingFansUnite is a sports and entertainment company, focusing on services related to regulated and lawful online sports betting, casino and other related products.
458 Followers 470 FollowingStageZero Life Sciences is dedicated to the early detection of cancer & multiple diseases through whole blood. For more information https://t.co/MZKNKqqgsD
878 Followers 218 FollowingRAD is high-tech start-up that delivers AI-based solutions that empower organizations to gain new insight, solve complex challenges and fuel new business ideas.
2K Followers 252 FollowingRadioGel® is a cancer treatment developed by Vivos Inc. that utilizes proprietary Precision Radionuclide Therapy™ (PRnT™) to treat solid tumors.
716 Followers 503 FollowingSWE & sometimes security researcher, NYU MSCS, member of https://t.co/R4a4yethba and @acebearteam. PL theorist wannabe. He/him/*. Views are my own, not my employers’
1K Followers 123 FollowingReverse, exploit, pwn. My blade is angry... Want a taste?! The name's 0xMitsurugi. Don't forget it. Member of HexpressoCTF https://t.co/OYV0jRCTIQ
1K Followers 368 FollowingWe put your organisation's #Cybersecurity efforts to the test, providing you with the cybersecurity confidence you need.
Part of Shearwater Group plc.
2K Followers 86 FollowingSecurity researcher at Oracle. Speaker at Blackhat USA 2018, Successful entries at pwn2own IOT/Mobile 2021,2022,2023,2024, ICS 2022. Opinions are my own etc..