At @assetnote, we found impactful vulnerabilities in static site generators and associated platforms (Netlify, GatsbyJS Cloud). You can read about our findings here: blog.assetnote.io/2022/10/28/exp… working with @samwcyo on this, has also been a pleasure.
Slides from the talk "An attacker’s guide to AWS Access Keys" that I have delivered a while ago.
Covers various techniques, tools using which attackers can gain access to #AWS Access Keys (Security Creds)
#AppSec#CloudSecspeakerdeck.com/0xbharath/an-a…
We at @PhonePe (Appsec team) are hiring Security Engineers (App-Mobile-Cloud-sec/DevSecOps/Payments)
I can share the job description but it doesn't do justice in explaining the opportunity so reach out to me if you are interested to know more!
#infosec#appsec#cloudsecurity
Our bug bounty program is 10 yrs old now, rewarded nearly 30M dollars for over 2000 researchers, launching new program at bughunters.google.com. Thanks for all your contributions and happy bug hunting!
security.googleblog.com/2021/07/a-new-…
Added a new blog post on how I developed a proof of concept exploit for the Jira DC RCE (CVE-2020-36239), including what I did wrong along the way :)
dozer.nz/posts/CVE-2020…
Linux LPE exploit for CVE-2021-3490: Tested on Ubuntu 20.10 (Groovy Gorilla) kernels 5.8.0-25.26 through 5.8.0-52.58. and Ubuntu 21.04 (Hirsute Hippo) 5.11.0-16.17.
github.com/chompie1337/Li…
Blog's up!
"Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties"
#GoogleVRP writeup included that relays how business rep & every user of Hangouts,Google Play Music, YouTube Go etc were affected!
abss.me/posts/fcm-take…#bugbounty#infosec
4 Followers 173 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/kSpmRipJEb
137 Followers 971 FollowingApplication Security Engineer , Infosec Enthusiast, Learner I love programming but I am not a coder. Economics / Bioinformatics stud!
2K Followers 1K FollowingEngineering | Reading | Cycling | Forests
Not here mostly as I prefer my sanity. Find me at:
https://t.co/vIiTEVbYGS
https://t.co/eoQjBeKcX7
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
324K Followers 3K FollowingThe only official HackerOne Twitter account.
A global leader in offensive security solutions. #HackForGood #togetherwehitharder
8K Followers 141 FollowingFounder of @Cuberks. Maker, hacker, security researcher. Love nature and psithurism. Tweets mostly about hacking, tech, entrepreneurship, and other geeky stuff.
48K Followers 622 FollowingThe power behind the @Synack platform is an elite team of the world's top cybersecurity researchers. Our best are honored at https://t.co/6bEAyp7HWJ
6K Followers 3K FollowingCommunity Builder. Pentester. Bug bounty Hunter. Bug bounty village @ DEFCON. https://t.co/PojmVAcqXQ
Tweets are my own and not the views of my employer.
61K Followers 804 FollowingSecurity Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
4.3M Followers 3 FollowingOpenAI’s mission is to ensure that artificial general intelligence benefits all of humanity. We’re hiring: https://t.co/dJGr6Lg202
2K Followers 1K FollowingEngineering | Reading | Cycling | Forests
Not here mostly as I prefer my sanity. Find me at:
https://t.co/vIiTEVbYGS
https://t.co/eoQjBeKcX7
8K Followers 426 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
3K Followers 5K FollowingSecurity Engineer @Hacker0x01, Co-founder of @seasides_conf conference, part time Bugbounty hunter.
Opinions are my own, not my employers.