Drive-By Attack in Ollama Desktop v0.10.0
Found a bug in Ollama desktop GUI (not the core API) where malicious websites could hijack all private chats. Ollama crew patched it within hours. Make sure to update!
Tech details, video, IoCs, and PoC here: gitlab-com.gitlab.io/gl-security/se…
A lot has happened in a year! I’ve refreshed the dynamic data sources for passphrase-wordlist and generated a new file. If you’re into cracking complex passwords, this may be for you. Enjoy!
github.com/initstring/pas…
I'm not very active on here, and probably won't be on the next one either. But just in case, here's the new Mastodon profile I set up: @[email protected]
Spent some time recently formalizing our Red Team workflow at GitLab. The process is open-source, and we're sharing our issue templates to track logistics, goals, TTPs, reports, etc.
about.gitlab.com/blog/2022/05/1…
I discovered a drive-by #RCE in the @gitlab Development Kit (it's now fixed). This took chaining multiple vulnerabilities and would have allowed me to remotely compromise developer machines. Details and tips to protect yourself from similar exploits here:
about.gitlab.com/blog/2021/09/0…
Stealing Bitcoin w/ CSRF via Ride The Lightning + Umbrel. Thanks to the RTL devs for pushing a quick fix! Here's my write-up: initblog.com/2021/rtl-drive…
Thanks to the @attackndefense team at @mozilla for inviting me on their blog!
This is a more personal overview on the Firefox Android bug I disclosed recently.
Thanks to the @attackndefense team at @mozilla for inviting me on their blog!
This is a more personal overview on the Firefox Android bug I disclosed recently.
The 4/25 training session for my Breaching the Cloud Perimeter course has reached max capacity but don't worry... I'm teaching it again on 5/28 for FREE. New registration link is here: attendee.gotowebinar.com/register/43640…
The 4/25 training session for my Breaching the Cloud Perimeter course has reached max capacity but don't worry... I'm teaching it again on 5/28 for FREE. New registration link is here: attendee.gotowebinar.com/register/43640… https://t.co/7q1Qrl6DYJ
6K Followers 371 Following💼 Principal Security Engineer
💬 I tweet about Cloud Security and technical leadership
✍🏻 Subscribe to https://t.co/MR69KiF8RH
📚 https://t.co/TrQKzxfnYg is out now!
2K Followers 5K Following(upcoming) tech bro. @money23green regen. palliative umu asa. currently in the process of falling in love with the process. qui audet adipiscitur.
136 Followers 357 Followingworld-renowned axolotl furry with terrible time management.
pfp by @indorak_ banner by Timber
retired account is @SpiritAxolotl
read pinned for where to find me
469 Followers 602 FollowingCybersecurity specialist, penetration tester, red teamer and capture the flag player. Currently hacking for the highest (legal) bidder.
190K Followers 0 FollowingWe make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
6K Followers 371 Following💼 Principal Security Engineer
💬 I tweet about Cloud Security and technical leadership
✍🏻 Subscribe to https://t.co/MR69KiF8RH
📚 https://t.co/TrQKzxfnYg is out now!
32K Followers 281 Following#Bitcoin & #lightningnetwork developer & educator demanding open knowledge! Proud member of @wikimediaDE @de_Serlo & former #BTW17 Frontrunner of @piratenpartei
783K Followers 0 FollowingMy team uses this account now. Find me on https://t.co/xXqqqjq7Mt or https://t.co/DrzRPDF6ug
#Bitcoin & Open Blockchains, since 2012.
Author of 6 books.
27K Followers 0 FollowingNo longer in this cesspool. Just popped by to announce my https://t.co/ktI8HgxRAQ. Not doing DMs, not looking for likes. See you in the next book :-)
7K Followers 186 FollowingRanked as the #1 security researcher for Google Play Security Rewards Program. The founder of @OversecuredInc Android and iOS vulnerability scanners
2K Followers 3K Following💻 Get your #IoT #Pentesting and #Hacking gear from the online store.⬅️⬅️ ⚙️Hardware / Embedded assessment, SDR and more. 🌍 Now SHIPPING WORLDWIDE! #ihackiot
26K Followers 0 FollowingZerodium is the world-leading acquisition platform for premium zero-days exploits and advanced cybersecurity research. We pay BIG bounties, not bug bounties!
24K Followers 2 FollowingSSD provides the support you need to turn your experience uncovering security vulnerabilities into a highly paid career. [email protected]
48K Followers 2K FollowingSpecializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
7K Followers 2K FollowingRhino Security Labs is a top penetration testing and security assessment firm with a focus on cloud (AWS, GCP, Azure), network, and web application pentesting.
18K Followers 659 FollowingHacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH
63K Followers 337 FollowingMake a dent in the universe. Find something that needs improvement: go there and fix things. If not you, then who? {he/they}
113K Followers 521 FollowingMITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Re-tweeting ≠ endorsement. @ https://t.co/wt46ArkZVt
386K Followers 622 FollowingLove Linux/Unix, open source, and programming? Into Sysadmin & DevOps? Follow us! Boost your IT career with daily new tools, apps, and humor ⤵️