H4cker, author of How to Hack Like a Pornstar https://t.co/VvRLVM6MUB & How to Hack Like a Ghost https://t.co/DXpFnQ3rYR
https://t.co/IrQjsNwxGVsparcflow.comJoined February 2017
#BHUSA is right around the corner!
Join @jaredcatkinson and @_xpn_ for our Tradecraft Analysis course, and learn how attack techniques work under the hood and how to make the best use of available telemetry.
Register today ▶️ ghst.ly/bhusa-atta
Our Hacking Humble ebook Bundle Starts NOW! Pay what you want for up to 18 of our bestselling hacking and security titles—plus, your purchase benefits @EFF and their fight against censorship. humblebundle.com/books/hacking-…
Adding the X-Frame-Options = "DENY" won’t make a dent in your security landscape, but it sure as hell will spare you a ton of spam from wannabe bugbounty hunters.
mtls is overkill for 99% of use cases, Bearer toke auth works just as fine and is arguably better.
Cert pinning in mobile apps does not make sense anymore in 2023…i mean i could go on…
mtls is overkill for 99% of use cases, Bearer toke auth works just as fine and is arguably better.
Cert pinning in mobile apps does not make sense anymore in 2023…i mean i could go on…
So let me get this right. When it comes to Cloud, companies have a choice between: a bad Console, unfixed 0-days, non-resilient DCs, and govt-owned DCs ? Oh my, what a tough choice!
While we're at it, Zero Trust architecture is not a good enough justification to remove that VPN or expose that app naked on the Internet...
We want to stack those security layers, before potentially chopping some of them away, if the threat modelling makes sense
It's always funny to read CFPs claiming to solve Zero Trust architecture through...wait for it...network restrictions.
Page 4 of the NIST paper:"Zero trust is the term [...] that move defenses from network-based perimeters to focus on users, assets, and resources"
“Anyone can rant on a ticket. A precious few can create value. Strive to be the latter.” Brilliant book by @sparcFlow, reminds me of “The Phoenix Project”.
🔖 So you think you can block Macros?
Exploring the quirks of MS Office macro security
* Abuse patterns
* Bypasses for enterprise VBA macro settings
* Legitimately signed Office docs
* Securing an Office environment
By @ptrpieter and @DaWouw#blueteamoutflank.nl/blog/2023/04/2…
"These are important issues, but, our roadmap is full for at least six months".
Classic rebuttal to a vulnerability. The discussion then shifts into a Tetris-like game trying to fit imaginary deadlines.
I detail how to avoid this trap in my book amazon.com/dp/B0C4LC4FDW
So finally feel like I can talk about this. Santa as in github.com/google/santa now supports file access authorization. This means that we can authorize if a binary should be able to open a file/path and leverage code signing for targeting/filtering.
486 Followers 2K FollowingTech enthusiast, space aficionado, and advocate for digital freedom. Always questioning the status quo and looking towards the stars. (Auto generated by Grok)
0 Followers 2 FollowingInnovative professional with a knack for transforming ideas into reality. With expertise in technology, excels at crafting solutions that drive efficiency.
53 Followers 190 FollowingCyber Security Consultancy & the premier Cyber Essentials certification body in NW England. Delivering Cyber Essentials to SMEs in UK, Europe, & beyond
325K Followers 119 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Build the path to a secure future with OffSec.
24K Followers 1K FollowingSoftware Engineer GenAI @Youtube | Building LLM serving infra | AI | ex : @Google Search & @Microsoft Azure | 3x hackathon winner | Views my own
3.1M Followers 150 FollowingEngineer. Selecting and curating pictures and videos trying to awaken your sense of wonder. Science, tech, art, weather, space, the unusual around us.
191K Followers 1K FollowingCEO & co-founder @Lightspark ➡️ building the open Money Grid on Bitcoin + @spark. Ran Payments/Crypto & @Messenger at @Meta, led @PayPal + 3 startups.
1.1M Followers 4K FollowingLearn the system I used to gain 1M+ followers, 5.5B impressions, & $217K on 𝕏. Join 1300+ students, go viral, & start earning: https://t.co/h7wKXJpuMV
883K Followers 0 FollowingCitizen journalism with a humorous flair. Following Fintech, Crypto, AI, Longevity, Politics, Memes, and whatever the current thing is.
3K Followers 2K FollowingPowerShell MVP that is passionate about helping others succeed with Active Directory, Entra ID, Defender XDR, and Microsoft 365. Always learning! ✝️👨👩👧👦☕
5K Followers 1K FollowingDFIR @Google by day; threat intel and malware analysis by night · BlueTeam (views are my own) · he/him · @[email protected] / @tomchop.bsky.social
16K Followers 454 Following"The Kafka Guy" 🧠
Have worked on Apache Kafka for 6+ years, now I write about it. (& the general data space)
Low-frequency, highly-technical tweets. ✌️
12K Followers 880 FollowingPassionate About Cybersecurity | Sharing Passion to Help Individuals Discover, Engage, and Level Up A Cyber Career | Tweets Sharing Cyber Tips, Tools, Love💙
57K Followers 1K FollowingCommentary on investing, politics, tech, and start-ups. Not Financial Advice. Sign-up for free quarterly newsletter: https://t.co/6G64m7pEi0
1.4M Followers 1K FollowingBuilding @EurekaLabsAI. Previously Director of AI @ Tesla, founding team @ OpenAI, CS231n/PhD @ Stanford. I like to train large deep neural nets.
83K Followers 898 FollowingI’m the dentist that doesn’t agree with the other 9 | Not Medical Advice | Co-founder of Twitters favorite toothpaste @betterbiom 👇
124K Followers 1 FollowingTrue stories from the dark side of the Internet. Host @jackrhysider.
New episodes released on the first Tuesday of each month.
Discord: https://t.co/bZZRR8C59R
17K Followers 4K FollowingThe official Twitter stream for the HITBSecConf conference series held annually in Europe (Amsterdam), Asia (Bangkok), & The Middle East (Abu Dhabi)
9K Followers 485 FollowingDirector of Mainframe Consulting Services at BMC. Co-founder of https://t.co/fg9TcY84rj and Chairman of the Security Working Group at GSUK.