Karim El-Melhaoui

1.3K posts

Karim El-Melhaoui

Karim El-Melhaoui

@karimscloud

Principal Security Architect & Partner at https://t.co/yIU71SfS40, CloudSec Researcher. Find me at bsky

Oslo, Norway Beigetreten Ağustos 2012
716 Folgt827 Follower
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
First P1 achieved, unfortunately a duplicate.
Karim El-Melhaoui tweet media
English
0
0
2
128
Karim El-Melhaoui retweetet
Amitai Cohen
Amitai Cohen@AmitaiCo·
Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):
Amitai Cohen tweet mediaAmitai Cohen tweet mediaAmitai Cohen tweet mediaAmitai Cohen tweet media
English
1
9
24
2.4K
Karim El-Melhaoui retweetet
Wiz
Wiz@wiz_io·
🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: wiz.io/blog/shai-hulu…
English
4
46
91
82.8K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
@gauravphoenix Not an investment analysis but since you mention a Norwegian company: There’s declining interest rates affecting mortgage yield of Norwegian banks, they’ve had a historically good yield. There’s also the competitive landscape with Sparebank 1 SMN which is strong in the region
English
1
0
1
60
Gaurav Kumar
Gaurav Kumar@gauravphoenix·
Melhus Sparebank ($MELG.OL) small Norwegian bank trades below book value. Yields 8%. Has paid dividends for the last 25 years (gone through GFC etc). low ROE but looks well capitalized. need to study this. anyone looked into it?
English
2
0
1
221
Karim El-Melhaoui retweetet
fwd:cloudsec
fwd:cloudsec@fwdcloudsec·
The schedule for fwd:cloudsec Europe is out, with a single track of high-quality talks over 2 days, along with “Birds of a Feather” interactive sessions! fwdcloudsec.org/conference/eur… Some sponsorship opportunities are still available
English
0
3
14
1.5K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
Another year in the books as a Microsoft MVP🎉
English
0
0
2
122
Scott Piper
Scott Piper@0xdabbad00·
Folks coming to fwd:cloudsec, my face looks different. I have a beard. Come find me and let's chat about the new CTF I put together. lnkd.in/geRrC3aN
Scott Piper tweet media
English
5
2
37
2.4K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
Reminder that the fwd:cloudsec Europe 2025 Call for Papers is open! First time speakers who requested feedback by May 30th and meet the submission criteria will receive feedback on how to improve during the second round. For more: fwdcloudsec.org/conference/eur…
English
0
6
11
1.4K
Dr. Nestori Syynimaa
Dr. Nestori Syynimaa@DrAzureAD·
Due to recent events, I decided not to give any talks in the US until further notice. If you know any non-US conferences that has a CFP open, please let me know!
English
21
6
152
17.4K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
What happens if a lambda that puts an event to an S3 triggers on the same S3… I can’t afford to find out
English
1
0
0
188
Karim El-Melhaoui retweetet
Liv Matan
Liv Matan@terminatorLM·
🏃‍♂️Meet ImageRunner: A privilege escalation vulnerability I discovered in GCP Cloud Run. Thank you for the @GoogleVRP team for working closely with us on this one. *Stay tuned for more blogs to come! tenable.com/blog/imagerunn…
English
0
4
23
1K
Melvin langvik
Melvin langvik@Flangvik·
Super happy to re-join the amazing folks at @TrustedSec today! Thanks for welcoming me back home with open arms 🥰
GIF
English
18
6
135
7.6K
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
@cnotin Yes! Unfortunately not recorded 🥲 but send me an email on Karim at o3c dot no and I’m happy to share the slide deck
English
1
0
0
40
Clément Notin
Clément Notin@cnotin·
@karimscloud Oh nice! Did you present this at HackCon? Could I get a look somewhere since I missed it?
English
1
0
0
122
Karim El-Melhaoui
Karim El-Melhaoui@karimscloud·
Last week, we presented our latest research into Azure and OIDC where we also released our latest tool for mapping attack paths between Azure and GitHub o3c.no/knowledge/tool…
English
2
0
3
349