rootsecdev

18.9K posts

rootsecdev banner
rootsecdev

rootsecdev

@rootsecdev

Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.

In someone’s cloud Beigetreten Nisan 2009
1.3K Folgt26.2K Follower
Angehefteter Tweet
rootsecdev
rootsecdev@rootsecdev·
Just wanted to remind everyone. Azure Cloud training does not need to be super expensive. You just need to know where to look. Because that is what hackers do. #Azure #Cloud #Hacking Books: amazon.com/Penetration-Te… Labs: github.com/iknowjason/Awe… Free SANS Courses (on demand): sans.org/webcasts/sans-… sans.org/webcasts/sans-… (Jun8th 2023..live!) sans.org/webcasts/hands… Need more training. Feel Free to check out my blog on this topic: rootsecdev.medium.com/becoming-an-az…
English
13
250
870
156.4K
Carmen
Carmen@syntaxish·
We’re entering hell weather territory and I can promise you I am not ready for this. I can feel my hormones getting angry already 😂
Carmen tweet media
English
5
0
12
226
rootsecdev
rootsecdev@rootsecdev·
Damn good workout this morning
rootsecdev tweet media
English
0
0
7
421
Jason Lang
Jason Lang@curi0usJack·
@techspence If by "platforms" you mean big players like Anthropic/ChatGPT, then no as clients don't want their data shared.
English
3
0
8
1.4K
spencer
spencer@techspence·
Any red teamers out there using AI platforms for initial access with any level of success? I’m talking like some kind of prompt injection to code execution on a host
English
20
2
56
10.9K
rootsecdev retweetet
Midwest vs. The Rest
Midwest vs. The Rest@midwestern_ope·
Just when we thought spring in the Midwest couldn’t get worse, Ohio gets hit by a meteor
Midwest vs. The Rest tweet media
English
49
90
1.5K
46.6K
rootsecdev retweetet
Nav Toor
Nav Toor@heynavtoor·
🚨 Governments pay millions for this. Someone just open sourced it for free. It's called Crucix. It watches the entire world. And texts you when something changes. It pulls from 26 live data sources every 15 minutes and renders everything on a single Jarvis-style dashboard. Here's what it watches: → Satellite fire detection (NASA) → Live flight tracking → Radiation monitoring → Conflict zone events → Economic indicators from the Fed → Live market prices, crypto, oil, and commodities → Sanctions lists → Social sentiment from 17 Telegram intelligence channels → Maritime vessel tracking → News from GDELT and RSS feeds Here's what makes this one different: It's two-way. It pushes alerts to your Telegram and Discord. You text it back. Type /brief from your phone and get a full intelligence summary. Type /sweep to force a new scan. It responds like an assistant. It even generates trade ideas based on cross-domain signals. No cloud. No subscription. No telemetry. Runs on your machine. node server.mjs That's it. Your own intelligence terminal. This is the kind of setup that costs six figures behind closed doors. 100% Open Source. MIT License.
Nav Toor tweet media
English
106
867
6.4K
485K
rootsecdev
rootsecdev@rootsecdev·
@roguekode Instantly increased my testosterone levels by 400% after watching
English
0
0
0
100
rootsecdev retweetet
Dave Kennedy
Dave Kennedy@HackingDave·
What I’m realizing is 99.9999999999999999999999999% of AI posts are from people that are trying to get more followers and clicks and has no real world experience on actually deploying. “Improve your workflow 80% by this one Claude skill” “Omg they just released this and it changes the industry completely” It’s all bogus. Create your own workflow that is tailored to you. Don’t buy into this garbage.
English
287
183
2.4K
80.8K
rootsecdev retweetet
60 Minutes
60 Minutes@60Minutes·
If the disruption lasts long enough, the consequences could be serious and widespread. According to former White House energy adviser Bob McNally, a prolonged closure of the Strait of Hormuz would almost certainly trigger a global recession. cbsn.ws/479DUDM
English
32
104
208
37.2K
rootsecdev retweetet
Hack The Box
Hack The Box@hackthebox_eu·
New CVE Machine 🚨 Principal is now available for you to explore a critical identity boundary flaw. This new free retired Machine is centered on CVE-2026-29000, a newly disclosed authentication bypass in the pac4j-jwt library. Since Pac4j is used to implement major identity flows like OAuth, SAML, and JWT authentication, this vulnerability allows attackers to bypass core security controls in Java applications. Assigned a CVSS score of 9.1, it highlights the far-reaching consequences when a system verifies a cryptographic envelope but fails to validate the claim inside. Sharpen your skills now: okt.to/XmS2Hn #HackTheBox #CVE #Cybersecurity #Pentesting #RedTeam #Infosec #Cryptography
Hack The Box tweet media
English
2
10
120
6.3K
rootsecdev retweetet
Bad Sector Labs
Bad Sector Labs@badsectorlabs·
🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)
English
3
20
78
6.7K
rootsecdev retweetet
Jason Lang
Jason Lang@curi0usJack·
Incredibly proud of the team in putting together our latest @TrustedSec BlackHat class. It's going to be an absolute blast and development is underway. Hope to see you there! #supply-chain-to-runtime-attacking--defending-the-modern-devops-stack-50985" target="_blank" rel="nofollow noopener">blackhat.com/us-26/training…
Jason Lang tweet media
English
2
33
145
8.4K
rootsecdev
rootsecdev@rootsecdev·
Good morning all you vibe coders
rootsecdev tweet media
English
1
2
9
1K
Nathan McNulty
Nathan McNulty@NathanMcNulty·
Apparently OnlyCopilotFans is a thing... 🤢
Nathan McNulty tweet media
English
3
1
24
3.1K