Karim El-Melhaoui
1.3K posts

Karim El-Melhaoui
@karimscloud
Principal Security Architect & Partner at https://t.co/yIU71SfS40, CloudSec Researcher. Find me at bsky
Oslo, Norway Joined Ağustos 2012
716 Following827 Followers
Karim El-Melhaoui retweeted
Karim El-Melhaoui retweeted

🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast.
Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation.
Details: wiz.io/blog/shai-hulu…
English

@gauravphoenix Nordnet’s social forum is usually good for nordic stocks: nordnet.no/aksjer/kurser/…
English

@gauravphoenix Not an investment analysis but since you mention a Norwegian company: There’s declining interest rates affecting mortgage yield of Norwegian banks, they’ve had a historically good yield. There’s also the competitive landscape with Sparebank 1 SMN which is strong in the region
English
Karim El-Melhaoui retweeted

The schedule for fwd:cloudsec Europe is out, with a single track of high-quality talks over 2 days, along with “Birds of a Feather” interactive sessions!
fwdcloudsec.org/conference/eur…
Some sponsorship opportunities are still available
English

Great work by the @SpecterOps team adding Entra ID to GitHub attack paths! Will officially archive once I can validate it supports OIDC github.com/O3-Cyber/oidc-…
English

I’m left wondering how many unpaid AWS bills are related to this.
Department of Government Efficiency@DOGE
Credit Card Update! After 14 weeks, the program to audit unused/unneeded credit cards has expanded to 55 agencies resulting in ~610k de-activated cards. As a reminder, at the start of the audit, there were ~4.6M active cards/accounts; more work to do!
English

Folks coming to fwd:cloudsec, my face looks different. I have a beard. Come find me and let's chat about the new CTF I put together. lnkd.in/geRrC3aN

English


Reminder that the fwd:cloudsec Europe 2025 Call for Papers is open!
First time speakers who requested feedback by May 30th and meet the submission criteria will receive feedback on how to improve during the second round.
For more: fwdcloudsec.org/conference/eur…
English

@DrAzureAD fwdcloudsec.org ?
CFP opens soon. European conference would be 15-16.9. in Berlin
English
Karim El-Melhaoui retweeted

🏃♂️Meet ImageRunner: A privilege escalation vulnerability I discovered in GCP Cloud Run.
Thank you for the @GoogleVRP team for working closely with us on this one.
*Stay tuned for more blogs to come!
tenable.com/blog/imagerunn…
English

@CraigHRowland Interested in reading your research, where may I find it?
English

Tor and many other VPNs are not anonymous. About 10 years back I did anti-fraud research that caused ~50% of all mobile Tor browsers to leak their real IP addresses. I never used it since. Tor is also the most surveilled network on the planet. It's anti-anonymous.
Nicolas Krassas@Dinosn
Novel technique can unmask up to 70% of crooks hiding behind VPNs, proxies, Tor scworld.com/feature/novel-…
English

Super happy to re-join the amazing folks at @TrustedSec today! Thanks for welcoming me back home with open arms 🥰
GIF
English
Karim El-Melhaoui retweeted

📖 CloudSecList Issue 276 just got released, w/ content from @HuntressLabs @elasticseclabs @O3CYBER @InvictusIRand more!
cloudseclist.com/issues/issue-2…
English

@cnotin Yes! Unfortunately not recorded 🥲 but send me an email on Karim at o3c dot no and I’m happy to share the slide deck
English

@karimscloud Oh nice! Did you present this at HackCon? Could I get a look somewhere since I missed it?
English

Last week, we presented our latest research into Azure and OIDC where we also released our latest tool for mapping attack paths between Azure and GitHub
o3c.no/knowledge/tool…
English









