exploresecurity

950 posts

exploresecurity

exploresecurity

@exploresecurity

IT security miscellany, commentary and curiosities || the geeky alter ego of @MrJeromeSmith || thoughts are my own (who else's would they be?)

Cambridge, England 参加日 Mart 2013
215 フォロー中692 フォロワー
exploresecurity
exploresecurity@exploresecurity·
@Grazitti you might want to reword this response; bit harsh I thought 😆
exploresecurity tweet media
English
0
0
0
3
exploresecurity
exploresecurity@exploresecurity·
2 instances this week of OAuth SaaS integrations where the setup guide says "login as admin". Even with scopes, the connections are overprivileged. Getting flashbacks of software that "needs" to be installed as admin (translation: cos then it just works).
English
0
0
1
49
exploresecurity がリツイート
AmberWolf
AmberWolf@AmberWolfSec·
All I want for Christmas is U(RL handlers not vulnerable to RCE)... AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here: blog.amberwolf.com/blog/2024/dece…
English
1
9
32
3.2K
exploresecurity
exploresecurity@exploresecurity·
New @Sonos app - yuk. Key features missing. Maybe I've just not found things like how to edit the queue. Best case, unintuitive UI; worst case, something that worked (mostly - has definitely got buggier and slower recently) is undeniably worse. Trust that updates are coming...
English
0
0
0
113
exploresecurity
exploresecurity@exploresecurity·
A lot of people will be forgetting @evernote now. I only store text (more or less). I appreciate they have costs and I'd be prepared to bung them a few quid but this drastic change without warning will push many to find an alternative.
exploresecurity tweet media
Luke Rogerson@NullMode_

@exploresecurity @evernote Have to say I forgot all about evernote as a thing

English
1
0
0
246
exploresecurity
exploresecurity@exploresecurity·
Poor show @evernote - used to be able to export all notebooks at once for back-up, now it seems I have to export each notebook in turn. Why make something so important harder to do?
English
1
0
0
157
exploresecurity
exploresecurity@exploresecurity·
@AppOmniSecurity Interesting stuff but I'm unclear if the core vulnerability and analysis was done by someone else. Can't see a source credited so maybe it is original. Could you clarify?
English
0
0
0
29
AppOmni
AppOmni@AppOmniSecurity·
A widespread #Salesforce data exposure has been uncovered from misuse of the Platform Cache. In this blog by AppOmni AO Labs, read how incorrect use of this feature is causing information disclosure in over 80% of implementations handling sensitive data: hubs.la/Q01VybTP0
English
1
2
3
392
exploresecurity
exploresecurity@exploresecurity·
Calling all infosec students near #Glasgow #DC44141 - a worthy cause and potentially more than a warm glow in return
English
1
1
2
401
exploresecurity
exploresecurity@exploresecurity·
Is there really no way @JustEatUK that a lost-n-found gift card can be reactivated? I assume it's expired (website only says "invalid" and have triple-checked code). Having to tweet because your "Contact us" page does no such thing.
English
1
0
1
105