/* BlazingWind */

532 posts

/* BlazingWind */

/* BlazingWind */

@BlazingWindSec

Not active. Security researcher at @GHSecurityLab. Views are my own.

Katılım Eylül 2017
489 Takip Edilen284 Takipçiler
/* BlazingWind */ retweetledi
Tim Willis
Tim Willis@itswillis·
It doesn't happen very often, but Project Zero is hiring! goo.gle/41DBQBY Please share with anyone you think would be awesome for the role 🎉 Looking for at least one person. DMs open if you want to reach out about the role. The team: youtu.be/My_13FXODdU
YouTube video
YouTube
English
4
94
268
49.1K
/* BlazingWind */ retweetledi
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
🎉 Excited to announce the launch of CodeQL Community Packs for Security teams and researchers! 🚀 Supercharge your code analysis with new Query, Model, and Library packs, to find more vulnerabilities, accelerate codebases audit, and secure code effortlessly. github.blog/security/vulne…
English
1
12
39
5K
/* BlazingWind */ retweetledi
GitHub
GitHub@github·
A new free tier of GitHub Copilot in @code. ✅ 2,000 code completions per month 💬 50 chat messages per month 💫 Models like Claude 3.5 Sonnet or GPT-4o ♥️ More fun for you Check it out today! Oh yeah, and we passed 150M developers on GitHub 💅 github.blog/news-insights/…
English
107
625
2.7K
3.1M
/* BlazingWind */ retweetledi
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
🎉 You can now enable code scanning in your GitHub Actions workflow files! ✅ By opting-in to this feature, you can enhance the security of repositories using GitHub Actions. github.blog/changelog/2024…
English
0
7
18
5.6K
/* BlazingWind */ retweetledi
eul3r
eul3r@0x_dea110c8·
If you dont have time to go through a 1000 page book about compilers but you are curious about them you might follow this instead lowlevelbits.org/how-to-learn-c…
English
5
112
1.1K
57.4K
/* BlazingWind */
/* BlazingWind */@BlazingWindSec·
🚀 CodeQL zero to hero part 4: Gradio case study is out! This time we dive into how I wrote CodeQL to support the Gradio framework, scaled the research to a thousand repositories on GitHub, and found 11 vulnerabilities. gh.io/codeql-part-4
English
0
7
15
1.2K
/* BlazingWind */
/* BlazingWind */@BlazingWindSec·
I've wanted to contribute to @freeCodeCamp for a while, and now I got a chance. Happy to help secure one of the best platforms for learning programming 🤩
GitHub Security Lab@GHSecurityLab

Excited to see @blazingwindsec recognized in @freeCodeCamp's Security Hall of Fame for uncovering and reporting a security vulnerability in their demo projects. 🎉 Her work helps keep open source safer for everyone! Check it out: contribute.freecodecamp.org/security-hall-…

English
0
0
1
151
/* BlazingWind */ retweetledi
Jorian
Jorian@J0R1AN·
Aaaaand that's a wrap! Very fun to be on the organizing side of a CTF for once. In the end, Conversationalist was solved 20 times and Global Backups only had 1 solve by @havce_ctf! I've published detailed writeups/source code for both challenges below: github.com/JorianWoltjer/…
Jorian@J0R1AN

The @intigriti #1337UPLIVE CTF just started. I made two hard challenges: Crypto - Conversationalist and Web - Global Backups. Enjoy! ctf.intigriti.io

English
0
1
8
756
/* BlazingWind */ retweetledi
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
Want to learn how to secure your browser extensions? Read our latest blog post where we talk about the security model of browser extensions and how developers can keep them secure. github.blog/security/vulne…
English
1
8
27
2.2K
/* BlazingWind */ retweetledi
Ekoparty | Hacking everything
Charlas MainTrack #EKO2024 🔥 📌 @artsploit, Security Researcher at GitHub Security Lab 💡 “Breaking corporate Maven repositories”: In the Java ecosystem, companies often use in-house repository managers, such as Sonatype Nexus or JFrog Artifactory, to store artifacts and cache their dependencies locally. This helps to provide certainty and security about used dependencies, but it also brings a whole new attack surface. In this presentation, I’ll reveal some intriguing vulnerabilities and CVEs that I've recently found in popular Maven repository managers. I'll illustrate how specially crafted artifacts can be used to attack not the users, but the repository managers that distribute them. Finally, I'll demonstrate some exploits that can lead to pre-auth remote code execution and poisoning of the local artifacts. This research might be interesting to people who specialize in web, Java or supply chain security. All vulnerabilities mentioned in the outline are already patched, but some of them are not public yet. I'm going to fully disclose them on the day of the conference. A full whitepaper will be published alongside the presentation. Note: I can also make it as a lightning talk if necessary. ✅ Esta charla será dictada en inglés. 📍 13, 14 y 15 de noviembre en el CEC - Buenos Aires 🎟️ ¡Registrate gratis hasta el 31/10! >> entradas.ekoparty.org 🚀 Podés ver la agenda completa en ekoparty.org/agenda
Ekoparty | Hacking everything tweet media
English
0
4
13
2.7K
/* BlazingWind */
/* BlazingWind */@BlazingWindSec·
Which lock picking sets do folks recommend for a student hacking club that wants to do it as fun workshop for beginners? Preferably a set that comes with a few easier and medium-hard locks, or a few that are modifiable.
English
1
0
1
149
Michael Blake
Michael Blake@Michael1026H1·
@ngalongc I really like CodeQL with custom rules for things like authorization issues.
English
1
0
2
333
/* BlazingWind */
/* BlazingWind */@BlazingWindSec·
Yesterday, I had a blast presenting "Finding vulnerabilities with CodeQL" workshop OrangeCon. Thank you to the organizers for creating such a great conference @OrangeCon_nl 👏👏
English
0
2
14
759