Ilay Goldman

36 posts

Ilay Goldman banner
Ilay Goldman

Ilay Goldman

@GoldmanIlay

Security Engineer at Meta, Speaker at BlackHat, RSA

Israel Katılım Ağustos 2018
59 Takip Edilen66 Takipçiler
Ilay Goldman retweetledi
Shaked Klein Orbach 🇮🇱
אמ;לק: @YakirKad, @GoldmanIlay מ @AquaSecTeam עשו מחקר מרתק על סיקרטים שלא ניתנים לאיתור ע״י הסורקים הנפוצים כיום. הצוות גילה קרדנשילס לסביבות ענן, תשתיות פנימיות, פלטפורמות טלמטריות, רשתות, מצלמות ועוד, חשופים לעולם. מחקתם את הסיקרט? חושבים שזה מספיק? אולי כדאי לכם לצלול >>
עברית
2
3
28
1.9K
Ilay Goldman
Ilay Goldman@GoldmanIlay·
We also found that 26% of the apt packages' commands could be impersonated by attackers! Understand our findings, implications, and defenses for developers and users alike on our blog. (3/3) 🧵
English
0
0
0
59
Ilay Goldman
Ilay Goldman@GoldmanIlay·
In our research, we delve into how attackers can manipulate the 'command-not-found' package into suggesting their malicious snap packages. We explain how the suggestion mechanism works and the dangers of installing malicious snap packages. (2/3) 🧵
English
1
0
1
82
Ilay Goldman retweetledi
MrBeast
MrBeast@MrBeast·
I’m gonna give 10 random people that repost this and follow me $25,000 for fun (the $250,000 my X video made) I’ll pick the winners in 72 hours
English
383.8K
2.6M
1.9M
282M
Ilay Goldman
Ilay Goldman@GoldmanIlay·
In this blog, we detail our criteria for npm package deprecation and introduce Dependency-Deprecated-Checker, our new open-source tool. This tool scans your package.json file and alerts you about deprecated packages. (4/4) 🧵
English
0
0
2
33
Ilay Goldman
Ilay Goldman@GoldmanIlay·
Moreover, these developers sometimes archived the corresponding repository instead of officially deprecating the package at npm. This behavior led to a discrepancy between the official deprecation status of the package at npm, to the actual deprecation of the package. (3/4) 🧵
English
1
0
2
29
Ilay Goldman retweetledi
RSAC
RSAC@OneRSAC·
In this #RSAC 2023 presentation, speakers @YakirKad and @GoldmanIlay elaborate on the many attack vectors in the supply chain ecosystem, including integrated development environment (IDE), source code management (SCM), package managers and CI/CD. spr.ly/6014u022j
English
0
2
2
850
Ilay Goldman
Ilay Goldman@GoldmanIlay·
In our blog, we delve into Microsoft's lack of protection regarding impersonation of popular packages. Additionally, we explore how attacker's unearth hidden packages, potentially exposing secrets. These flaws were confirmed by Microsoft, but they still persist! (2/2) 🧵
English
0
0
0
27
Ilay Goldman
Ilay Goldman@GoldmanIlay·
🚨PowerShell Gallery: Security Alert- New Research🚨 The PowerShell Gallery stands as a vital registry for modules and scripts (over 9 Billion downloads). However, it is not as protected as we thought it to be. blog.aquasec.com/powerhell-acti… (1/2) 🧵
English
1
0
1
40
Ilay Goldman retweetledi
Clint Gibler
Clint Gibler@clintgibler·
⚔️ GitHub Repositories Vulnerable to RepoJacking Obtaining remote code execution on 37K GitHub repos via RepoJacking: * Exploitation Scenarios * RepoJacking Restrictions and Bypasses * Summary and Mitigations + more! By @goldmanilay and @YakirKad blog.aquasec.com/github-dataset…
GIF
English
1
5
18
1.7K