Matthew Kienow

802 posts

Matthew Kienow banner
Matthew Kienow

Matthew Kienow

@HacksForProfit

hacks for fun and profit / software engineer / security researcher PGP: 9DCD 23A2 0181 B684 C21C 0ED2 9903 D880 6069 F788

Katılım Ağustos 2014
550 Takip Edilen467 Takipçiler
Matthew Kienow retweetledi
runZero, Inc.
runZero, Inc.@runZeroInc·
Tracking unsupported edge devices just got easier! CISA’s BOD 26-02 requires agencies to identify internet-exposed EOS edge devices by May 5, 2026. Our new Findings tab surfaces them automatically. 👉 Read more from @todb & @HacksForProfit runzero.com/blog/finding-c…
runZero, Inc. tweet media
English
0
1
1
123
Matthew Kienow retweetledi
runZero, Inc.
runZero, Inc.@runZeroInc·
EOS edge devices exposed to the internet = a 'please hack me' sign on your front door. CISA agrees. And that's what BOD 26-02 is all about. In our latest blog, @todb, @HacksForProfit & Colin Dupreay break down how runZero customers can get ahead. 👉 runzero.com/blog/cisa-bod-…
runZero, Inc. tweet media
English
0
1
1
95
Sipeed
Sipeed@SipeedIO·
What about this Spec #SLogic32U3 with simple oscilloscope functions: 1. USB3.2 gen2 10Gbps interface 2. Digtal sample: Max 1600M@4CH, 800M@8CH, 400M@16CH, 200M@32CH 3. Analog input: 200Msps@4CH, 400Msps@2CH, 800Msps@1CH 4. LA for 149$, ADC module 15$/CH.
Sipeed tweet media
English
8
19
181
17.6K
Matthew Kienow
Matthew Kienow@HacksForProfit·
@SipeedIO Thanks for the quick reply. Hopefully there is better engagement from upstream soon. Are you able to provide sample rates that are possible when using the device in a Linux VM?
English
1
0
0
79
Sipeed
Sipeed@SipeedIO·
@HacksForProfit We have submit PR, but sigrok upstream is very inactive and hasn't merged anything for a long time. HDL is not opensource
English
1
0
0
147
Matthew Kienow
Matthew Kienow@HacksForProfit·
@UjlakiMarci It appears the initial CVSS score for CVE-2025-36636 doesn't align with the description. "Authenticated user" yet the CVSS vector has privileges required (PR) none. The initial CVSS record went through as a 10 for some reason and has not been updated yet.
English
0
0
0
81
Marci Ujlaki
Marci Ujlaki@UjlakiMarci·
A security center which... isn't secure? 🤔 NVD lists it as a max score severity vulnerability, but the official site says medium? 🟥 CVE-2025-36636, CVSS: 10.0 (#Critical, #Highest) Tenable Security Center version prior to 6.7.0 Improper access control vulnerability. Authenticated users can access areas outside their authorized scope, leading to potential data exposure. #CyberSecurity #CVE #Vulnerability #Tenable #AccessControl #670" target="_blank" rel="nofollow noopener">docs.tenable.com/release-notes/…
Marci Ujlaki tweet media
English
3
0
0
156
Matthew Kienow retweetledi
runZero, Inc.
runZero, Inc.@runZeroInc·
🗣️ Happening today at Black Hat Arsenal! Join @HacksForProfit & @Percent_X at 11am PDT for a live demo of Akheron Proxy, a tool for bridging, capturing, replaying, and manipulating UART inter-chip communications. 📍 Business Hall, Arsenal Station 9 🔗 runzero.com/black-hat-arse…
runZero, Inc. tweet media
English
0
1
0
214
Matthew Kienow retweetledi
HD Moore
HD Moore@hdmoore·
I'm excited to announce our "Out-of-Band" series; focused on the security risks of management devices like BMCs, serial servers, and KVMs. "Out-of-Band, Part 1: The new generation of IP KVMs and how to find them" is now live at: runzero.com/blog/oob-p1-ip…
HD Moore tweet mediaHD Moore tweet mediaHD Moore tweet mediaHD Moore tweet media
English
2
45
124
13.9K
Matthew Kienow retweetledi
Stephen Fewer
Stephen Fewer@stephenfewer·
We have just published our AttackerKB @rapid7 Analysis for CVE-2024-47575, the recent FortiManager 0day, aka FortiJump 🔥 Read our full technical analysis; detailing firmware decryption, protocol analysis, and unauthenticated RCE 🚀 attackerkb.com/topics/OFBGprm…
English
7
65
168
39.2K
Matthew Kienow retweetledi
Caitlin Condon
Caitlin Condon@catc0n·
CVE and vendor advisory now available on the #FortiManager 0day that's been knocking around the rumor mill (and evidently some Fortinet customers' email inboxes) for a while. Mitigate immediately, but IOCs need investigating, too. rapid7.com/blog/post/2024…
English
0
8
16
2.1K
Matthew Kienow retweetledi
Caitlin Condon
Caitlin Condon@catc0n·
Rapid7's 2024 Attack Intelligence Report was released today and includes insights from 14 months of vulnerability and exploit analysis, thousands of ransomware incidents, 180+ APT campaigns, and a year+ of Rapid7 incident response findings. rapid7.com/research/repor…
English
2
56
171
29.5K