Jinson Varghese

20.5K posts

Jinson Varghese banner
Jinson Varghese

Jinson Varghese

@JinsonCyberSec

Author & Editor @OWASP_WSTG. Reviewer @OWASPTop10. Information Security Lead @GetAstra. Follow me for the latest tips and updates in #Cybersecurity

Katılım Temmuz 2010
90 Takip Edilen4.2K Takipçiler
Sabitlenmiş Tweet
Jinson Varghese
Jinson Varghese@JinsonCyberSec·
#IfYouDidntKnow Running "cat /etc/passwd" gives an output that is a bit hard to read. Thanks to the column command, we can make it easier on the eyes. cat /etc/passwd | column -t -s : -t is used for creating a table -s defines the column delimiter, in this case ":" #ShellTips
Jinson Varghese tweet media
English
7
30
142
0
Jinson Varghese retweetledi
David J Phillips
David J Phillips@davj·
"Make no mistakes DO NOT HALLUCINATE. YOU ARE AN EXPERT SOFTWARE ENGINEER"
English
192
2.1K
24.4K
1.3M
Jinson Varghese retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
543
4.1K
16.3K
12.1M
Jinson Varghese retweetledi
Jordan
Jordan@jorolevenque·
Twitter is less fun because you can no longer tell who is naturally dumb and who is trying to make rent from ragebait
English
931
34.5K
257.8K
3M
Jinson Varghese retweetledi
The Figen
The Figen@TheFigen_·
Japanese actor Hiroyuki Sanada spoke about the contradictions of human nature: “Some people dream of having a swimming pool at home, while those who have one hardly ever use it. Those who have lost a loved one feel a profound sense of loss, while others often complain about their living relatives. Those without a partner long for one, while those who have one often don't appreciate it. The hungry would give anything for a meal, while the satiated complain about the taste of their food. Those without a car dream of owning one, while those who have a car are always looking for a better one.” The key to happiness is gratitude: truly seeing and appreciating what we already have, and understanding that somewhere, someone would give anything for what we take for granted.
The Figen tweet mediaThe Figen tweet media
English
1.1K
18.9K
99.1K
3.5M
Jinson Varghese retweetledi
Ramin Nasibov
Ramin Nasibov@RaminNasibov·
Does anyone remember having to defrag their computer? 😆
English
668
291
12.2K
414.2K
Jinson Varghese retweetledi
Massimo
Massimo@Rainmaker1973·
19-year-old finds abandoned baby and raises him like a little brother, now they're inseparable
English
94
727
7.3K
181.9K
Jinson Varghese retweetledi
Karen Tumulty
Karen Tumulty@ktumulty·
My late cousin, who I adored and miss every day, once said to me: Never make fun of someone for mispronouncing a word. It means they learned it by reading.
English
390
2.8K
30K
988.1K
Jinson Varghese retweetledi
ASTRA Security
ASTRA Security@getastra·
AI and the preteen mind - guide or corrupt? The choices we make today shape how the next generation learns.🧠
English
0
1
1
78
Jinson Varghese retweetledi
𐌁𐌉Ᏽ 𐌕𐌉𐌌𐌉
Some Twitter users don't even tweet, they just retweet, laugh, and have fun.
English
1.4K
40.7K
198.9K
3.2M
Jinson Varghese retweetledi
Nyatsimba Mutotesi
Nyatsimba Mutotesi@timiretimzzy2·
I run every day for 30 minutes, if I miss a day I add 30 minutes to the next day. This has truly been a game changer, tomorrow I’m supposed to run for 3 weeks.
English
3.5K
30.3K
314.7K
5.9M
Jinson Varghese retweetledi
Wholesome Side of 𝕏
Wholesome Side of 𝕏@itsme_urstruly·
Dialogue 0% Happy Men 100% 😂
English
72
1.8K
30.5K
655.5K
Jinson Varghese retweetledi
Branko
Branko@brankopetric00·
A penetration tester got root access to our Kubernetes cluster in 15 minutes. Here's what they exploited. The attack chain: - Found exposed Kubernetes dashboard (our bad) - Dashboard had view-only service account (we thought this was safe) - Service account could list secrets across all namespaces - Found AWS credentials in a secret - Used AWS credentials to access EC2 instance profile - Instance profile had full Kubernetes admin via IAM - Used kubectl to create privileged pod - Escaped to node - Root access to entire cluster What we thought we did right: - Dashboard was read-only - Secrets were encrypted at rest - Network policies were in place - Regular security updates What we missed: - Dashboard shouldn't be exposed at all - Service accounts need principle of least privilege - Secrets shouldn't contain AWS credentials (use IRSA instead) - Pod Security Policies weren't enforced - Node access wasn't hardened The fix took 2 weeks: - Removed Kubernetes dashboard entirely - Implemented IRSA for all pod AWS access - Applied strict PSPs/Pod Security Standards - Audit all RBAC permissions - Regular penetration testing Cost: $24K for the pentest Value: Prevented what could have been a catastrophic breach
English
72
343
3.2K
219.5K
Jinson Varghese retweetledi
Madrid Zone
Madrid Zone@theMadridZone·
🚨 Carlos Alcaraz: "Real Madrid will win 2-1 today. Mbappé and Bellingham will score."
Madrid Zone tweet media
English
1.6K
7.7K
105.7K
5.6M