Nate Robb

659 posts

Nate Robb

Nate Robb

@NateRobb

Senior Threat Enablement Operator @BishopFox

Phoenix, AZ Katılım Şubat 2009
315 Takip Edilen202 Takipçiler
Moloch
Moloch@LittleJoeTables·
Well, that'll wake you up in the morning.
Moloch tweet media
English
4
3
12
1.5K
Nate Robb retweetledi
shenetworks
shenetworks@shenetworks·
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
English
174
266
1.9K
293.5K
Nate Robb
Nate Robb@NateRobb·
LiteLLM Proxy has a pre-auth SQL injection (CVE-2026-42208) I recently reproduced as part of @bishopfox's Emerging Threat process. Below is a technical analysis I put together with a safe detection payload that can be used to identify vulnerable deployments.
Bishop Fox@bishopfox

A failed login should not take 6 seconds. Bishop Fox researchers reproduced CVE-2026-42208 in LiteLLM’s proxy. The attack requires no authentication, still returns HTTP 401 responses, and uses timing delays to extract sensitive data. Observed in the wild roughly 36 hours after disclosure. Upgrade to 1.83.7 or higher.

English
0
1
5
1.5K
Nate Robb retweetledi
Bishop Fox
Bishop Fox@bishopfox·
We’re heading to @CactusCon 14! 🌵 Bishop Fox is sponsoring again this year, with talks from Dan Petro and Nate Robb on EDR evasion and real-world CVE prioritization. We’ll be around all weekend to talk Red Team tradecraft, research, and offensive security. See you in Mesa!
Bishop Fox tweet media
English
0
2
2
423
Nate Robb
Nate Robb@NateRobb·
@CactusCon Just a heads up, not seeing a "Notes to Organizer" section to include a talk outline on the session submission page. Tried throwing the outline at the end of the session description but hit the character limit.
English
0
0
0
31
CactusCon
CactusCon@CactusCon·
🥳 IT BEGINS 🥳 The CactusCon 14 CFP is now OPEN! sessionize.com/cactuscon-14/ Theme is an oldie but a goodie, regardless as usual we are looking for those juicy technical talks that make CactusCon great. #cc14
English
2
9
15
2.4K
Nate Robb
Nate Robb@NateRobb·
@vxunderground Looks to be an n-day disclosed in April (CVE-2025-31324), but appears to be the first full proof-of-concept available.
English
0
0
7
1.9K
vx-underground
vx-underground@vxunderground·
"Scattered Lapsus$ Hunters (UNC3944)", have released an alleged SAP7 0day exploit onto Telegram. I can't confirm or deny if it's an actual 0day, I have no way to test or confirm anything. However, it is fully weaponized. I've uploaded it to VXUG vx-underground.org/tmp
English
15
41
243
51.7K
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to @mwulftange
CODE WHITE GmbH tweet media
English
8
160
635
110K
Nate Robb
Nate Robb@NateRobb·
Ever feel overwhelmed by the constant firehose of newly disclosed vulnerabilities? Check out my latest blog post where I outline the methodology our Threat Enablement team at Bishop Fox uses to cut through the noise: bfx.social/3GcLIdz
English
0
0
1
183
Nate Robb retweetledi
Bishop Fox
Bishop Fox@bishopfox·
Our Threat Enablement and Analysis team built a better way to cut through the noise. This is how we triage the firehose, turning chaos into action. By Senior Operator Nate Robb: bfx.social/45Ltri1
English
0
1
1
565
Nate Robb
Nate Robb@NateRobb·
@Jhaddix Is this the issue where the valid hits in feroxbuster disappear from the terminal window and you just see the list of invalid attempts?
English
1
0
0
797
JS0N Haddix
JS0N Haddix@Jhaddix·
Recently I ran into an unresolvable issue with one of my wordlists & content discovery. I had to switch from FeroxBuster to FFuF In security testing It will greatly benefit you to have redundancies in tools: nmap <-> naabu <-> ++ httpx <-> httprobe jaeles <-> nuclei etc..
English
10
24
177
28.8K
Nate
Nate@nnwakelam·
so I just got my pool upgraded and I'm pretty sure I can get ssh access to my pool unsure how I feel about this
English
4
0
42
0
Nate Robb
Nate Robb@NateRobb·
@jonathandata1 FYI: I could reproduce the Airdropped website auto accept only when both devices were signed in with the same Apple ID. When the Apple IDs were different (as would be the case in an attack) the victim device was prompted for permission to open the Airdropped website.
English
2
0
9
0
Nate Robb
Nate Robb@NateRobb·
@AndrivetSeb I ask because I could use it for an engagement I am currently on if you would be willing to share.
English
0
0
0
0
Nate Robb
Nate Robb@NateRobb·
@AndrivetSeb I just stumbled upon your talk "The Security of MDM systems" from Hack in Paris 2013. Did you happen to publicly release the Java tool to decrypt passwords from identityconfig.xml files?
English
0
0
0
0