Devon Kerr

12.4K posts

Devon Kerr banner
Devon Kerr

Devon Kerr

@_devonkerr_

Custodian of secret histories. Posts are my own.

New York State Katılım Ekim 2014
762 Takip Edilen7.9K Takipçiler
Andrew Thompson
Andrew Thompson@ImposeCost·
Build with the assumption that some manager is going to want performance metrics. Hell, maybe even draw those requirements out of them early. How many times people want to measure performance across a range of data points and milestones in a workflow, and a system doesn't facilitate it...
English
2
1
25
1.4K
Devon Kerr retweetledi
Dan Black
Dan Black@DanWBlack·
Good overview of tactics being used to compromise Signal accounts. Government/military officials, or anyone working at the intersection of Russian security issues (private sector, journalists, civil society orgs writ large) should urgently review. ic3.gov/PSA/2026/PSA26…
Dan Black tweet mediaDan Black tweet media
English
5
67
161
18.1K
Devon Kerr retweetledi
watchTowr
watchTowr@watchtowrcyber·
~150 S3 abandoned buckets. 8M+ requests. Two months. Software updates, binaries, VMs and more. This week, AWS rolled out namespaces for new S3 buckets - finally. This is why offensive security research is so important - to move the needle. labs.watchtowr.com/8-million-requ…
English
5
30
139
21.3K
Devon Kerr retweetledi
laulukaskas
laulukaskas@clockstiqqun·
there should be a goulash based fast food chain. like there's just a few pots of very hearty hungarian stew plus a few other magyar basics to go with it and you can get a big bowl of it for like $5
English
48
227
3.9K
77.2K
Devon Kerr retweetledi
丂卄ㄖᗪ卂几 - 👋 crack fingers
Free research idea! * VGA/HDMI has an i2c interface * Probe this, you might find flash programmers * Maybe they’re connected to SPI chips holding EDID / UI of the monitor menu * Maybe KVMs just join these lines together * Maybe you can move data between air gapped machines
KF@d0tslash

"Your KVM is the Weak Link: How $30 Devices Can Own Your Entire Network" @securityweekly eclypsium.com/blog/your-kvm-…

English
0
1
15
1.6K
Devon Kerr
Devon Kerr@_devonkerr_·
For twenty-three years I’ve been twenty-three years They made me out of stone For you
English
0
0
2
128
Devon Kerr retweetledi
Anton
Anton@Antonlovesdnb·
@_subTee People sleep on data sources for sure!
English
0
1
4
296
Devon Kerr
Devon Kerr@_devonkerr_·
@cyb3rops It could be way easier to implement a local model, but them SaaS revenue metrics
English
0
0
1
324
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Can anyone explain this to me? First Claude Workspace, then Perplexity, now Manus - they keep using words like “my”, “personal”, and “local” in a way that suggests local information isn’t being sent to a remote LLM or RAG system for evaluation. But if no local LLM is actually running, then almost nothing except maybe config stays local. The reasoning still happens remotely. Right? Also - does anyone really think this belongs on a corporate workstation?
Manus@ManusAI

Today, we're taking Manus out of the cloud and putting it on your desktop. Introducing My Computer, the core feature of the new Manus Desktop app. It’s your AI agent, now on your local machine.

English
40
23
253
37.5K
Devon Kerr
Devon Kerr@_devonkerr_·
@filar @_subTee The best of lifetimes, reflected in photographic stills captured alongside Robert Kennedy’s funeral train.
English
0
0
2
28
Devon Kerr retweetledi
Olivia Gallucci ✨
Olivia Gallucci ✨@OliviaGalluccii·
I'm excited to announce my latest blog post: Boot ROM security on Silicon Macs! 🥾 This article marks the start of a 4-part series, detailing each stage of the boot process. My next post will be on the low level bootloader (LLB). oliviagallucci.com/boot-rom-secur…
Olivia Gallucci ✨ tweet media
English
3
25
161
8.6K
Devon Kerr
Devon Kerr@_devonkerr_·
@HackingLZ @JBizzle703 Every single time I move, a lab finds a new home and I get 6-8 months of relative peace to learn stained glass composition before I start building a new one.
English
0
0
6
104
Justin Elze
Justin Elze@HackingLZ·
@JBizzle703 If you’re old enough there are those of us who built and tried to give away some giant home Cisco labs 🤣
English
4
0
15
1.9K
Devon Kerr
Devon Kerr@_devonkerr_·
Ohohoho new work laptop
English
0
0
3
438
Devon Kerr
Devon Kerr@_devonkerr_·
Week one of the vacation between jobs is almost done and I’ve built a 12’ tall ag fence, painted my office, diagnosed a fuel line issue, started landscaping the front garden, and cleaned the garage. And only got one thing on my todo list done, somehow.
English
1
0
9
579
Devon Kerr retweetledi
MG
MG@_MG_·
If you use a personal phone/laptop for your work, pay very close attention to this little detail. Iran attackers wipe 200k devices at a company called Stryker. Within those devices appears to be employees PERSONAL devices. The attackers used the company’s MDM software, which is basically IT management software running on everything. It’s an incredibly attractive backdoor to an attacker. I successfully targeted MDM software for several Red Team engagements. It’s… lots of fun :) Anyway, a lot of companies require you to install their MDM software on your personal devices before you can access resources like Corp email. It’s used to keep devices updated, lock things down if they get stolen, etc. The company often promises that they won’t access personal data, erase any personal data, etc. But this is often ONLY POLICY. If a bad actor gains access to the MDM tool, as was the case here, then anything can happen. People should be aware of these risks. I refused to run MDM software on any of my personal devices. The company needs to provide me with hardware if they want that. I personally isolate all corp devices to their own network too. If an adversary can get into the corp laptop, then can then get inside my network… there have been cases of it happening in the past.
MG tweet media
Kim Zetter@KimZetter

I've published more details about the cyberattack in this piece: zetter-zeroday.com/iranian-hackti…

English
88
652
3.3K
560.6K