Beau Bullock

4.2K posts

Beau Bullock banner
Beau Bullock

Beau Bullock

@dafthack

Hacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH

Florida, USA Katılım Ocak 2013
661 Takip Edilen18.4K Takipçiler
Josh
Josh@passthehashbrwn·
@_subTee @dafthack I took the class around 2020(?) and pretty much as a direct result got a job doing cloud pentesting and found multiple Azure 0days, can't say enough good things
English
1
0
7
1.1K
Beau Bullock
Beau Bullock@dafthack·
@_subTee Thanks so much for the kind words Casey! I hope you are doing well man!
English
0
0
3
208
Beau Bullock retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
Next week at @WWHackinFest I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
Dirk-jan tweet media
English
2
30
149
10.8K
Beau Bullock retweetledi
Graham Helton (too much for zblock)
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
Graham Helton (too much for zblock) tweet media
English
46
377
2.6K
408.9K
Beau Bullock retweetledi
nyxgeek
nyxgeek@nyxgeek·
Here's a video PoC for Azure Entra ID SignIn Log Bypass in action. I had to make it to help MSRC replicate it (lol). You'll see how simple this bypass was. No worries admins, Microsoft says that it was only a "Moderate" issue.
English
12
68
418
41.4K
Beau Bullock retweetledi
Marcello
Marcello@byt3bl33d3r·
“Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models” One day we might be hiring literature majors in cybersecurity. arxiv.org/abs/2511.15304
English
1
4
17
1.9K
Beau Bullock retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
902
3.2K
470.4K
Beau Bullock retweetledi
Beau Bullock
Beau Bullock@dafthack·
Two opportunities to take my Breaching the Cloud course live are coming up soon. If you want to learn how to hack cloud environments like Azure and AWS this is the course for you. Sep. 23 & 24 - Fully remote and live Oct. 7 & 8 - In-person only at @WWHackinFest Register here: antisyphontraining.com/course/breachi…
Beau Bullock tweet media
English
2
12
34
3.5K
Sol Roberts
Sol Roberts@Badgerops·
Just thinking about that time I ran into @stokfredrik and @dafthack at a random metal shop in Stockholm and had no idea who Stök was. Was good to meet both of y’all, and discover the cool things you’ve been working on!
English
3
1
9
2.6K
Beau Bullock retweetledi
Kuba Gretzky
Kuba Gretzky@mrgretzky·
FIDO downgrades are still possible, in reverse proxy phishing attacks, if you manage to convince the server that your device does not support strong MFA. 🪝🐟 Research from @proofpoint: proofpoint.com/us/blog/threat…
English
2
28
87
13.3K
Beau Bullock retweetledi
The Hacker News
The Hacker News@TheHackersNews·
🚨 Microsoft just warned: CVE-2025-53786 lets hackers silently escalate privileges from on-prem Exchange to the cloud. No logs. No easy traces. Your hybrid setup could be a silent breach vector. Full details + fixes → thehackernews.com/2025/08/micros…
English
5
135
360
72.7K
Beau Bullock retweetledi
Michael Bargury
Michael Bargury@mbrg0·
we got a persistent 0click on ChatGPT by sharing a doc that allowed us to exfiltrate sensitive data and creds from your connectors (google drive, sharepoint, ..) + chat history + future conversations it gets worse. we deploy a memory implant #DEFCON #BHUSA @tamirishaysh
English
21
193
813
79.6K
Beau Bullock retweetledi
Garrett
Garrett@unsigned_sh0rt·
I pushed updates to SCCMHunter as part of my Arsenal demo at #BHUSA today! New features include a relay module for TAKEOVER-5 and a community contribution to coerce client push from a *nix host for ELEVATE-2. github.com/garrettfoster1….
English
1
52
137
7.3K
Beau Bullock retweetledi
Black Hills Information Security
Black Hills Information Security@BHinfoSecurity·
**NEW RELEASE** Offensive Tooling Cheatsheets: An Infosec Survival Guide Resource 10 essential offensive tool references, available as PDFs or blog posts. Download all or individual sheets. Thanks again to all our contributors! Check it out: blackhillsinfosec.com/offensive-tool…
Black Hills Information Security tweet media
English
1
8
27
5.1K