Beau Bullock

4.2K posts

Beau Bullock banner
Beau Bullock

Beau Bullock

@dafthack

Hacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH

Florida, USA Katılım Ocak 2013
645 Takip Edilen18.4K Takipçiler
Sabitlenmiş Tweet
Beau Bullock
Beau Bullock@dafthack·
I’m excited to announce my newest training course, Breaching M365, is now available on-demand through @Antisy_Training. For $295, you get a full offensive methodology for attacking Microsoft 365 environments, from unauthenticated recon and initial access to OAuth abuse, persistence, privilege escalation, and data harvesting. If you want to level up your M365 tradecraft, check it out here: antisyphontraining.com/product/breach…
Beau Bullock tweet media
English
3
16
102
6.6K
Beau Bullock retweetledi
Beau Bullock
Beau Bullock@dafthack·
I’m excited to announce my newest training course, Breaching M365, is now available on-demand through @Antisy_Training. For $295, you get a full offensive methodology for attacking Microsoft 365 environments, from unauthenticated recon and initial access to OAuth abuse, persistence, privilege escalation, and data harvesting. If you want to level up your M365 tradecraft, check it out here: antisyphontraining.com/product/breach…
Beau Bullock tweet media
English
3
16
102
6.6K
Beau Bullock retweetledi
Anthropic
Anthropic@AnthropicAI·
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing
English
2K
6.7K
44.1K
31.3M
Beau Bullock retweetledi
Alex
Alex@xaitax·
So Microsoft Copilot has its own App-Bound Encryption now. The standalone Copilot app (mscopilot.exe) is a full Chromium browser based on Edge, ships with its own elevation_service.exe, a dedicated COM interface (IElevatorCopilot), and a separate ABE key scope. Decrypting the ABE key gives us some cookies (copilot.microsoft.com auth, MUID, MSAL session, Cloudflare tokens) and the Microsoft Account token from the token_service database. Local Storage also holds MSAL.js cached tokens. An ID token, two access tokens (chatai.readwrite for the Copilot API + user.read for Microsoft Graph), and account metadata for the signed-in MSA. These use MSAL's own browser-bound CryptoKey encryption, not ABE. Edge 147 also quietly hardened IElevator2 by switching from oleaut32 to a custom proxy/stub but simultaneously registered IElevatorCopilot with oleautomation. Closed one door, opened another. Next up: decrypting the MSAL tokens? 🤔
Alex tweet media
English
7
58
237
21.2K
Beau Bullock retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️ BREAKING: PyPI package telnyx has been compromised by TeamPCP in yet another supply chain attack. The malware executes immediately upon importing telnyx. It drops a valid WAV audio file and runs an executable embedded within the frames.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
63
543
2.9K
707.6K
Beau Bullock retweetledi
Daniel Hnyk
Daniel Hnyk@hnykda·
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
English
308
2.3K
9.4K
5.8M
Josh
Josh@passthehashbrwn·
@_subTee @dafthack I took the class around 2020(?) and pretty much as a direct result got a job doing cloud pentesting and found multiple Azure 0days, can't say enough good things
English
1
0
7
1.1K
Beau Bullock
Beau Bullock@dafthack·
@_subTee Thanks so much for the kind words Casey! I hope you are doing well man!
English
0
0
3
208
Beau Bullock retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
Next week at @WWHackinFest I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
Dirk-jan tweet media
English
2
30
152
11.2K
Beau Bullock retweetledi
Graham Helton (too much for zblock)
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
Graham Helton (too much for zblock) tweet media
English
47
375
2.6K
413.4K
Beau Bullock retweetledi
nyxgeek
nyxgeek@nyxgeek·
Here's a video PoC for Azure Entra ID SignIn Log Bypass in action. I had to make it to help MSRC replicate it (lol). You'll see how simple this bypass was. No worries admins, Microsoft says that it was only a "Moderate" issue.
English
12
67
421
41.6K
Beau Bullock retweetledi
Marcello
Marcello@byt3bl33d3r·
“Adversarial Poetry as a Universal Single-Turn Jailbreak Mechanism in Large Language Models” One day we might be hiring literature majors in cybersecurity. arxiv.org/abs/2511.15304
English
1
4
18
2K
Beau Bullock retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
139
903
3.2K
474.5K
Beau Bullock retweetledi
Beau Bullock
Beau Bullock@dafthack·
Two opportunities to take my Breaching the Cloud course live are coming up soon. If you want to learn how to hack cloud environments like Azure and AWS this is the course for you. Sep. 23 & 24 - Fully remote and live Oct. 7 & 8 - In-person only at @WWHackinFest Register here: antisyphontraining.com/course/breachi…
Beau Bullock tweet media
English
2
12
34
3.5K
Sol Roberts
Sol Roberts@Badgerops·
Just thinking about that time I ran into @stokfredrik and @dafthack at a random metal shop in Stockholm and had no idea who Stök was. Was good to meet both of y’all, and discover the cool things you’ve been working on!
English
3
1
9
2.6K
Beau Bullock retweetledi
Kuba Gretzky
Kuba Gretzky@mrgretzky·
FIDO downgrades are still possible, in reverse proxy phishing attacks, if you manage to convince the server that your device does not support strong MFA. 🪝🐟 Research from @proofpoint: proofpoint.com/us/blog/threat…
English
2
28
87
13.3K