Daniel Sagi retweetledi
Daniel Sagi
45 posts

Daniel Sagi retweetledi
Daniel Sagi retweetledi

Key takeaways from the new video published on Palestinian channels showing the moments that preceded the death of journalist Shireen Abu Akleh:
1. Palestinian militants were at the scene, heard firing rapid bursts (0:12, 0:23, 0:30, 0:38). The #IDF, and especially its... (1/3)
English
Daniel Sagi retweetledi
Daniel Sagi retweetledi
Daniel Sagi retweetledi

@kvlly Work from home on open source, cloud native, security stuff. DM me for details
Itay Shakury@itaysk
Who wants to join our awesome Open Source Engineering team at @AquaSecTeam ? aquasec.com/about-us/caree…
English
Daniel Sagi retweetledi

💥VMware fixed an Unauth RCE in vCenter (CVE-2021-21972) found by our researcher Mikhail Klyuchnikov.
CVSS: 9.8 🔥
Advisory: vmware.com/security/advis…

English
Daniel Sagi retweetledi

@pst418 @lizrice Another could argue that they already issued a cve for MITM that requires CAP_NET_RAW.
*One year* after my disclosure.
Maybe because they can actually easily fix that by changing one sysctl parameter. blog.alcide.io/new-kubernetes…
English

@lizrice @danielsagi15 One could argue, K8s services are a direct responsibility, while CAP_NET_RAW is inherited from the container runtime or kernel and therefore only an indirect responsibility.
English

@saronyitbarek Being a luthier and building classical/acoustic guitars for sure
English
Daniel Sagi retweetledi
Daniel Sagi retweetledi

CVE-2020-12418 - Mozilla Firefox URL mPath Information Disclosure Vulnerability
All details in the advisory : talosintelligence.com/vulnerability_…
or just take a glance at this picture:

English
Daniel Sagi retweetledi

Windows 10 changed the way console applications (I/O) work. Now every console has a child process called "conhost.exe (Console Window Host)":
devblogs.microsoft.com/commandline/wi…
Your fuzzing process will likely be slower if your harness is developed as a console application.
English
Daniel Sagi retweetledi
Daniel Sagi retweetledi

I’ve made a new python lib that send raw HTTP requests using requests, now you will be able to send non RFC compliant requests to test web servers and you will get for free the connection handling, session handling, redirects, retries and more 😊 pypi.org/project/reques…
English
Daniel Sagi retweetledi

I discovered QNAP pre-auth root RCE affecting ~450K devices on the Internet
link.medium.com/BFxvQFGcB6
English










