Grambulf

9.2K posts

Grambulf

Grambulf

@grambulf

Katılım Ekim 2011
631 Takip Edilen345 Takipçiler
Grambulf retweetledi
zhiniang peng
zhiniang peng@edwardzpeng·
#VisualStudio 1-click RCE, No Smartscreen warning, No trust need, No futher interaction need. Just download from internet, 1-click then pwn. But it will not be fixed, because Microsoft consider it's not a vulnerability😅
English
8
54
193
32.2K
kat traxler
kat traxler@NightmareJS·
Ever wanted to attack AWS from GCP? I know I did. Unveiling The DeRF @cloudvillage_dc Friday August 11th at 12:30 PDT. #talks?collapsekattraxler" target="_blank" rel="nofollow noopener">cloud-village.org/#talks?collaps…
English
1
6
34
2.5K
Grambulf retweetledi
FerrousSystems
FerrousSystems@FerrousSystems·
Today, we're announcing the immediate availability of the Ferrocene release candidate! We're also inviting you to our birthday party on October 4th, where we will meet online with guests, have fun conversations and unveil the Ferrocene product fully. ferrous-systems.com/blog/a-decade-…
English
0
32
112
31.6K
RedTeam Pentesting
RedTeam Pentesting@RedTeamPT·
🚨 New Advisory: RWS WorldServer 🚨 redteam-pentesting.de/advisories/rt-… The vulnerability allows to feasibly enumerate session tokens. While it was fixed by the vendor prior reporting, no concrete information is publicly available that this critical issue was fixed in v11.8.0. #infosec
English
1
3
7
1.1K
Grambulf
Grambulf@grambulf·
@RedTeamPT "A significant number of security enhancements have been included in this release" 🤡 Awesome work (again)
English
0
0
1
52
Andreas Lehr
Andreas Lehr@shakalandy·
Can I have your API Key? oh wait. "Data analysis using regular expressions to search for specific secrets revealed the exposure of 52,107 valid private keys and 3,158 distinct API secrets in 28,621 Docker images" bleepingcomputer.com/news/security/…
English
1
0
0
326
Grambulf retweetledi
Truffle Security
Truffle Security@trufflesec·
Introducing Forager! Check to see if anyone using your company's email domain posted LIVE SECRETS to GitHub and NPM: forager.trufflesecurity.com
Truffle Security tweet mediaTruffle Security tweet media
English
2
33
88
30.4K
Grambulf retweetledi
Dylan
Dylan@InsecureNature·
Okay, so why are we releasing a free tool to see which companies are exposing secrets? A little while ago we started doing disclosure emails for every key leaked out, but we were shocked to with what we saw Short 🧵
Truffle Security@trufflesec

People don’t realize how often live keys leak out on GitHub in 2023, despite this being a known problem for almost a decade. Next week we’re releasing a tool to check if your company exposed any. Here’s a thread on it 1/6

English
2
9
29
10.9K
Grambulf retweetledi
Marc Backes
Marc Backes@marcba·
As an introvert at a tech conference
Marc Backes tweet media
English
122
617
5.5K
681.4K
Grambulf retweetledi
BSides Zurich
BSides Zurich@BSidesZurich·
📢📢📢 Accepted Talks and Speakers' Bios published 📢📢📢 Thanks to all who applied to our #CfP and to our reviewers, the list of accepted talks is now on our website. Detailed agenda will follow bsideszh.ch/talks-bios/ REMEMBER: Tickets sale starts tomorrow 3pm Zurich time 🥳
GIF
English
0
15
14
2.8K
Grambulf retweetledi
Malcolm
Malcolm@malkoegler·
@N4hualH @CyberSleuth1 @solminingpunk @BruteBee There might already be active exploitation on this. Check for files newer than the installation date in /netscaler/ns_gui/ /var/vpn/ /var/netscaler/logon/ /var/python/
English
3
3
15
3.2K
Grambulf retweetledi
joernchen
joernchen@joernchen·
"Sollte es jedoch Zero-Day-Exploits bei Messengerdiensten geben, müsse das BSI diese konsequenterweise verschweigen, wenn "andere Stellen" diese offenhalten wollten." golem.de/news/neue-bsi-…
Deutsch
3
3
6
1.8K
Grambulf retweetledi
Dr. Anton Chuvakin
Dr. Anton Chuvakin@anton_chuvakin·
"Log Centralization: The End Is Nigh?" buff.ly/3CQQmZw <- a VERY incomplete thought blog that talks about centralized vs decentralized/federated/distributed approaches for dealing with logs, at scale.
English
9
7
40
11.8K