Enrico M.

981 posts

Enrico M. banner
Enrico M.

Enrico M.

@ilmila

product security - appsec - caffeine addicted

Trieste - Italy Katılım Ağustos 2009
1.3K Takip Edilen387 Takipçiler
Enrico M. retweetledi
Enno Rey
Enno Rey@Enno_Insinuator·
Uncovering hidden paths in 5G core: Exploiting protocol tunneling and network boundary bridging tu.berlin/fileadmin/www/… [PDF]
Enno Rey tweet mediaEnno Rey tweet media
English
1
5
6
2K
Enrico M. retweetledi
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
🔥 Microsoft fixed a high severity data exfiltration exploit chain in Copilot that I reported earlier this year. It was possible for a phishing mail to steal PII via prompt injection, including the contents of entire emails and other documents. The demonstrated exploit chain consists of techniques that didn't even exist 2 years ago. 🔥 In particular, it involves: 1. Prompt Injection 💉 2. Automatic Tool Invocation (without human in loop) to bring PII into chat context ⚙️ 3. ASCII Smuggling 🫣 4. Rendering of benign link + invisible text 👀 5. (Optional) Conditional instructions to only trigger when certain users view the content ☝️ Discussing two demos (stealing sales data and MFA codes), including the videos I had shared with MSRC in February. @simonw @goodside @llm_sec embracethered.com/blog/posts/202…
English
7
70
266
73.5K
Enrico M. retweetledi
Chris Bakke
Chris Bakke@ChrisJBakke·
The next time you have imposter syndrome at work, just remember:
Chris Bakke tweet media
English
186
4.7K
57.6K
4.8M
Enrico M. retweetledi
@mikko
@mikko@mikko·
Andy was the CISO for Maersk Line when they were hit by Notpetya in 2017. He told what really happened to the audience of the t2 conference this May. Video here: youtu.be/wT2r5VuYCU0
YouTube video
YouTube
@mikko tweet media
English
3
98
331
82.9K
Enrico M. retweetledi
Security Obscurity
Security Obscurity@SecObscurity·
@theluemmel @ZephrFish Based on my experience, the most interesting vulnerabilities on Nessus you can find it tagged as INFO <.<
English
0
1
9
633
Enrico M. retweetledi
Offensive OSINT
Offensive OSINT@the_wojciech·
I built a real-time intelligence gathering tool and it's accessible online. Open Source Surveillance has 18 features including social media, cameras, #IoT, #ICS, transportation and more. #osint #intelligence #infosec #privacy
GIF
English
21
214
832
101.3K
Enrico M. retweetledi
Trond Hjorteland
Trond Hjorteland@trondhjort·
TIL: The CIA “The Simple Sabotage Field Manual” from WWII suggested enforcing the bureaucracy at companies that delivered to the enemy as a viable sabotage technique. corporate-rebels.com/cia-field-manu…
Trond Hjorteland tweet mediaTrond Hjorteland tweet mediaTrond Hjorteland tweet mediaTrond Hjorteland tweet media
English
3
16
51
18.3K
Enrico M. retweetledi
Soufiane
Soufiane@S0ufi4n3·
Just installed Nmap and ran it... Mind blowing tho.. I'm getting addicted to this shit lol OpenAI is awesome 😁😁
Soufiane tweet mediaSoufiane tweet media
English
9
29
193
0
Enrico M. retweetledi
raptor
raptor@0xdea·
Not fan of "awesome" lists in general, however these maturity models collected by @Eliyahu_Tal_ can turn out to be pretty useful github.com/TalEliyahu/awe… I've developed some maturity models myself in the past, and I found them to be a valuable infosec tool (if used properly).
English
1
4
11
0
Enrico M. retweetledi
Mark Simos
Mark Simos@MarkSimos·
What are your top security Antipatterns? (opposite of best practice) (en.wikipedia.org/wiki/Anti-patt…) I have these so far - 10 patching antipatterns - "compliant is not secure" @scritches - "Collection is not detection" for log data - re-using the same password what else?
Mark Simos tweet mediaMark Simos tweet mediaMark Simos tweet media
English
4
10
35
0
Aaron Manville
Aaron Manville@ACmanville·
@ring my account was hacked and I can’t recover my account the hacker is making vulgar comments towards me and my neighbors through my door bell
English
76
293
3.1K
0
Enrico M.
Enrico M.@ilmila·
@0xdea MS Teams with "take control" functionality acts exactly in that way...A user can access to the clipboard of the other user..
English
0
2
2
0
raptor
raptor@0xdea·
I wonder if that’s still the case. I haven’t looked into RDP architecture, but this seems likely. Also other similar products, including video conferencing with screen sharing capabilities, might work this same way…
raptor@0xdea

I was reading this old whitepaper and something got my attention: “A malicious RDP server can eavesdrop on the client’s clipboard – this is a feature, not a bug. For example, the client locally copies an admin password, and the server can read it.” i.blackhat.com/USA-19/Wednesd…

English
2
1
0
0