Logan
3.6K posts

Logan
@maclarel_
Scotch enthusiast and mediocre powerlifter. I also break computers sometimes. Obligatory "tweets don't represent views of my employer, ever" disclaimer.
The Great White North Katılım Mart 2011
259 Takip Edilen225 Takipçiler

@github can anyone please help me with my github account i would like to be certain i have remedied any issue with compromise. contacting through support is not really fast enough
English
Logan retweetledi
Logan retweetledi

We’ve been digging through the #React RCE mess for two days now, trying to get at least some visibility into what’s going on out there. None of this is easy to detect, and most signals vanish in memory before you can even look at them.
My teammate @_swachchhanda_ put together a pair of #Sigma rules that cover the one thing that reliably shows up when someone actually executes code on a Node.js server -> child processes. One rule for Linux, one for Windows. It’s not a silver bullet, just one of the few angles that makes sense right now.
We pushed all our #YARA and #Sigma signatures for the React RCE cases as well, and contributed the Sigma rules upstream:
github.com/SigmaHQ/sigma/…
This whole situation shows how much attack surface lives in places many of us didn’t think about before. I expect we’ll see more of this class of issues now that people realize what’s possible.


English
Logan retweetledi

Don't miss "Hunters and Gatherers: The Realities of Bug Bounty Life" by Logan MacLaren (@maclarel_), Jeffrey Guerra (@s2jeff_gh), Johnathan Kuskos, Katie Noble, Sam Erb (@erbbysam)! 📅 Saturday, Aug 10 ⏰ 11:30 AM 📍 Creator Stage 4 #BugBounty #DEFCON

English
Logan retweetledi

Exciting news! The Bug Bounty Village website is live! 🚀🌐 Join us at @defcon for everything bug bounty. Explore our speakers, presentations, sponsors, events, and more. Visit bugbountydefcon.com #BugBountyVillage #DEFCON #CyberSecurity #BugBounty #HackerCommunity
English
Logan retweetledi

📢 Calling all hackers! Submit your CFP for the first official Bug Bounty Village at @DEFCON 32! Share your research, techniques, or run a workshop.
🕒 Deadline: May 31. Don't miss out!
Check the guidelines and submit here bit.ly/bugbountydefcon
#bugbounty #infosec #DEFCON32
English
Logan retweetledi
Logan retweetledi

In this post I'll use CVE-2023-6241, a vulnerability in the Arm Mali GPU that I reported last November to gain arbitrary kernel code execution from an untrusted app on a Pixel 8 with MTE enabled. github.blog/2024-03-18-gai…
English
Logan retweetledi
Logan retweetledi

Marty Stratton, @idSoftware Studio Director, lied about @DOOM Eternal's OST events in a Reddit post that used disinformation to blame me entirely for its failure
Later, he offered me a six-figure sum to never speak about it
The truth is more important.
link.medium.com/USjGbPeBOub
English
Logan retweetledi

Are you attending @ekoparty ? Go stop by the @GitHubSecurity booth and say hello to @s2jeff_gh from our Bounty Team.
English
Logan retweetledi

Check out the latest researcher interview in GitHub's Bug Bounty Researcher Spotlight series github.blog/2022-10-28-cyb…
English

@MakeItHackin @defcon @thedarktangent @jaysonstreet @deviantollam @marcwrogers @AlexChaveriat @maclarel_ found your halloween costume
English

get them while they last! @defcon goon costume.
what items are missing?
@thedarktangent @jaysonstreet @deviantollam @marcwrogers @AlexChaveriat
#defcon

English
Logan retweetledi

Did you know that GitHub doesn’t just encrypt data at rest but also encrypts specific database columns? Read about our column encryption strategy and our decision to adopt the #Rails column encryption standard. github.blog/2022-10-26-why…
English

@ArchAngelDDay I write out my daily agenda each morning when I get into my office. My handwriting has never been good, but this helped get it back to (mostly) legible levels.
English

Odd question - has anyone else with poor #handwriting had any success in improving it? If so, what tools/methods did you find helpful?
English
Logan retweetledi

Extremely valuable advice!
Gergely Orosz@GergelyOrosz
When I was a manager, I keept track of what people worked on, in my team. Yet, I can't count the number of times when I realized I am unaware of a good chunk of *additional* things engineers on my teams did. Don't assume your manager knows about all the good work you do.
English
Logan retweetledi

We confirm that iOS 16 does communicate with Apple services outside an active VPN tunnel. Worse, it leaks DNS requests. #Apple services that escape the VPN connection include Health, Maps, Wallet.
We used @ProtonVPN and #Wireshark. Details in the video:
#CyberSecurity #Privacy
English





