Mohammed Diaa

981 posts

Mohammed Diaa

Mohammed Diaa

@mhmdiaa

Build things, break things, build things that break things

Katılım Haziran 2016
970 Takip Edilen1.4K Takipçiler
Mohammed Diaa retweetledi
Bryan Onel
Bryan Onel@BryanOnel86·
A year ago, we had product–market fit. Today we have something harder to build: a GTM machine. This was the biggest quarter in Oneleet's history. It wasn't one whale, and it wasn't luck. It was the unglamorous work we started right after Series A: - Hired AEs and built them a playbook - Turned on paid acquisition for the first time and measured it scientifically - Built GTM engineering so growth doesn't depend on me. None of that existed a year ago. Every month since has been bigger than the last. We've been hitting 7-figures in ARR added each month as a result. And here's what I want people to understand about this category: compliance gets you in the door, but security is the product. Anyone can automate a checklist. We put a real security team behind it, because a SOC 2 that doesn't actually make you safer is just paperwork with a badge on it. The market is waking up to that difference. We're not slowing down.
Bryan Onel tweet media
English
10
7
40
3.6K
Mohammed Diaa retweetledi
Nate
Nate@nnwakelam·
It’s fascinating to me to see a cultural gap between existing computer hackers and bug bounty hunters and people that simply had no ability to surface vulnerabilities in companies meaningfully before LLMs made it as easy as asking a question. Feeling justified dropping an unfixed vulnerability on a company with little or no security posture on Twitter just signals to anyone that’s an adult that you are probably a dumbass. It’s optimising for attention rather than impact. You can report this to the CERT in the relevant country and move on with your day, posting it on Twitter is entirely self-serving and disingenuous. There’s a real decoupling of several things at play, in order to find issues of substance it actually conferred skill (and most likely intellect and critical reasoning skills) and now as that rising tide has lifted all boats you are going to get more and more people that can surface the issue but don’t understand the customs surrounding how vast swathes of this industry function.
English
19
26
296
26.2K
Mohammed Diaa
Mohammed Diaa@mhmdiaa·
This isn't even an "AI can't be held professionally accountable" or "that's not how red teaming works" take. Even ignoring all that, if your goal is to throw random open-source tools at a target and hope for the best, a shell script would genuinely do this better
English
0
0
0
45
Mohammed Diaa
Mohammed Diaa@mhmdiaa·
Do people watch these demos before reposting them? The video shows the tool fumbling every step of the way It googles "how to automate vulnerability scanning", tries (and sometimes fails) to install random tools, hallucinates commands, and can't access its target for 20 minutes
Mohammed Diaa tweet mediaMohammed Diaa tweet mediaMohammed Diaa tweet mediaMohammed Diaa tweet media
English
1
0
0
296
Mohammed Diaa
Mohammed Diaa@mhmdiaa·
Just released AcquiScan, a tool that extracts acquisition and subsidiary information from SEC filings by parsing structured filing exhibits or using an LLM to analyze unstructured filing documents github.com/mhmdiaa/acquis…
English
1
0
3
237
Mohammed Diaa retweetledi
James Kettle
James Kettle@albinowax·
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
English
19
241
745
86.8K
Mohammed Diaa retweetledi
Trickest
Trickest@trick3st·
ToolShell coverage has been all over the place. We held off publishing until we could reconcile the discrepancies between the original exploit reports, Microsoft’s advisories, public PoCs, and vendor writeups. Appendix breaks down the CVE mixups and variant exploits
Trickest tweet media
English
2
2
6
882
Mohammed Diaa retweetledi
s1r1us
s1r1us@S1r1u5_·
Hacking Windsurf: I asked the AI for the shell, it said yes. new video’s out. I show how I could’ve hacked you… just by getting you to click my link. Link posted below.
s1r1us tweet media
English
19
76
411
67.4K
Mohammed Diaa retweetledi
James Kettle
James Kettle@albinowax·
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓↓↓
James Kettle tweet media
English
29
102
613
87.7K
Mohammed Diaa retweetledi
Trickest
Trickest@trick3st·
Subdomain DNS brute force isn't just blasting "word + domain" DNS queries Here are six common pitfalls and how to avoid them:
English
1
21
99
14.3K
Mohammed Diaa retweetledi
­Mathias Karlsson
­Mathias Karlsson@avlidienbrunn·
I made a tool to help test archive (zip/tar) extraction bugs (synk working directory into archive, add path traversals, links, permissions, etc): github.com/avlidienbrunn/…
English
2
31
179
19.4K
Mohammed Diaa retweetledi
Trickest
Trickest@trick3st·
Trickest CLI v2.0 is out! This update focuses on turning the workflows you build into production-ready processes that feel intuitive and are easy to monitor. Let's break it down 👇 (1/7)
English
2
4
5
633
Mohammed Diaa retweetledi
Joseph Thacker
Joseph Thacker@rez0__·
I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a reference of all of the ways that you can hack AI. It has saved me hours. Bookmark this if you need a reference for what all to try (AND includes mitigations).
Joseph Thacker tweet media
English
73
726
4.4K
340.7K
Mohammed Diaa retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
Introducing MSFTrecon - MSFTRecon is a reconnaissance tool designed for red teamers and security professionals to map Microsoft 365 and Azure tenant infrastructure. It performs enumeration without requiring authentication, helping identify potential security misconfigurations and attack vectors. github.com/Arcanum-Sec/ms…
JS0N Haddix tweet media
English
23
286
1.1K
64.1K
Mohammed Diaa retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)! Link 👇 mizu.re/post/exploring… 1/2
English
4
102
359
37K
Mohammed Diaa retweetledi
James Kettle
James Kettle@albinowax·
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10-w…
English
7
65
272
140.7K