pyn3rd

974 posts

pyn3rd banner
pyn3rd

pyn3rd

@pyn3rd

Security Researcher. Over 10 years in cloud WAF/ RASP engineering. Focused on cloud security. Speaker at Black Hat, HITB and CanSecWest.

Melbourne, Victoria Katılım Şubat 2016
687 Takip Edilen14.7K Takipçiler
pyn3rd
pyn3rd@pyn3rd·
Does OpenClaw 🦞 plan to ship with native runtime security (e.g., RASP-style detection), or is security expected to be handled via external hardening, isolation, and monitoring?:-) @steipete
English
0
0
1
1.2K
Matthias Kaiser
Matthias Kaiser@matthias_kaiser·
This week is my last week at my current employer. The last few months were quite intense, so after 18 months, I finally made the decision to start working as an independent vulnerability researcher. I wish the company all the best and speedy recovery. 1/2
English
15
3
151
13.8K
pyn3rd
pyn3rd@pyn3rd·
@testanull “What I’m looking for is a poisoned one — the prefix is ORG, not COM. Just a slight difference :-D
English
1
0
1
134
pyn3rd retweetledi
OmerAF
OmerAF@omer_asfu·
👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️
OmerAF tweet mediaOmerAF tweet media
English
12
112
564
61.5K
b33f | 🇺🇦✊
b33f | 🇺🇦✊@FuzzySec·
After 6+ years at IBM it’s time for me to say goodbye! When I joined Adversary Services the team was small, over my tenure it x²’d in size. It’s been an interesting ride, many shells in many places, cool tradecraft and some of the best operators in the business. Now the time has come to take on a new, exciting, challenge! But first, I’m taking an unstructured detour, catching up on some side-quests and touching grass in the real world ✌️
GIF
English
19
5
175
8.5K
SinSinology
SinSinology@SinSinology·
photos
SinSinology tweet mediaSinSinology tweet mediaSinSinology tweet mediaSinSinology tweet media
Português
1
0
35
2.1K
pyn3rd
pyn3rd@pyn3rd·
I had a long chat today with a friend who’s a senior security engineer at Apple.
pyn3rd tweet media
English
1
1
15
2.8K
SinSinology
SinSinology@SinSinology·
photos
SinSinology tweet mediaSinSinology tweet mediaSinSinology tweet mediaSinSinology tweet media
Português
2
0
28
2.1K
pyn3rd
pyn3rd@pyn3rd·
Spending a few days in LA & SF. If you’re around and want to meet up and chat, DM me.:-)
English
0
0
7
2K
pyn3rd
pyn3rd@pyn3rd·
@Y4tacker 对。2种姿势,1.覆盖config.ini,security-level为normal- 就可以,2.直接写一个start-scripts,这不需要
中文
1
0
1
1.9K
Y4tacker
Y4tacker@Y4tacker·
@pyn3rd 只发了利用的Step3 复活CVE-2024的步骤?
中文
1
0
1
2K
pyn3rd
pyn3rd@pyn3rd·
#CVE-2025-67303 ComfyUI-Manager Remote Code Execution
pyn3rd tweet media
English
3
49
325
31.2K
pyn3rd
pyn3rd@pyn3rd·
@GodfatherOrwa This was classified as informational because the feature is experimental and has not been officially released yet.
English
0
0
2
327
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
@pyn3rd Duplicate happens all the time , but why (informational) ? If the original report provides low quality of POC or not fully exploited, then submit a blocker to BC team to send it to the team I found some similar cases before and then triaged
English
2
1
13
1.6K
pyn3rd
pyn3rd@pyn3rd·
First vuln of the new year ✅ First duplicate of the new year ✅ 2026, on to the next one.
pyn3rd tweet media
English
5
0
82
6.6K
pyn3rd
pyn3rd@pyn3rd·
@h3xkatana The context requires a more detailed explanation. The finding was a duplicate, and given that the feature hasn’t been officially released and the issue was already known, it was classified as informational.
English
0
0
1
127
pyn3rd
pyn3rd@pyn3rd·
I understand why it might appear honeypot-related, but it isn’t tied to my report. It’s a generic component with a fairly complex setup. The finding was a duplicate, and given that the feature hasn’t been officially released and the issue was already known, it was classified as informational.
English
0
0
1
142
pyn3rd
pyn3rd@pyn3rd·
@Random_Robbie Nice! Let me know how it goes when you try it out.:-)
English
0
0
1
127
Random Robbie
Random Robbie@Random_Robbie·
@pyn3rd Oooh interesting I've not played with that yet! Making a note to play with it when back in work
English
1
0
1
137
pyn3rd
pyn3rd@pyn3rd·
@Random_Robbie Aww, that’s really kind of her. Glad it turned into a happy ending.❤️
English
0
0
1
96
Random Robbie
Random Robbie@Random_Robbie·
@pyn3rd She's an idiot but the lady whos car she hit came to check on her today and gave her some treats
English
1
0
0
111
Random Robbie
Random Robbie@Random_Robbie·
My dog is an idiot just got hit by a car cause another dog was over the road and we had the door open due to a friend dropping off our daughter. Dog is fine just being sheepish.
English
1
0
1
419