Our team participates in public bug bounty programs to sharpen our vulnerability research skills.
We recently looked at Firedancer, a blockchain validator client, and found a remotely triggerable vulnerability.
https://t.co/7hi19uyWDB
Congrats to security researcher Liork (@LucidBitLabs) for earning $50,000 from a blockchain/dlt High vulnerability.
They're now ranked 83rd on the all-time leaderboard.
Pledge IMU behind them so that when they find new bugs and increase their rank, you both get IMU rewards.
https://t.co/ZOO3mHfEwp
I'll be speaking at the Infrastructure & Ops Superstream: Securing your Kubernetes Clusters from Known and Unknown Weaknesses.
Tomorrow! Sept 6 11am EDT
Sign in, or sign up for your free trial: https://t.co/JCpl7GzWTS
In part one of our series on the reemergence of TeamTNT, we provided an overview of the preliminary stages of an aggressive botnet campaign aimed at cloud-native environments. ☁
After further research of the novel #TeamTNT botnet, Aqua Nautilus has discovered an unprecedented scan rate of the entire internet every hour and a staggering infection rate of at least 1 victim per hour. 🤯
If you are using docker, k8s, redis, hadoop, ssh, or jupyter we strongly encourage you to check out these new findings. 🔎
https://t.co/2v5m5OAqvn
@ofekitach@MoragAssaf
Another Master student flew through the thesis defense at @TelAvivUni with flying colors: @EilatLevAri had presented her thesis: Product Managers' Role in Incorporating Values into Digital Products. Thanks to @DanKotliar and Joachim Meyer for evaluating the thesis
🚨 Aqua Nautilus researchers have discovered a new elusive and severe threat known as HeadCrab that has compromised a large number of Redis servers.
📖 on for details of the attack and steps organizations can take to safeguard their systems.
https://t.co/9pIVpyH6ZD
Our SVP of Strategy, @ranio1, recently sat down with @ashimmy to chat about where the security market is headed, #CNAPPs as an important emerging security category, and why Aqua was named the Best Cloud Native Security Solution/Service at the #DevOpsDozen
https://t.co/etN2t0W8Xq
In 2023, personal #data is being generated at an unprecedented rate.
In this issue of @cybersec_mag, Assaf Morag of Aqua Nautilus and other experts share their insights on how to best protect your data. ☁ 🔒 @MoragAssaf
https://t.co/1pYFzG76sW
Super proud of lab member Assaf Morag, who presented his Masters research, "SamPass:
Secure and Memorable Password Recommendation System". Assaf had presented a recommendation system that helps users improve their passwords with massive leaked account datasets
CVE-2022-0847 “Dirty Pipe” is dissected and analyzed very well by Alon Zivony / Team Nautilus @AquaSecTeam in this writeup. https://t.co/VXpmDgzoIi
Happy to announce that our paper, “Can Previews Mitigate the Effect of Interruptions? Findings from a Lab Experiment under Various Workloads”, was accepted by the International Journal of Human-Computer Interaction -- paper by @frankbolton, Dov Te'eni and I, all from @TelAvivUni
I’n the past couple of months I worked at @AquaSecTeam on a cool project that target hunting kernel rootkits with ebpf.
And today one of those techniques came public with a nice blog that introduces tracee’s new detection event.
Hope you’ll enjoy it
https://t.co/CSakmP75eT
Aqua's #TeamNautilus created a honeypot to better understand how adversaries are exploiting the initial #Log4j vulnerability (CVE-2021-44228) in real-world attacks.
Read on to learn the key findings from their research: https://t.co/G0QnJzyjkQ
Read about Aqua’s exciting new addition of cloud native detection and response (#CNDR) capabilities to our Cloud Native Application Protection Platform (#CNAPP)!
https://t.co/gnd73d6A0F
What was the effect of Israel’s decision to use mass surveillance of cellular phones for COVID-19 contact tracing? @oshratayalon and I uploaded a new manuscript to arxiv that analyzes the relationship to the installation of the more accurate app
https://t.co/s6645gg4F5