Our security team at @YSecurity has identified multiple vulnerabilities in TIM BPM Suite/TIM FLOW, allowing authorization bypass, privilege escalation, and SQL/HQL injection.
Advisory + Mitigation: https://t.co/8hQFq0wn2s
Giving away one ticket for German OWASP Day 2025 incl. hotel night! 25.11 pre-event, 26.11 conference. Interested? Email us – first come, first served. Info: https://t.co/ZTAWzrSvkv Already have a ticket? Meet the Y-Security team on site. #OWASP#GOD2025#GOD
Our security team at @YSecurity has identified a vulnerability in AXESS Auto Configuration Server (CVE-2024-56316) which allows unauthenticated remote attackers to trigger a permanent DoS.
Advisory + Mitigation: https://t.co/6P23JaVskn
#YSecurity#CVE202456316#TR069#ACS
We have publicly released our internal tool StealthGuardian at Black Hat USA 2024.
It can be combined with adversary simulation tools to verify the resistance, detection level and behaviour detection of defence mechanisms.
https://t.co/QzlnzvmAAS
#bhusa#blackhat#redteam
Wir suchen derzeit zur Unterstützung Werkstudent:innen im Bereich Anwendungsentwicklung.
Wenn du Lust auf ein innovatives Unternehmen mit flexiblen Arbeitsmöglichkeiten hast, dann freuen wir uns, von dir zu hören.
#Werkstudent#Job#Germany#Business#Development
Are you taking steps towards a career as an Attack Simulation Specialist?
Maybe you already have experience as a Penetration Tester or with platforms like Hack The Box or certifications like OSCP?
If so, we would love to talk to you!
#job#redteam#pentest#germany
Our tool StealthGuardian has been accepted for Black Hat ARSENAL USA 2024. The Y-Security team will be in Las Vegas to present on protecting Red Team payloads from Blue Teams.
https://t.co/2yV075y5Pj
#BlackHat#BHUSA#RedTeam#VegasBaby
Our team recently took the challenge of mastering the Red Team Ops I and Red Team Ops II exam offered by @zeropointsecltd . After completion, we received both the Red Team Operator and Red Team Lead certifications.
Read our recent post: https://t.co/fAeTOhkHgv
#RedTeam#RTO
Recently we checked the security of a LoRaWAN implementation. In our latest post we share insights about the security of LoRaWAN, common LoRaWAN attacks and how we built a custom methodology and testing environment.
https://t.co/z5vyADDsyf
#pentest#lorawan#ysecurity
We have moved our twitter account to @YSecurity - All our new content will be available here. Followers have been moved to the new account. Thanks for following @YSecurity
Y-Security carries out projects in a climate-neutral way. Companies that work with Y-Security have the option of taking over a share to offset the CO2 produced in our projects too.
We have just claimed 2,98 tons CO2 via @compensatorsNGO
https://t.co/1HIbHWpJF4
#climateaction
Looking to strengthen your cloud security and safeguard your data from cyber threats?
Then don't miss our latest blog post about the Advantages of Cloud Audit and Cloud Penetration Testing: https://t.co/vPJrYECHSY
#cloud#cloudsecurity#bugbounty#Y#penetrationtesting
Have you ever wondered how to start #AWS penetration testing? We have published AWS penetration testing: A step-by-step guide at the @hackthebox_eu website:
https://t.co/EBaX3GqZXV
#HTB#BugBounty#Y#Security#Cloud
@hackthebox_eu 's BlackSky Cloud Hacking Labs doesn't only include AWS and Azure, but also Google Cloud Platform.
Read Sven's feedback and insights on the Blizzard: Google Cloud Platform scenario at: https://t.co/lQLVgckDKb
#HackTheBox#GCP#Blizzard#BugBounty#htb#pentest#Y
Have you enjoyed our last week review on @hackthebox_eu's BlackSky Cloud Hacking Labs for AWS?
Our team member Thore shared his feedback and insights on the Cyclone: Microsoft Azure scenario at: https://t.co/QBApGVi1eN
#Y#HackTheBox#Cloud#Azure#Cyclone#BugBounty