We hacked the AWS JavaScript SDK, a core library powering the entire @AWScloud ecosystem - including the AWS Console itself 🤯
How did we do it? Just two missing characters was all it took.
This is the story of #CodeBreach 🧵👇
Gemini 3.0 just refactored my entire codebase in one call.
25 tool invocations. 3,000+ new lines. 12 brand new files.
It modularized everything. Broke up monoliths. Cleaned up spaghetti.
None of it worked.
But boy was it beautiful.
We accidentally got access to every Academy Award nominee's home address and phone number.
Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors around the world - from @ladygaga to @JaredLeto.
We were interested in the security of award ceremony shows, especially with the rise of @Kalshi and @Polymarket betting on winners. We wanted to check if it would be possible for an attacker to leak the winner before the official announcement.
While we didn't find evidence of that, we did notice that two of the Academy Awards' primary services had their APIs publicly facing without any authentication.
One offered general information about the ceremony, and the other allowed nominees to sign up and vote.
The first one - https://t.co/ddhQbVsYVd - allowed us to fetch every transaction made to sign up as a nominee for the Academy Awards, including member IDs and last four digits of credit cards.
With one request, we could get hundreds of contact IDs which could be chained with another API to correlate them to actual Hollywood actors via https://t.co/O0lrQQpXXR{ID}
Randomly skimming through the results, we saw they leaked full names, home addresses, phone numbers, email addresses of famous Hollywood stars.
We responsibly disclosed the findings to the Academy Awards on January 14th, which were promptly fixed.
Why is no one talking about this?
This is why I don't use an AI browser
You can literally get prompt injected and your bank account drained by doomscrolling on reddit:
I've been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record.
Yesterday, my wallet was drained by a malicious @cursor_ai extension for the first time.
If it can happen to me, it can happen to you. Here’s a full breakdown. 🧵👇
👿 MCP is all fun, until you add this one malicious MCP server and forget about it.
We have discovered a critical flaw in the widely-used Model Context Protocol (MCP) that enables a new form of LLM attack we term 'Tool Poisoning'.
Leaks SSH key, API keys, etc.
Details below 👇
New blog post with @infosec_au:
We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely.
The issue was reported and patched.
Full post here: https://t.co/QPzRIqqx9t
🚨Data Leak - Volkswagen
Volkswagen has faced a major data leak involving sensitive information from 800,000 electric vehicles, including location data and owner contact details.
https://t.co/l5g8vCcyfy
A misconfiguration in the systems of Cariad, VW's software subsidiary, left data stored on Amazon Cloud publicly accessible for months. The exposed information included precise GPS data, enabling detailed movement profiles and linking vehicles to their owners. High-profile individuals such as politicians, business leaders, and law enforcement were among those affected.
Crowdstrike Analysis:
It was a NULL pointer from the memory unsafe C++ language.
Since I am a professional C++ programmer, let me decode this stack trace dump for you.
why the fuck SSL VPN softwares are vulnerable to path traversal in the body lol.
CVE-2024-24919 Check Point Remote Access
https://t.co/hCdjA0RTB3
#infosec#bugounty#cyberattack
I feel like these are backdoors, not bugs LOL
🚨ALERT🚨@GoGalaGames has experienced a security breach!
Attacker has minted 5B $GALA which is around $212M.
Team has announced that "The security incident involving the $GALA token has been contained and the impacted wallet has been frozen".
Attacker has swapped $21.5M to $ETH and rest of the $GALA sits at attacker's address!
Want to keep your company off our alerts radar? Learn how to secure your assets: Book a Demo 🚀 https://t.co/qYomYZUVB1
#CyversAlert
I don’t really care which messenger you use. I just want you to understand the stakes. If you use Telegram, we experts cannot even begin to guarantee that your communications are confidential. In fact at this point I assume they are not, even in Secret Chats mode.
This dude found a kernel RCE on PS5 via the network (!!!). “Heartbleed”-like attack using an ancient bug from 2006. Disclosed via @Hacker0x01 to @Sony. This bug allows 3rd parties to clone games (!), cheat, or APTs to persist by compromising PS5/PS4.
What did he get? $12.5k 🤦♂️
On the .xz backdoor.
It is hard to see how the developer Jia Tan is innocent. The backdoor was added in 5.6.0 by his account. He contacted Fedora to push them to move to 5.6.0. There was a problem with valgrind, they worked with hi to resolve it. He commits the fix in 5.6.1.
PoC Released for SharePoint Pre-Auth RCE Chain (CVE-2023-29357 & CVE-2023-24955)
It can be exploited to achieve unauthenticated remote code execution
https://t.co/uRjXzpnW54