Just completed a CTF challenge in #TheUltimateCloudSecurityChampionship by @Wiz_io 🥊 Put your cloud security skills to the test in this monthly series and join the competition https://t.co/GvCpN0CTQL
Had a fun time with the Google Security team yesterday, got to see a lot of innovative things they are doing to keep users safe.
Definitely want to look into scalibr when I get back home .
Excited to see what #defcon33 has to offer today!
Don't always have time to hack and the reports don't always turn out in my favor, but it's fun when they do!
Just got a reward for a critical vulnerability submitted on @yeswehack -- Insecure Storage of Sensitive Information (CWE-922). #YesWeRHackers
I recently had the opportunity to speak @fwdcloudsec in Arlington, VA alongside some amazing people. My talk leveraged research published by Sam Cox and Ben Bridts that allows anyone to discover the AWS account ID of any S3 bucket. I go into detail of what I did (and any attacker could do 😉) with this information.
I've even been able to send in a few #BugBounty reports with some of the data I've collected.
https://t.co/lSFyug7bbE