It’s really funny watching companies learn things like patching at high velocity isn’t a cybersecurity silver bullet
The state of cybersecurity is so bad in tech today, they’re recreating defense in depth from first principles
This is my favorite climate change chart. Japanese monks, aristocrats, and emperors kept meticulous records of cherry blossom festivals for 1,200 years and accidentally built the world's longest climate dataset.
New blog post: Breaking SAPCAR! 🪓
@Anvil_Secure's Tao Sauvage shares new research on four local privilege escalation bugs in SAPCAR’s SAR parsing. A great example of the deep, methodical work we value at Anvil.
Read it here: https://t.co/kJfhxedD9k
#infosec#SAPSecurity
@dhh Because the annoyance with software that looks amazing but is unusable is infinitely worse than the annoyance with software looks ugly but is efficient
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
@_dirkjan@bookingcom This has been going on for months and @bookingcom does not seem to care about it. Made the news in several countries already, e.g. https://t.co/C33Z9X7tvE