I’ve spent the last 2 years at @Tanium, best job I ever had. But resource realignment happens, and I am seeking a new opportunity. I am a security innovator, to the extent that nearly every computer on the Internet is using at least one of my technologies or inventions.
1/n
Our blog post with full technical details about the two vulnerabilities in the TPM 2.0 reference implementation discovered by @fdfalcon is now live at
https://t.co/7aeuTPkVTC
#TPM#0day#not0day
Quarkslab @fdfalcon discovered 2 vulns in the TPM2.0 Reference Implementation. They affect many hardware, software and firmware TPMs. The Trusted Computing Group and CERT/CC issued security bulletins. Stay tuned for our technical analysis on March 14th https://t.co/pVHrVB8psQ
I solved the Blue Frost Security linux kernel challenge they published for Ekoparty 2022 and loved it! @bluefrostsec
Here's my writeup: https://t.co/C0hi6UAr0N
During last year's #BlackFriday promotion, half the internet bought a Burp Suite Certified Practitioner exam but mysteriously got cold feet about taking it. We feel really guilty about taking your $10, so this year we have a new deal: you prepare, we pay:
https://t.co/Bia8bFrKJB
1995: PHP is dead, learn ColdFusion
2002: PHP is dead, learn ASP.net
2003: PHP is dead, learn Django
2004: PHP is dead, learn Ruby on Rails
2010: PHP is dead, learn Flask
2011: PHP is dead, learn AngularJS
2016: PHP is dead, learn Next.js
2022: okay this is awkward
@dragosr@robertgraham Not sure if it has been mentioned already, but shellshock comes to my mind. Even if your Apache was updated, the underlying problem was inside bash. Maybe Rob considers that you are exposing bash by enabling CGI, but there are tons of software features that work like that.