🏴☠️ I can finally share a VMware 0day I discovered that led to CVE-2026-41702 (LPE as root). Funny enough, I found the bug in my hotel room after the second day of attending Csaba Fitzl (@theevilbit) & Gergely Kalman (@gergely_kalman) training at Zer0con.
https://t.co/mG55Ksc4gE
@CynicLib@merill Hmmm, AppRegistration credentials can be used to authenticate in every tenant it has a ServicePrincipal (multi tenant app scenario). A MI as FIC and no creds needed anymore :D. But maybe that break your security policies. It’s not very elegant but solves your 0 credential goal
Claude Code 4.7 is insane.
i know literally NOTHING about coding. ZERO. and i just built 3 fully functioning web apps in 30 minutes.
http://localhost:3000/
http://localhost:8000/
http://localhost:5000/
check it out.
My new blog post is released. It explains in detail how applications (App Registrations, Service Principals, MI) and their permissions really work, why they can introduce several subtle paths for privilege escalation, and presents my open-source tool designed to uncover them.
Do you know how Entra ID applications work?
What about the security mess they can bring and what they can quietly break?
New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool built to make sense of it:
https://t.co/MkWdsuqF0Z
Do you know how Entra ID applications work?
What about the security mess they can bring and what they can quietly break?
New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool built to make sense of it:
https://t.co/MkWdsuqF0Z
Rise and shine, it's @GrehackConf time! Doors should already be open and at 9:10 we kick off with Nicolas Kovacs and Sébastien Rolland and their talk Google Apps Script: This Talk Requires Access To Your E-mails.
They ain't getting mine...hopefully...
WhatsApp has been using the microphone in the background, while I was asleep and since I woke up at 6AM (and that's just a part of the timeline!) What's going on?
Today with @lestutosdenico we presented Google App Script and several different scenarios in order to possibly exfiltrate data from enterprise which use Google Workspace at annual @quarkslab conference; Quarks in the Shell. Was a great day 👌
The @EuCyberCup, the first eSport competition dedicated to ethical #hacking during the #FIC2023 (International #Cybersecurity Forum), will start in a few minutes ! Our team is setting up and preparing for these two intense days ! Stay tuned ;-)
Microsoft OMI is an open source systems management framework for Linux and UNIX used on-premise and Azure. In this blog post @blindevy and @mtardy_ give a brief introduction to it and tell us how they found some bugs while fuzzing the project. #omi#Azure
https://t.co/wJFSed9REz
Do not get stuck trying to understand container specifications!
Here is a blog post by @cryptonitemmk that dissects the OCI Image Specification with practical examples and hints 😉at why it is Not A Good Idea to leave any secrets in them
https://t.co/mtrWom6T37
Our 2022-2023 internship season is open! Looking for a 6-month immersion in a top-notch security research environment? Searching for final answers to "pain au chocolat or chocolatine", "emacs or vi"?
Check out these other important topics & apply soon
https://t.co/6NI7jnm6Ib
@GanPatrimoine quelqu’un s’intéresse à la sécurité de vos comptes clients en interne ? Aucun point de contact trouvable pour remonter les problèmes de sécurité et personne ne me répond via le formulaire de contact avec 48h. J’ai une vulnérabilité à vous remonter 🤷♂️