Led by our experts, this hands-on, intermediate training flips the script on DevOps security ๐ Register now for "Supply-Chain to Runtime: Attacking & Defending the Modern DevOps Stack" at @BlackHatEvents 2026. See you in Las Vegas!
#BHUSA
https://t.co/TuJToeFX40
Since we're sharing MSRC stories: a few months back I gave them an Azure Sign-In logging bypass.
They said it was no biggie, as it merely allows attackers to bypass the logging that every admin relies on. Doesn't meet the bar.
Fixed in record time. No recognition. No bounty.
The amount of stories like this I have heard as well is why I concur with @curi0usJackโฆ like wtf did they expect? hacker gonna hack and all that ๐คฃ
Last time I dealt with MSRC.
Responsibly disclosed an issue with legacy auth that allowed me to spray passwords at <redacted endpoint> and avoid smart lockout.
Receives email.. 5 months after initial case opening.
โDoesnโt meet the bar for servicingโ
Microsoft silently fixed. Closed case.
https://t.co/9iFpMJMSXC
I've heard nothing but horror stories about those submitting to MSRC, so it's no surprise that this would be the fallout. Personally, I find this post hilarious.
https://t.co/AZR5jwc9hg
Off-topic post, but some wonderful friends of our just welcomed their first child into the world. His name is Wilder. He was born with Down's and has already had multiple heart surgeries. He has been in the NICU for weeks.
I realize the economy is pretty difficult right now, but any pennies you could spare would be greatly appreciated by the couple (they are farmers; money is tight). Thank you kindly.
https://t.co/QC7aoaBpSr
OnlyFans is Hacked ๐จ
Apparently OnlyFans has been hacked and they're selling the complete database of 340 million users
including data of content creators and consumers.
The leaked data includes
- Usernames and profile names
- Email addresses
- Phone numbers
- Account creation dates
- Follower/subscriber metrics
- Creator/fan rankings
- Linked social media profiles
- Partial payment card metadata (last 4 digits of the card)
The result of this is going to be a massive wave of extortion attempts against users
We'd like to thankย TrustedSec researcher Christopher Paschenย (@freefirex2) for sharing the details and their proof-of-concept, which allowed us to create a patch for Windows users who are no longer receiving official Windows patches.