New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
The exploding Hezbollah pagers situation is an incredibly impressive supply chain attack by Israel (most likely). I am sure more details will come, but there are already some educated guesses to be made that narrow it down.
🧵1/n
D'oh, so you leaked your AWS credentials 🤦♂️ Does it matter 𝐰𝐡𝐞𝐫𝐞?
It turns out there's a HUGE difference in how fast attackers will find them.
Idan Ben Ari deployed canary tokens (fake AWS credentials) using @ThinkstCanary to a number of different locations and analyzed:
- How quickly they were accessed.
- Where were they accessed from (IP).
- User agent, etc.
📊 Results
NPM: <1 min.
PyPI and GitHub: ~2 minutes
Pastebin ~1 hour
Web server ~2 days
DockerHub ~7 days
BitBucket and GitLab: …never.
https://t.co/SmVHf1LcBA
Big thanks to @offsectraining's UGC program for kickstarting my journey! 🚀
- How it started: Built vulnerable machines, earned OSCP, and joined OffSec as a VM Engineer
- How it’s going: Still building & breaking boxes! 🔥
Grateful for the ride and excited for the future! 🙌
We are thrilled to celebrate the tremendous success of our UGC program and share some exciting milestones we have achieved along the way: https://t.co/2sgsSoH9my
Decided to start an IoT hacking blog!
The blog will be featuring the best projects from my YouTube vids. First post details the reverse engineering of the VStarcam CB73 security camera.
https://t.co/NROZuhH7sF
We slipped one of these in the bags at @BSidesJoburg this weekend because we are looking for amazing support engineers (to join our amazing support engineers).
"If you’re driven by a commitment to excellence with impeccable attention to detail, you need to join us"
Join us!
I'm excited to be selected as a Subject Matter Expert by @hackthebox_eu, sharing insights to help over 2 million professionals learn and grow.
Thank you, HTB, for this incredible opportunity!
#Cybersecurity#HackTheBox
After that excellent first Hacker Mixer, I am organising one more on 10th July (Wednesday) in Hyderabad.
Hackers in Hyd, go ahead and register.
https://t.co/onTA1Xcgjl
RequestTinter: workflow that applies color tints to in-scope HTTP requests, making it easier to identify them based on their respective methods.
https://t.co/C43wqfdQBA