Just released a blog post "Deanonymizing Users at Scale: When Blocking Becomes an Oracle".
In it, I describe an attack that made it possible to reveal the phone number of almost any user on one of the world’s largest social platforms:
https://t.co/CuTMMmm1X0
🎉Announcing the latest research from our intern @maikypedia! In it, you'll learn all about Decompression Attacks, get to practice in custom-built labs and get some free @semgrep rules for detecting flaws. Check it out today!
https://t.co/we46rcyptw
#appsec#doyensec#semgrep
New blog! This time a high severity session takeover in Zoom worth $15,000. Read the story of how @sudhanshur705 , @BrunoModificato and I chained 2 completely useless XSS vulns to steal OAuth tokens, hijack browser permissions, and more:
https://t.co/qVUgk5shqh
I'm thrilled to announce "Listen to the whispers: web timing attacks that actually work" will premiere at Black Hat USA!
After nine months of running bulk timing attacks on thousands of live sites, I've got a lot to share :D #BHUSA@BlackHatEvents
https://t.co/YsrfM0SUm7
A public service announcement about #CVE-2024-4367 that we found in one of our pentests at Codean Labs. Make sure to update your #Firefox version to 126 and for #developers to update your PDF.js dependency. You can read our blog post for all details.
https://t.co/4hJ0kSh87r
Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server:
https://t.co/jmjTTOxEGY
Just published a writeup on my account takeover vulnerability in ChatGPT, using a really cool web cache deception technique. Waited a while to finally publish this, enjoy :)
https://t.co/P1vHoSzABX