Senior Security Consultant @ Reversec (fka @withconsulting / MWR).
Talks mostly about security.
As Rino put it, sometimes maybe good sometimes maybe shit
Bookmarked. Nice to have a db for all these vulns never assigned CVEs.
(Randomly found through this, which actually looks like a very interesting read)
https://t.co/YBnWUf96UR
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation https://t.co/i08oDU55QA
When researching a topic, I prefer watching conf talks because speakers have (usually) done their lit review, and point to other sources too.
But search engines, LLMs, and even YT's search are all crap at finding relevant talks. Missing tons.
This will be a good place to start
Cool site to watch all BSides talks! 👉 https://t.co/EywKZvELJk
If you've got nothing better to do, you can watch my contributions on there as well:
https://t.co/uBXbmRSmc8
@ipurple Hey Panos,
I think https://t.co/ZEsDdUSR36 deserves a spot in this list. I'm biased but you'll see yourself that we've been posting non-stop, very frequently, for around 20 years, with the current name and all previous ones (WithSecure, F-Secure, MWR)
Some pretty dodgy stuff possible using undocumented APIs... MS says "works as intended"... portal shows nada... Admins left scratching their heads...
It's @chrispy_sec back at it again with another Entra Persistence trick 🕜
If you're curious to see how you can backdoor conditional access policies by using a legitimate hidden condition then have a gander here:
https://t.co/PcS4spbfCA
This was a very interesting read.
"In 40', the conversation moved from “I’m not going to create that file” to
“What command do you want to execute now?” on a live government server"...
https://t.co/agauPXSd4T
Going to be dropping a new blog in due time 😉 next week Tuesday.
This will be a fun one for all the Entra people that follow or get this trickled through their timeline so keep an eye out! Useful info for offensive folk and also people wanting to keep their tenant safe
For many years, I've joked that, technically, nothing is stopping anyone from implementing PacMan inside of an iOS keyboard.
Thanks to some free Claude Code credits, this very important dream is now a reality.
https://t.co/gSHfj33sdC
New blog post out:
We built an AI Vishing system in 7 days to show that Scattered Spider's helpdesk campaigns can be automated at mass scale, easily.
(clip included 🔊)
https://t.co/KldyPacSVu
Let’s turn gclifix into an RFC..
After decades of every CLI tool inventing its own bracket prefixes, such as [*] ( or [+] ) meaning success here, error there, progress somewhere else, I decided to write the standard that should have existed all along.
The draft-fragkos-cliprefix-standard-00 defines "gclifixes": 56 event prefixes and 9 context prefixes for CLI output and logs. Three characters, fixed position, human-readable and machine-parseable.
The full introduction document is already submitted as an official Internet-Draft (I-D) and can be found the IETF website here:
https://t.co/6q3w7AlIil
See also the additional analysis document:
https://t.co/aPCKObnKGT
In addition, I also compiled the attached PDF, to briefly showcase all aspects, the extend, and overal impact this rather simple approach, can have.
Why now? Because LLMs are generating CLI tools at scale; each independently inventing output conventions. A canonical reference means every generated tool emits consistent, interoperable output. Consider it as "the Markdown of Logging".
A reference implementation exists (PowerShell modules with keyword auto-detection, 8 accessibility palettes, and full colour mapping), and the draft has received positive feedback.
Call to Action; I seeking your help with two things:
1. The RFC process: this is my first IETF submission and it was a lot of work but, there is more to go until it becomes an officially adopted RFC. Kindly, if you have experience with IETF working groups or know someone who does, I'd welcome guidance or an introduction for guidance.
2. Visibility: if this idea resonates with you, a share helps it reach the people who can move it forward.
The spec is free, the concept is simple, and the problem it solves is one most of us have quietly lived with for years. Especially now that has the ability to bridge a gap between human and machine.
Happy to discuss any aspect of the design. Some of those decisions were more interesting than they might first appear.
#gclifix #IETF #InternetDraft #RFC #CLI #stdout #logs #standards #DevOps #AI #LLM #developer
❗️A hack at one of Europe's biggest football clubs Ajax made it possible to steal season tickets, attend matches, and even lift stadium bans.
RTL news found you can see which 500+ supporters are banned from the stadium and remove their bans...
Revealed by @danielverlaan
In his latest research, @MGrafnetter looks at Okta attack paths, and where they actually show up.
Not in Okta itself, but in everything connected to it. With OktaHound you can map that in BloodHound.
Check it out! https://t.co/jYHB9N894s
Infosec hive, if you're in London and keen to put them skills to good use, @CyberpeaceInst will be hosting a chill IRL meetup this Friday🍻
Come join us and find out what it's all about
https://t.co/FlBBf7eZVh
@__noided Indeed, VAPI like Twilio and the ElevenLabs telephony feature were nice and simple.
Just didnt seem possible to spoof caller ID (and leverage the legit CNAM) which I needed for my scenario (business impersonation) as it increased perceived legitimacy from before even saying Hi
New blog post out:
We built an AI Vishing system in 7 days to show that Scattered Spider's helpdesk campaigns can be automated at mass scale, easily.
(clip included 🔊)
https://t.co/KldyPacSVu