The Randori Attack Team developed a working exploit for #f5 BIG-IP CVE-2022-1388. To help the #infosec community assess their risk, we published our technical analysis and a bash one-liner that organizations can run to test exploitability. Details here: https://t.co/4ovFJhUvuz
Another awesome season with @NationalCCDC has come to an end. It has been an honor working with @HECFBlog and the rest of the @CCDCRedTeam crew over the years.
https://t.co/rsFPI7OfnL
Does your org have an understanding of its External Attack Surface? If the answer is yes, how often are you validating that? The data from @RandoriSecurity suggests most organizations don't know or validate often due to the cost of the validation activity
https://t.co/jTWh9pK5VT
Starting at 1030 EDT, I'll be emceeing the attack surface management forum with @RandoriSecurity. We'll be joined by @thegrugq for a *fantastic* presentation on cyber warfare, specifically discussing Ukraine and Russia today.
Join us!
https://t.co/jTWh9pK5VT
The following non-malicious request can be used to test susceptibility to the @springframework 0day RCE. An HTTP 400 return code indicates vulnerability.
$ curl host:port/path?class.module.classLoader.URLs%5B0%5D=0
#SpringShell#Spring4Shell#infosec
@bbaskin That is pretty impressive Brian! Just from a Math standpoint and all. You indeed are a thought leader so I could see this result happening. So, big question is: Is this badge also an NFT or no.... ? ;)
New high severity DoS in OpenSSL just released: https://t.co/3ZoLlRIlQB CVE-2022-0778 was reported by @taviso and appears to affect systems that parse user-supplied certificates.
We’ve just posted a vulnerability researcher role: https://t.co/pKPhI3g2WF Come join us writing exploits and doing zero day research for use in our automated red teaming platform!
Getting into the #haxmas spirit, I have three copies of the awesome @nostarch@humble I'm going to give to followers. RT to help get the word out. Like to enter.
I'll DM the download link to the winners Monday.
#Hacks#Holiday#Redteam#Blueteam
https://t.co/3va49WERzr
The Randori Attack Team can confirm exploitability of VMWare products in live environments (VMSA-2021-0028) via Log4j (CVE-2021-44228) aka "Log4Shell". This is a critical vulnerability. Follow @RandoriAttack for updates: https://t.co/3V12TcuK27 1/3
The Randori Attack Team has developed a working exploit and has been able to successfully leverage this vulnerability. Check out our analysis here:
https://t.co/3V12TcuK27
This is the kind of work the team at @RandoriSecurity does that only make the product, platform and the security community and other products better. Join us to help do more! https://t.co/lc1Yi5hoSq
Announcing CVE-2021-3064: a CVSS 9.8 unauthenticated RCE in @PaloAltoNtwks GlobalProtect VPN devices discovered and disclosed by @RandoriSecurity. Read on for our advisory and stay tuned for further technical details. https://t.co/18JGQnrBsm
Never one to shy away from a tough discussion, @HexadeciMoose details why we use #zerodays at Randori and why we feel they must become a more integral part of security testing: https://t.co/0f0w4pn6Yy #infosec
Follow @RandoriAttack & @RandoriSecurity to keep up with publishing of this advisory. The work @RandoriAttack does is what makes the Randori platform & capabilities so effective. They take apart and build some very interesting things. Join us! https://t.co/lc1Yi5hoSq #infosec
Last year we discovered an unauthed remote code execution vulnerability in a leading firewall and began exploiting @RandoriSecurity customers. Tomorrow we'll be publishing an advisory for the Critical CVSS 9.8 flaw in coordination with the vendor. Follow for updates.
Scoop —> Cybersecurity researchers, with the help of the NSA, are exposing a suspected foreign hacking campaign that has targeted multiple US defense contractors. https://t.co/HqlSraBKky
SCOOP - And a wild one…
Fraudsters used “deep voice” tech - as in deep fake for speech - to clone a company director’s voice.
They then convinced a bank manager to send $35 million to various accounts across the world.
AI-powered cybercrime is big.
https://t.co/4MERyCOG9g