I'm now GNA 119 under CIRCL's GCVE system.
I have authority to assign vulnerability IDs to my own cloud security
findings starting today.
I'm choosing not to.
Cloud finding validation shouldn't be one person's judgment. Forming a
consensus panel of practitioners per cloud platform. Charter coming.
https://t.co/PuDgKSPmlv
Microsoft ridiculed a researcher reporting very serious bugs to them, deleted his account, and no bug bounties were paid. These should be high payouts. Now $MSFT is threatening legal action and speaking as if a researcher’s proof of concept code is illegal.
This is because the unappreciated researcher released more zero-day vulnerabilities on his own and had those GitHub/Lab accounts banned.
They were serious enough that Microsoft is scrambling to fix them but wasn’t serious enough to be paid or recognized, instead was ridiculed.
News of the Nightmare Eclipse exploits are everywhere but read the personal blog of the researcher, Nightmare Eclipse:
https://t.co/SuSxBr5oT4
Decentralized identity verification via Keyoxide. This hash cryptographically proves I control this Twitter account, my Mastodon (@[email protected]), and my PGP key — without trusting any central authority.
Verify: https://t.co/OHg4xVTX9T
Confused deputy is everywhere in cloud infrastructure if you know how to look.
Wrote up the full methodology — taxonomy, diagrams, CLI enumeration, 10-question hunting checklist.
#cloudsecurity#infosec
MITRE TL-Root just ruled. No CVE.
CERT/CC's system: "1 Vulnerability Identified"
CERT/CC to MITRE: "We never validated it"
Microsoft described the exact behavior they patched while calling it "intended."
I followed every rule. The system worked exactly as designed.
Full MITRE decision on my page: https://t.co/JZPdmdfw06
MSRC silently rolled out a custom, cluster-wide code modification specifically tailored to break my exact exploit primitive, all while insisting "no product changes were made". Bespoke customer service right there.
Researcher @olearysec found privilege-escalation vuln in Azure Backup for AKS and reported to @microsoft. CERT validated it but Microsoft rejected it and asked Mitre not to give it CVE. Then he says Microsoft silently patched it without telling users https://t.co/CL1Jn8vyKL
No CVE? No problem.
@MSFTSecResponse won't give it a CVE but @BleepinComputer will give it a headline.
Article: https://t.co/WprSC4Erce
Video: https://t.co/zxFFAhfr0F
cc @Ax_Sharma