@HWB_HSF@KLA_HWB@Zetunz@_SaxX_ Bonjour @HWB_HSF , @KLA_HWB , @Zetunz , @_SaxX_ ,
Comme convenu et à votre demande suite à nos échanges par mail, voici votre article. Nous restons en contact pour le service après-vente : droit de réponse et de réhabilitation (si étayé) sans limite.
https://t.co/2GQteHqcFB
I wrote this to try to bring some reality to people trying to break into cyber. People will disagree with some (all) of it but hopefully somebody benefits from what I saw when I worked as a pentester.
https://t.co/LJaa7aA1Ty
"Exposed Swagger API docs can reveal all endpoints!🔍 Use URLs like https://t.co/Cg5WGpZ8kI<target_domain> to find unsecured endpoints.
#bugbountytip#infosecurity
"The WebP 0day" -- a full technical analysis the recently patched vulnerability in the WebP image library that was exploited in the wild (CVE-2023-4863). https://t.co/6yUcE9sOZa
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
My talk "What I Wish I Knew Before Pentesting AWS Environments" for SANS Pen Test Hackfest 2022 is now on YouTube! Check it out if you're interested in learning more ways to attack AWS environments.
https://t.co/upIxAvBhy9
I'm getting back into cloud vuln hunting in my free time and wrote up a short post on some concepts and ideas I've been thinking about lately. This post is on the potential attack surface of the AWS API protocols.
https://t.co/WUqLTDz9JZ
New cloud security research! We found a method to bypass CloudTrail logging for specific IAM actions via an undocumented API service! Attackers could perform some reconnaissance activities while being undetected.
https://t.co/wXirgdIlWz
During last year's #BlackFriday promotion, half the internet bought a Burp Suite Certified Practitioner exam but mysteriously got cold feet about taking it. We feel really guilty about taking your $10, so this year we have a new deal: you prepare, we pay:
https://t.co/Bia8bFrKJB
Our ninjas @yaumn_ and @mickaelweb recently assessed Microsoft Defender for Identity detection capabilities. In their recent blogpost, they describe the product's architecture, present some bypasses and give general Red Team advices. https://t.co/tuBoWYEVQ9