VMware acquisition by Broadcom led to cash and Broadcom shares for employees/shareholders.E*trade classified cash buyback as dividend, not capital gains, causing major tax issues.E*trade and Morgan Stanley ignoring responsibility.Seeking justice.#EtradeFraud#MorganStanleyFraud
Amazing writeup on finding a vulnerability through .NET reversing, enjoyed reading about the breakpoints that were set and how they logically owned Citrix ShareFile through a third party dependency https://t.co/2MusGNSz60
I’m looking to give away a voucher for the #OSCP PEN-200 w/ 30 day lab access ($999 value) for those in #InfoSec looking to grow their career! To enter for a chance to win, make sure to follow me AND retweet or like. The winner will be randomly selected on October 1st!
Inspired by @garethheyes' CSP bypass in PayPal, for the first time in 4 years, I found again that JS resources added by CloudFlare could introduce a CSP bypass.
https://t.co/lKccCfTo8a
NEW VIDEO!
Ever wondered what these "Browser Sandbox Escapes" are about? @freddyb wrote an article about how easy it is to look for vulnerabilities in the Firefox Sandbox and I turned it into a video.
What is a Browser Security Sandbox?!
https://t.co/2iXzhJmuKz
Interesting. The print() dialog has no information about the origin, so "document.write(document.domain);print()" might be better. By doing so, you can see document.domain on the print preview
https://t.co/5y4wxthfSv
@CRED_club Support team takes too long to even acknowledge the issue on a product purchased from cred store, let alone provide a resolution. Quite an indication of not to purchase from Cred store. Ticket #s 1500488, 1498357
I know there are lots of people waiting for the recent Microsoft Exchange pre-auth RCE on our side. This is a short advisory and detailed timeline. https://t.co/lgpW7AVZZJ
#proxylogon
Having discovered various issues with Windows mini-filter drivers lately I found public information about how to analyze such drivers for security issues somewhat lacking. Therefore today I've put out a blog post to try and fix that glitch :-) https://t.co/JwdxdxElfm
ICYMI @SecurityMB explained a few DOMPurify bypasses yesterday (https://t.co/vT8BL4V7A1). Today we're publishing a first part of two-part series about how he helped secure DOMPurify:
https://t.co/BZ4dH9B0Rv
Sharing this mindmap I personally created months ago when I was studying memory forensics. These are all publicly available on the volatility GitHub page but I find it very useful for mapping the plugins and their usage.
#dfir#incidentresponse#memoryforensics#infosec