Breaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJatorralba.github.io BarcelonaJoined December 2011
I remember being excited about AI. I remember 20 years ago, being excited about neuroevolutionary methods for learning adaptive behaviors in video games. And I remember three years ago, mouth watering at the thought of tasty experiments in putting language models inside…
New blog post with @infosec_au:
We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely.
The issue was reported and patched.
Full post here: samcurry.net/hacking-subaru
Security in Action(s): extending CodeQL to detect Workflow vulnerabilities
🎤 Álvaro Muñoz
Protege tus pipelines de CI/CD con detección avanzada de vulnerabilidades en GitHub Actions.
---
SALA A2 - Miércoles 13 Noviembre de 14:45 a 15:30 hs
@ekoparty CEC Buenos Aires
As someone who has always toyed with the idea of learning more about low-level exploitation (but is currently very bad at), I enjoyed this post a whole lot. Not only because of the insights about the whats and whys, but also because of the transversal look at the offsec industry.
As someone who has always toyed with the idea of learning more about low-level exploitation (but is currently very bad at), I enjoyed this post a whole lot. Not only because of the insights about the whats and whys, but also because of the transversal look at the offsec industry.
🚨 New Blog Alert! 🚨
Can an attacker execute commands by sending JSON? Learn how unsafe deserialization vulnerabilities in Ruby can be exploited and how they can be detected with CodeQL.
🔗 Read the full post: github.blog/2024-06-20-exe…
Stay safe and code responsibly! 🛡️💻
Happy to share that @pwntester and I will be presenting our talk "Finding vulnerabilities at scale in Jenkins plugins with CodeQL" at @BarcelonaBsides, happening on May 29-30. Join us to learn about CodeQL, vulnerability research at scale, and the Jenkins plugin ecosystem!
Learn to audit applications for vulnerabilities with CodeQL and find them in thousands of GitHub repositories at once.
🚀 My blog, CodeQL zero to hero part 3: Security research with CodeQL is out!
github.blog/2024-04-29-cod…
This is my favorite kind of talk: great storytelling, cool visuals, technically interesting scenarios, and inspiring discourse. Consider me impressed @curi0usJack :D
youtube.com/watch?v=i2cJ1v…
Ever wondered how the @GHSecurityLab performs security research?
Find out how they leverage code scanning, CodeQL, Codespaces and more🔒 ⬇️
github.blog/2024-04-03-sec…
In this post I'll use CVE-2023-6241, a vulnerability in the Arm Mali GPU that I reported last November to gain arbitrary kernel code execution from an untrusted app on a Pixel 8 with MTE enabled. github.blog/2024-03-18-gai…
1 Followers 174 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/MEeBemBbzC
724 Followers 2K FollowingCybersecurity Researcher. Threat Intel. SecOps. Love heavy metal 🤘🏻Tweets and opinions are my own. Co-organizer @BarcelonaBsides ex-@BSidesMontreal
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
6K Followers 602 FollowingCEO and founder of XBOW. Previously: Founder of GitHub Next, founder of GitHub Copilot, CEO and founder of Semmle (GitHub Advanced Security), prof at Oxford.
17K Followers 3K FollowingCo-Founder of @CygentaHQ former head of cyber research @Raytheon - Keynote Speaker, ethical hacker and physical security specialist. Author of How I Rob Banks.
5K Followers 2K FollowingSecurity Geek, Containers, Kubernetes, Ruby, Hillwalking. Probably more active on Mastodon (@[email protected]) or blue sky (@mccune.org.uk) these days.
19K Followers 537 FollowingThreat Hunting & DFIR, Hacker, Geek, DEF CON & Black Hat CFP Review Board Member, DEF CON Contest/Events/Demo Labs Dept. Head, Black Hat Staff, DC801 Founder
11K Followers 716 Following// principal cybersecurity anarchist
// unethical hacker
// ex aws, wn, else
// @redteamvillage_ & @sec_defcon daemon
// take sincerely at your own risk
5K Followers 9 FollowingPaged Out! is a free magazine about programming, hacking, security hacking, retro computers, modern computers, electronics, demoscene, and other amazing topics.
724 Followers 2K FollowingCybersecurity Researcher. Threat Intel. SecOps. Love heavy metal 🤘🏻Tweets and opinions are my own. Co-organizer @BarcelonaBsides ex-@BSidesMontreal
16K Followers 200 Following@TrustedSec Red Team lead | Hi-Fidelity trolling | Privacy Enthusiast | Putting the "no" in nano | Avatar: https://t.co/3XHmKR8nCk
5K Followers 315 FollowingSecurity but not as in "national security". Playing CTFs with @redrocket_ctf (and @Sauercl0ud). Pwn2Own Vancouver 2020..=2024\{2023}. @[email protected]
413K Followers 2K FollowingIngeniero, doctor en física de partículas. Fui investigador en @CERN.
Ciencia en Youtube #DateUnVoltio y autor. Canario.
[email protected]
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
10K Followers 17 FollowingAnd there is fire where we walk. they/them
Find our active account here: https://t.co/Q3se8nVme8
Also, fuck you very much, @elonmusk