Olga Barinova @_lely___
Manager, Product Security @Okta Joined August 2014-
Tweets82
-
Followers833
-
Following310
-
Likes75
The comprehensive list of today's emerging threats, nOtWASP bottom 10: vulnerabilities that make you cry by @albinowax, @artsploit and @garethheyes portswigger.net/research/notwa…
New attacks on OAuth: SSRF by design and Session Poisoning by @artsploit portswigger.net/research/hidde…
The top 10 web hacking techniques of 2020, by @albinowax with help from @filedescriptor, @irsdl, @Agarri_FR and the entire community portswigger.net/research/top-1…
Power up the Burp Suite and get stuck into our latest Web Security Academy topic! We've designed a whole new set of labs on OAuth Authentication for your password-avoiding pleasure. portswigger.net/web-security/o… #websecurityacademy #burpsuite #OAuth2
Can you spot a critical vulnerability in this innocent code? Learn about Spring View Manipulation in our latest article github.com/veracode-resea… #java @springframework
Jolokia enhances JMX remoting with unique features like pre-auth RCE 🤔
We have confirmed the successful demonstration from @artsploit used a previously reported bug. This counts as a partial win, but does earn him 12.5 Master of Pwn points. #P2OMiami #S4x20
Up next and making his #Pwn2Own debut, Michael Stepankin (@artsploit) of Veracode will be targeting a remote code execution with continuation against the Inductive Automation Ignition in the Control Server category. #P2OMiami #S4x20
Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :) spaceraccoon.dev/remote-code-ex…
I'm excited to share my post about discovering & exploiting multiple critical vulnerabilities in Cisco's DCNM. Busting Cisco's Beans :: Hardcoding Your Way to Hell srcincite.io/blog/2020/01/1… PoC exploit code: srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-… srcincite.io/pocs/cve-2019-…
Our guy, @SecurityMB, had a presentation at OWASP Poland Day about exploiting prototype pollution to RCE on the example of Kibana, by abusing environmental variables in node. The slides are here: slides.com/securitymb/pro… We will also release a writeup soon so stay in touch!
Here are my slides from XSS magic tricks slideshare.net/GarethHeyes/xs…
On the volunteering side this time at #GlobalAppSec #Amsterdam @AppSecEU
Apache Solr Injection whitepaper is now available at github.com/artsploit/solr… Thanks everyone who attended my #defcon talk!
Short story about blind HQL Injection (MySQL case) #hqlinjection #hibernate #spiderlabs trustwave.com/en-us/resource…
Apache Solr research is completed and I'm happy to present some ways to RCE in this innocent looking search engine. See you @ #defcon27 @defcon defcon.org/html/defcon-27… …
In our latest blog post we show you various ways how to attack RMI based JMX services. We also release our fork of sJET, which is called MJET (obviously). mogwailabs.de/blog/2019/04/a…
Expression Injection in Qlik Products (CVE-2019-11628). The fresh advisory has been published just now. trustwave.com/en-us/resource…
Blog post about attacking Java RMI services, a extension to the talk from Hans-Martin Münch at this years Bsides Munich mogwailabs.de/blog/2019/03/a…. You can also find the slides/material on our GitHub account #BSidesMUC19
heh :D

Ben Sadeghipour @NahamSec
235K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
shubs @infosec_au
56K Followers 2K Following Co-founder, security researcher. Building an attack surface management platform, @assetnote
Soroush Dalili @irsdl
20K Followers 912 Following Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, @SecProjectLtd founder 🕸️https://t.co/YipuTcYnWc🥷 🍏A dad-joke maker🍐
Tamara Dixon @TamaraDixo1466
1 Followers 173 Following Recruiti ng webshell e ngineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/DxhrzTFVyE
Cyber Security Pengui... @CySecPenguin
56 Followers 3K Following Cyber security information is collected.
/Users/avltree9798 �... @avltree9798
35 Followers 190 Following macOS & iOS security enthusiast 🇬🇧🇮🇱
Christopher John Maho... @KelvinDavi21097
207 Followers 4K Following My name is Christopher John Mahoney,I'm from Weymouth Massachusetts,i work with the department of defense,i'm the assistant commandant of the US Marines
ice @ice98079542
97 Followers 3K Following
Felix Kochi @felix_kochi
34 Followers 673 Following
Yannick Boog @YannickBoog
65 Followers 5K Following
Andrew Baji @baji_andrew
3 Followers 5K Following
Tony Torralba @_atorralba
407 Followers 374 Following Breaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJ
mandy😔✌️ @Mxndyy___
5 Followers 111 Following
Robert Baker @RobertB49596600
810 Followers 2K Following
HCL AppScan @AppScanHCL
263 Followers 631 Following Fast, Accurate, Agile Security Testing. To request a free trial of HCL AppScan, visit us here: https://t.co/cFmNhATwgg
nuyo4h @nuyo4h
0 Followers 3K Following
Juan Pablo Perata @cxzero
286 Followers 5K Following OSCP | Pentester | Bug Hunter | CTF player | Developer | Community
Jack7 @jackjoh07
88 Followers 2K Following
SergioV @0xValverde
70 Followers 2K Following
Mo0n Sha𝄞ow @null001__
55 Followers 3K Following
Para_n0i4 @Para_n0i4
22 Followers 324 Following
Mr Elliot @eliotsec
0 Followers 2K Following
Jason Firch @Jfirch
964 Followers 3K Following President @ PurpleSec | Marketing Leader | AI & Cybersecurity Nerd
Lucky Luke @Lky_hkr
9 Followers 338 Following
𝚝𝚑𝚎𝚜𝚎�... @T_0_r_nado
61 Followers 5K Following
nameless @JazonTWong
30 Followers 1K Following I identify as a a plant, please be respect and use the appropriate pronouns (plant/planted)
BRUNO @skksnsbsbsmsmd
9 Followers 2K Following
🦉 @deathoax
0 Followers 63 Following
I love NoStarchPress @Dot_Loki
101 Followers 3K Following #malware #websec #osint #ctf how do i use internet??
badr eddine @ivarov54
511 Followers 4K Following
Siva Siva @zebasquared
448 Followers 418 Following App Sec @doordash former @okta @thezdi @TrendMicroRSRCH
Rollo Davies F.ISRM M... @SecurityRollo
12K Followers 13K Following Award Winning Security Ops Leadership. Co-Founder: The Guild of Security Industry Professionals & TPSO Magazine. Security Standards Campaigner. Let's Connect!
@MichaelAltfield@Mast... @MichaelAltfield
767 Followers 5K Following 🐧 #Linux Hacker. 🔑 #Security Guru. I write articles about #opsec & #privacy. 💙 #OpenSource 💾 I use mastodon, not twitter @[email protected]
Lucy_noob @Unident31289637
1 Followers 111 Following I am a full time bug bounty hunter and I am here to share happiness. https://t.co/12hJpBVtD3
Ethan Lim ʕ•ᴥ•... @xpectomas
19 Followers 186 Following
hateshape @hateshaped
835 Followers 461 Following
Huan Lopes @Huan_Lopez_
21 Followers 404 Following 0-Day Development,0-Day Brokering E:[email protected]
Marina Rodriguez @marinarodrubio
7 Followers 250 Following
Moad Akhraz @mdakh404_
76 Followers 2K Following I like computers, security and everything in between.
KR. LABORATORIES 🇺... @KrLaboratories
299 Followers 5K Following IT Security and Research Labs ⚡🛡️ #cybersec #infosec #tech #intelligence https://t.co/AYuTZlxhkN
jiji @Wolf_AK0
23 Followers 684 Following just a soul that wanna grow up like ,seed with sunlight of knowledge .
Laluka@OffenSkill @TheLaluka
5K Followers 1K Following Sharing is Caring, Hacker, Eternel Learner, Cat! =^~^=
Ben Sadeghipour @NahamSec
235K Followers 1K Following Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
Trend Zero Day Initia... @thezdi
83K Followers 16 Following Trend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Nicolas Grégoire @Agarri_FR
27K Followers 631 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
publiclyDisclosed @disclosedh1
65K Followers 2 Following This is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
bugcrowd @Bugcrowd
188K Followers 6K Following The leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
Gareth Heyes \u2028 @garethheyes
37K Followers 1K Following JavaScript for hackers: Learn to think like a hacker. https://t.co/e0aNEbEDk5
Frans Rosén @fransrosen
43K Followers 900 Following Co-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
Binni Shah @binitamshah
141K Followers 165 Following Linux Evangelist, Malwares, Security enthusiast , Investor, Contrarian , Philanthropist , Reformist , Sigma female 🦋 https://t.co/WOvf41tMKV
Florian Roth ⚡️ @cyb3rops
207K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Soroush Dalili @irsdl
20K Followers 912 Following Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, @SecProjectLtd founder 🕸️https://t.co/YipuTcYnWc🥷 🍏A dad-joke maker🍐
Web Security Academy @WebSecAcademy
131K Followers 36 Following Free web security training from @PortSwigger
zseano @zseano
79K Followers 703 Following
BugBountyHQ @BugBountyHQ
24K Followers 95 Following
The Hacker News @TheHackersNews
933K Followers 2K Following The #1 trusted source for cybersecurity news, insights, and analysis — built for defenders and trusted by decision-makers.
Alisa Esage Шевч�... @alisaesage
38K Followers 101 Following Independent Hacker, Sovereign Builder, Solo Business Owner • @zerodaytraining • Pronounced ‘is edge’
James Kettle @albinowax
79K Followers 94 Following Director of Research at @PortSwigger aka @Burp_Suite. Find my research, tools & contact details at https://t.co/vP6UbGmvl3
Jobert Abma @jobertabma
43K Followers 718 Following I tweet about security and my experience as a hacker. Co-founder of HackerOne (@Hacker0x01).
DC4131 - DEFCON CH @defconch
1K Followers 110 Following
Tony Torralba @_atorralba
407 Followers 374 Following Breaking builds and building breakages. He/him. ProdSec Engineer @okta. Opinions are my own. Mastodon: https://t.co/oFZdTxYDMJ
Ekoparty | Hacking ev... @ekoparty
25K Followers 160 Following The coolest #hacking conference and meeting point in LATAM since 2001 🏴☠️
Jayson E. Street 💙... @jaysonstreet
67K Followers 401 Following ➡️Hacker - Helper - Human ⬅️ . . . Also Author. Speaker & Scientific Hooligan! A bona fide teachable moment for hire! he/him
Tanya Janca | Shehack... @shehackspurple
50K Followers 2K Following Secure Coding Trainer, Best-selling author of Alice and Bob Learn Secure Coding & Alice and Bob Learn Application Security. #AppSec she/her 🌻
Esteban Guillardoy @sagar38
1K Followers 2K Following Security Researcher (posts & opinions are my own)
TLDR Newsletter @tldrnewsletter
123K Followers 141 Following Startups, Tech & Programming Newsletter: https://t.co/7gjBLYeOxY | Crypto Newsletter: https://t.co/4Xa63QkGMf | AI Newsletter: https://t.co/UsowDlp8JM | Curated by @tldrdan
Siva Siva @zebasquared
448 Followers 418 Following App Sec @doordash former @okta @thezdi @TrendMicroRSRCH
Queen Elizabeth Olymp... @noordinarypark
34K Followers 821 Following Be Inspired, Be Amazed, Be Here. Immerse in world-class culture, sport & iconic architecture. 🎤 Stunning parklands & great food in the heart of east London. 🌲
Dmitriy Shagov @dmi3sh
2K Followers 596 Following
Home Office @ukhomeoffice
1.1M Followers 513 Following We are the lead UK government department for immigration & passports, crime & policing, homeland security and protecting vulnerable people.
Priti Patel MP @pritipatel
453K Followers 352 Following Conservative Party Shadow Foreign Secretary and Member of Parliament for Witham. Promoted by Priti Patel of WCCA, Essex House, 21 Eastways, Witham, CM8 3YQ
Marina Rodriguez @marinarodrubio
7 Followers 250 Following
Wallarm @wallarm
3K Followers 4K Following Wallarm is the fastest, easiest, most effective way to block API attacks in real-time
Anna Lebedeva @neurvanna
422 Followers 372 Following Postdoc in David Ginty lab at Harvard Medical School.
SPAC Shack @ShackSpac
2K Followers 179 Following SPAC musings, watch lists, viz, polls, and other nuggets. Evening and weekend warrior. Definitely NOT a financial advisor so don’t listen to me.
SPACWatch.com @spac_watch
11K Followers 66 Following Definitive agreement alerts sent via SMS and email.
Trading 212 @Trading212
83K Followers 1 Following Build wealth every day. When investing, your capital is at risk. For support: @Trading212Help
Cathie Wood @CathieDWood
1.9M Followers 489 Following Founder, CEO and CIO @ARKinvest. Thematic portfolio manager for disruptive innovation, mom, economist, and women's advocate. Disclosure: https://t.co/chxRD4oWOd
Hacking is NOT a Crim... @hacknotcrime
24K Followers 0 Following A global organization advocating the decriminalization of hacking through policy reform. Privacy and security hacktivism. Hack, ergo sum. #HackingIsNotACrime
x0rz @x0rz
96K Followers 420 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
Jake Miller @theBumbleSec
2K Followers 384 Following Web Security Researcher | h2c smuggling, JSON Interop vulns, RMIScout, GadgetProbe, Server-side Spreadsheet Injection | AppSec @BrexHQ; formerly @BishopFox
GitHub Security Lab @GHSecurityLab
26K Followers 15 Following GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
terjanq @terjanq
11K Followers 258 Following security enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish. infosec at @google. opinions are mine.
Ian Beer @i41nbeer
48K Followers 147 Following
Jeff Moss @thedarktangent
106K Followers 7 Following https://t.co/fgXNGNt7gm Abandoned this site in 2022 but hopeful for the future of social media. Consider migrating to DEFCON.socal
Hack3rScr0lls @hackerscrolls
10K Followers 57 Following for hackers by hackers Contact: [email protected]
Tobias Scharnowski @ScepticCtf
2K Followers 404 Following Embedded Firmware Fuzzing at https://t.co/h3RnGfm20g. Ph.D. student. Working on advancing embedded systems software security.
Trend Micro @TrendMicro
113K Followers 4K Following We're a global leader in cybersecurity that helps make the world safe for exchanging digital information.
spaceraccoon | Eugene... @spaceraccoonsec
25K Followers 301 Following Here to learn! Infosec@Open Government Products | White Hat && SecOps
Markus Wulftange @mwulftange
3K Followers 196 Following Principal Security Researcher and Pâtissier at @codewhitesec
Katie🌻Moussouris (... @k8em0
110K Followers 10K Following @LutaSecurity CEO @payequitynow MIT&Harvard visiting scholar, @MasonNatSec fellow, 1/2 Chamoru, hacker @k8em0.bsky.social Legacy blue check
Allyson O'Malley @ally_o_malley
4K Followers 525 Following Ethical hacker with a focus on iOS, web, and API security. https://t.co/UEAHujr2mj
Kelly Villanueva @kellthenoise
4K Followers 285 Following Previously Red team @ Salesforce, SpecterOps & Big4 | Interested in security, puns, and mountains | Opinions my own @[email protected]
Vickie Li @vickieli7
32K Followers 194 Following Infosec nerd. Hacks and secures. Creates god awful infographics. Author of #BugBountyBootcamp. Security @instacart.
Konstantin Batygin @kbatygin
13K Followers 170 Following Planetary Science Prof at @Caltech | Vox & Guitar at https://t.co/EH8ewMgoDz
Rachel Tobac @RachelTobac
108K Followers 8K Following Friendly Hacker & CEO @SocialProofSec security awareness/social engineering prevention Training, Videos, Talks | 3X @DEFCON🥈| Board @WISPorg | Ex @CISAgov TAC![Security Researcher @ Veracode ... [... your usual company disclaimer here ...]](https://pbs.twimg.com/profile_images/1012397891137232896/O2ddxgpG.jpg)
Giuseppe Trovato @otavorteppesuig
107 Followers 556 Following Security Researcher @ Veracode ... [... your usual company disclaimer here ...]