Wormable Substack XSS: blog.calif.io/p/wormable-sub…
It must have been years since the last time a wormable XSS was found in a major social media website. This beautiful type confusion XSS attack vector is a gift that keeps on giving.
But most of all, @samykamkar is our hero!
Wormable Substack XSS: blog.calif.io/p/wormable-sub…
It must have been years since the last time a wormable XSS was found in a major social media website. This beautiful type confusion XSS attack vector is a gift that keeps on giving.
But most of all, @samykamkar is our hero!
New blog post: in a recent engagement, we turned a simple XSRF in Argo CD to a shell with cluster admin privileges.
No fix is available. We recommend hosting Argo CD on an isolated domain.
Details: blog.calif.io/p/argo-cd-csrf
In a recent engagement, we encountered a target running CraftCMS, and discovered a Remote Code Execution vulnerability that allowed us to compromise the target.
blog.calif.io/p/craftcms-rce
CC @yeuchimse
Great usage of the xpath attack vector in xmlsec. A powerful deserialization bug and an ssrf in the public interface to break yet another SSO product. Beautiful stuff!
Great usage of the xpath attack vector in xmlsec. A powerful deserialization bug and an ssrf in the public interface to break yet another SSO product. Beautiful stuff!
2K Followers 339 FollowingSecurity Engineer at @calif_io. Winner of Pwn2own Vancouver 2021, Torento 2022, Vancouver 2023. MSRC top 100 2019, 2020, 2021.
37K Followers 530 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
5K Followers 875 FollowingSecurity Researcher aka Bug Bounty Hunter | HackerOne|BugCrowd|Yogosha #bugbounty #whitehathacker || Follow me on social media @0x0asif
4 Followers 87 FollowingCreator of Gen Snippets – turn shortcuts into full content fast. Boost productivity on macOS: https://t.co/oSH4nEOVsK. Built in public. Feedback welcome!
884 Followers 8K FollowingPersona humana, desarrollador de software, promotor de accesibilidad, miembro de @KipuLlaxta. Nacido en España, residente en Perú. Bético de por vida 💚🤍💚
2K Followers 339 FollowingSecurity Engineer at @calif_io. Winner of Pwn2own Vancouver 2021, Torento 2022, Vancouver 2023. MSRC top 100 2019, 2020, 2021.
27K Followers 631 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks
20K Followers 271 FollowingOffensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
3K Followers 354 FollowingBeautiful open-source tools to debug, test & develop with HTTP.
👨🔧 Built by @pimterry
🦣 https://t.co/8DW87wpAYw
🦋 https://t.co/E4x3L3UoNM
3K Followers 865 FollowingEthical hacker building the future of software & AI security. My path: Unit 8200 → Stanford → Trail of Bits → Anthropic → @depthfirstlabs
270K Followers 394 FollowingOfficial account of the Defense Advanced Research Projects Agency. Follows/retweets/links do not = endorsement. Breakthrough technologies for national security.
7K Followers 871 FollowingCEO, RemoteThreat, Head of Red team @ IBM X-Force, Black Hat Review Board. Founder and co-organizer of Offensive AI Con. inveni et usurpa
1K Followers 1 Followingjswzl helps make web application testing easier with static analysis, making it easier to audit JS code and do your recon/mapping
48K Followers 1 FollowingA fast, trustworthy, and easy-to-use VPN is a good first step toward reclaiming your privacy. Just €5/month.
// Need help? Email [email protected]
35K Followers 256 FollowingWe help secure the world’s most targeted organizations and products. We combine security research with an attacker mentality to reduce risk and fortify code.
286K Followers 72 FollowingPart of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
No recent Favorites. New Favorites will appear here.