KernelCaleb's profile picture.

KernelCaleb

@KernelCaleb

KernelCaleb reposted

when you see a README that's full of emojis

RhysSullivan's tweet image. when you see a README that's full of emojis

KernelCaleb reposted

On this day 6 years ago, Palpatine somehow returned

sw_holocron's tweet image. On this day 6 years ago, Palpatine somehow returned
sw_holocron's tweet image. On this day 6 years ago, Palpatine somehow returned

KernelCaleb reposted

🚨 Heads up: A stolen GitHub PAT can open your cloud. Attackers don't need skill, just patience - one NPM supply-chain hit is enough. Our IR team shows how PATs are abused to pivot from code ➝ cloud ⬇️ wiz.io/blog/github-at…

wiz_io's tweet image. 🚨 Heads up: A stolen GitHub PAT can open your cloud. Attackers don't need skill, just patience - one NPM supply-chain hit is enough. 

Our IR team shows how PATs are abused to pivot from code ➝ cloud ⬇️ 
wiz.io/blog/github-at…

KernelCaleb reposted

Last quarter I rolled out Microsoft Copilot to 4,000 employees. $30 per seat per month. $1.4 million annually. I called it "digital transformation." The board loved that phrase. They approved it in eleven minutes. No one asked what it would actually do. Including me. I…


KernelCaleb reposted

Great to see this article from Wiz. Those in the SSC space have been sounding the alarm on just how bad PAT compromise could get for years, but real world cases mean the threat is real and not just "Oh, only security researchers do this." I hope more victims of GitHub PAT-based…


KernelCaleb reposted

This pretty much sums up the situation: an in-memory (!) JavaScript-based (!) webshell gets implanted into a vulnerable React server with a single(!) POST request and leaves zero(!) trace in logs or on disk. Someone used that POC, successfully injected the shell and still…

cyb3rops's tweet image. This pretty much sums up the situation: an in-memory (!) JavaScript-based (!) webshell gets implanted into a vulnerable React server with a single(!) POST request and leaves zero(!) trace in logs or on disk.

Someone used that POC, successfully injected the shell and still…

It’s wild how little sticks around when someone hits a server with the #React RCE payload. All the interesting parts of the POST request live for a moment in memory, get decoded, executed (or rejected), and vanish. Nothing hits a log, nothing lands on disk. You can scan process…



KernelCaleb reposted

Love the outrage about a "CVSS 10 on a Friday" when this thing has been out since Wednesday(!!!) #react

cyb3rops's tweet image. Love the outrage about a "CVSS 10 on a Friday" when this thing has been out since Wednesday(!!!) #react

KernelCaleb reposted

There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/0…


KernelCaleb reposted

🚨 CRITICAL RCE ALERT: React & Next.js Vulnerability ↓ Critical remote code execution (RCE) vulnerabilities have been published affecting the React 19 ecosystem and Next.js. These vulnerabilities (CVE-2025-55182 & CVE-2025-66478) reside in the React Server Components (RSC)…

wiz_io's tweet image. 🚨 CRITICAL RCE ALERT: React & Next.js Vulnerability ↓

Critical remote code execution (RCE) vulnerabilities have been published affecting the React 19 ecosystem and Next.js.

These vulnerabilities (CVE-2025-55182 & CVE-2025-66478) reside in the React Server Components (RSC)…

KernelCaleb reposted

I finally came around and documented all the Conditional Access bypasses in a single blog post. It contains not only the documented bypasses, but also the results of new research. #Entra #ConditionalAccess #Security #Cheese cloudbrothers.info/en/conditional…


KernelCaleb reposted

My gift for Thanksgiving 💜 I wrote for you the blog post I always wanted to read! Happy holiday!🦃 PLEASE READ IT!!! wiz.io/blog/recent-oa…


KernelCaleb reposted

Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):

AmitaiCo's tweet image. Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):
AmitaiCo's tweet image. Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):
AmitaiCo's tweet image. Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):
AmitaiCo's tweet image. Shai-Hulud 2.0, a tale of 4 graphs: many numbers have made the news in regards to this story - such as 800 compromised packages - but visualizing the data clearly shows the potential impact of hijacking even a small set of key packages (in terms of prevalence or dependents):

KernelCaleb reposted

⚠️ Update on the Shai Hulud v2 campaign: We’ve confirmed 834 malicious packages and now see spillover into Maven Central. The package org.mvnpm:posthog-node:4.18.1 contains the same Bun-based payload used in the npm compromise. Updated analysis → socket.dev/blog/shai-hulu… #Java


KernelCaleb reposted

🚨 New Shai-Hulud-style npm attack hitting 25k+ repos and growing fast. Devs & CI/CD exposed via malicious preinstall. Wiz Research has detection + mitigation. Details: wiz.io/blog/shai-hulu…


KernelCaleb reposted

Microsoft is adding Sysmon directly into Windows. The Sysinternals utility will make it easier for security teams to detect and respond to threats theverge.com/news/822023/mi…


KernelCaleb reposted

The knowledge leaving your brain if you don't renew a certification:


KernelCaleb reposted

today.

_JohnHammond's tweet image. today.

KernelCaleb reposted

We accidentally got access to every Academy Award nominee's home address and phone number. Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors…

galnagli's tweet image. We accidentally got access to every Academy Award nominee's home address and phone number.

Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors…
galnagli's tweet image. We accidentally got access to every Academy Award nominee's home address and phone number.

Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors…
galnagli's tweet image. We accidentally got access to every Academy Award nominee's home address and phone number.

Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors…
galnagli's tweet image. We accidentally got access to every Academy Award nominee's home address and phone number.

Before last year's Oscars Ceremony, together with @iangcarroll and @samwcyo, we found a way to leak every nominee's PII, including phone numbers and home addresses of the biggest actors…

KernelCaleb reposted

🚨 We caught active exploitation in the wild by tracking unusual IMDS requests Our research team built a simple hunting method: find processes that don't normally access cloud metadata services, but suddenly started doing it. Works surprisingly well for finding real threats.…

wiz_io's tweet image. 🚨 We caught active exploitation in the wild by tracking unusual IMDS requests

Our research team built a simple hunting method: find processes that don't normally access cloud metadata services, but suddenly started doing it.

Works surprisingly well for finding real threats.…

KernelCaleb reposted

☎️ A new era of incident response is here: Wiz IR! Built for the cloud, it delivers rapid scoping, cloud forensics, expert-guided containment & ongoing monitoring. The way cloud IR should be done. 👉 Learn more: wiz.io/blog/introduci…


Loading...

Something went wrong.


Something went wrong.