Anirudh Anand
@a0xnirudh
Head of Product Security Engineering at @CRED_club | Application Security ♥ | CTF lover - @teambi0s | Security Trainer - @7asecurity | Tweets are my own.
내가 좋아할 만한 콘텐츠
Diving deep into Jetbrains #TeamCity Part 2 - Analysing CVE-2024-24942 leading to unauthenticated Path Traversal: blog.0daylabs.com/2024/12/11/jet…
Applications of Large Language Models (LLMs) in Offensive Security: blog.xint.io/offensive-secu…
CVE-2024-0132: Escaping @NVIDIA Container Toolkit allowing attackers to gain full access to the host's filesystem leading to Remote Code Execution (#RCE). Amazing research from @wiz_io 🔥 wiz.io/blog/wiz-resea…
Hacking Kia: Remotely Controlling Cars With Just a License Plate, amazing read from @samwcyo 🔥😎 samcurry.net/hacking-kia
CVE-2024-45489 - Gaining access to anyone's browser without them even visiting a website, fun read from @xyz3va 🔥 kibty.town/blog/arc/
[Must Read] Using #YouTube to steal your files - Crazy writeup by @rebane2001 🔥 lyra.horse/blog/2024/09/u…
Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from @wunderwuzzi23 embracethered.com/blog/posts/202…
Detailed analysis on #XSS -> #RCE in #electron bypassing the nodeintegration affecting user note app ! Amazing writeup from @retr0reg 🔥 0reg.dev/blog/electron-…
Just released the first part of a multi-part series on analyzing recent #TeamCity vulnerabilities! Part 1 is all about CVE-2024-23917 and how it leads to Authentication Bypass.
Diving deep into Jetbrains #TeamCity Part 1 - Analysing CVE-2024-23917 leading to Authentication Bypass: blog.0daylabs.com/2024/05/27/jet…
Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from @0Xhunterx 🔥 medium.com/@ahmedelmorsy3…
Exploiting CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM 🔥: labs.nettitude.com/blog/cve-2024-…
Race Condition on Changing Email Leading to Arbitrary Email Forgery by @blackarazi 🤠 link.medium.com/jZUVZpf1WIb
An interesting collection of Server-Side Prototype Pollution gadgets found in Node.js, Deno standard libraries, and various third-party NPM packages along with exploits: github.com/KTH-LangSec/se…
[Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty ! "the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣 johnstawinski.com/2024/04/15/fix…
CVE-2023-46851: #Apache Allura (< 1.15.0) Arbitrary File Read via Discussion Import leading to Remote Code Execution (#RCE) via Signed Serialized Session, amazing read from @Sonar_Research 🔥 sonarsource.com/blog/dangerous…
CVE-2024-0333: ZIP embedding attack on Google #Chrome extensions through abusing CRX file format ( Embedding malicious extension inside a valid Chrome extension to create a malicious extension with a valid signature) readme.synack.com/exploits-expla…
Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (@pwnthem0le) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…
Making #PHP Great Again 2.0, or how to use filters with `require_once` ? Fun read from @dustriorg 🔥 dustri.org/b/solution-to-… If you love solving similar PHP challenges, do checkout websec.fr (Extremely fun PHP based challenges)
An Obscure Github Actions Workflow Vulnerability in @Google's Flank leading to leaking Google service account credentials & Github Tokens (write access) with @GoogleVRP awarding $7500 ! A nice read from @adnanthekhan 🔥 adnanthekhan.com/2024/04/15/an-…
United States 트렌드
- 1. #SantaChat 9,126 posts
- 2. Jack Smith 95.4K posts
- 3. Venezuela 754K posts
- 4. Big Christmas 15.6K posts
- 5. Dan Bongino 14.9K posts
- 6. Ewers 13.1K posts
- 7. Weaver 7,886 posts
- 8. Endrick 13.4K posts
- 9. Jared Isaacman 3,676 posts
- 10. The Oscars 26.9K posts
- 11. Cherki 29.6K posts
- 12. Talavera 23.7K posts
- 13. NextNRG Inc 1,517 posts
- 14. Gunna 23.7K posts
- 15. Fani 34K posts
- 16. Jimmy Stewart 2,999 posts
- 17. Kawhi 5,035 posts
- 18. Puka 9,356 posts
- 19. Unblock 3,512 posts
- 20. Presidential Walk of Fame 5,330 posts
내가 좋아할 만한 콘텐츠
Something went wrong.
Something went wrong.