
Anirudh Anand
@a0xnirudh
Head of Product Security Engineering at @CRED_club | Application Security ♥ | CTF lover - @teambi0s | Security Trainer - @7asecurity | Tweets are my own.
Dit vind je misschien leuk
Diving deep into Jetbrains #TeamCity Part 2 - Analysing CVE-2024-24942 leading to unauthenticated Path Traversal: blog.0daylabs.com/2024/12/11/jet…

Applications of Large Language Models (LLMs) in Offensive Security: blog.xint.io/offensive-secu…
CVE-2024-0132: Escaping @NVIDIA Container Toolkit allowing attackers to gain full access to the host's filesystem leading to Remote Code Execution (#RCE). Amazing research from @wiz_io 🔥 wiz.io/blog/wiz-resea…
Hacking Kia: Remotely Controlling Cars With Just a License Plate, amazing read from @samwcyo 🔥😎 samcurry.net/hacking-kia
CVE-2024-45489 - Gaining access to anyone's browser without them even visiting a website, fun read from @xyz3va 🔥 kibty.town/blog/arc/

[Must Read] Using #YouTube to steal your files - Crazy writeup by @rebane2001 🔥 lyra.horse/blog/2024/09/u…
![a0xnirudh's tweet image. [Must Read] Using #YouTube to steal your files - Crazy writeup by @rebane2001 🔥
lyra.horse/blog/2024/09/u…](https://pbs.twimg.com/media/GYKVALgXIAATkUj.jpg)
Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from @wunderwuzzi23 embracethered.com/blog/posts/202…

Detailed analysis on #XSS -> #RCE in #electron bypassing the nodeintegration affecting user note app ! Amazing writeup from @retr0reg 🔥 0reg.dev/blog/electron-…
Just released the first part of a multi-part series on analyzing recent #TeamCity vulnerabilities! Part 1 is all about CVE-2024-23917 and how it leads to Authentication Bypass.
Diving deep into Jetbrains #TeamCity Part 1 - Analysing CVE-2024-23917 leading to Authentication Bypass: blog.0daylabs.com/2024/05/27/jet…


Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from @0Xhunterx 🔥 medium.com/@ahmedelmorsy3…

Exploiting CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM 🔥: labs.nettitude.com/blog/cve-2024-…

Race Condition on Changing Email Leading to Arbitrary Email Forgery by @blackarazi 🤠 link.medium.com/jZUVZpf1WIb

An interesting collection of Server-Side Prototype Pollution gadgets found in Node.js, Deno standard libraries, and various third-party NPM packages along with exploits: github.com/KTH-LangSec/se…

[Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty ! "the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣 johnstawinski.com/2024/04/15/fix…
![a0xnirudh's tweet image. [Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty !
"the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣
johnstawinski.com/2024/04/15/fix…](https://pbs.twimg.com/media/GLicXu8XMAECnM1.jpg)
CVE-2023-46851: #Apache Allura (< 1.15.0) Arbitrary File Read via Discussion Import leading to Remote Code Execution (#RCE) via Signed Serialized Session, amazing read from @Sonar_Research 🔥 sonarsource.com/blog/dangerous…
CVE-2024-0333: ZIP embedding attack on Google #Chrome extensions through abusing CRX file format ( Embedding malicious extension inside a valid Chrome extension to create a malicious extension with a valid signature) readme.synack.com/exploits-expla…
Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (@pwnthem0le) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…

Making #PHP Great Again 2.0, or how to use filters with `require_once` ? Fun read from @dustriorg 🔥 dustri.org/b/solution-to-… If you love solving similar PHP challenges, do checkout websec.fr (Extremely fun PHP based challenges)

An Obscure Github Actions Workflow Vulnerability in @Google's Flank leading to leaking Google service account credentials & Github Tokens (write access) with @GoogleVRP awarding $7500 ! A nice read from @adnanthekhan 🔥 adnanthekhan.com/2024/04/15/an-…

United States Trends
- 1. Jets 105K posts
- 2. James Franklin 38.9K posts
- 3. Drake Maye 11.6K posts
- 4. Justin Fields 20.9K posts
- 5. Penn State 53.7K posts
- 6. Broncos 44.5K posts
- 7. Aaron Glenn 8,761 posts
- 8. Puka 7,326 posts
- 9. Derrick Henry 2,446 posts
- 10. George Pickens 4,124 posts
- 11. Rico Dowdle 2,339 posts
- 12. Steelers 42.4K posts
- 13. #RavensFlock 1,748 posts
- 14. Cooper Rush 1,877 posts
- 15. Saints 47.3K posts
- 16. #DallasCowboys 2,267 posts
- 17. Cam Little N/A
- 18. Boutte 2,616 posts
- 19. #KeepPounding 2,091 posts
- 20. Eberflus N/A
Dit vind je misschien leuk
-
pwnmachine 👾
@princechaddha -
Sébastien Morin
@SebMorin1 -
Riyaz Walikar
@riyazwalikar -
Rajanish Pathak
@h4ckologic -
Yogendra Jaiswal
@vulnh0lic -
Ashwin
@0xsilipwn -
Abhijeth D
@abhijeth -
Sahil Ahamad
@ehsahil -
Evan
@evanricafort -
Anshuman Bhartiya
@anshuman_bh -
yappare
@yappare -
Akhil Mahendra
@Akhil_Mahendra -
Himanshu Kumar Das
@mehimansu
Something went wrong.
Something went wrong.