
Anirudh Anand
@a0xnirudh
Head of Product Security Engineering at @CRED_club | Application Security ♥ | CTF lover - @teambi0s | Security Trainer - @7asecurity | Tweets are my own.
Вам может понравиться
Diving deep into Jetbrains #TeamCity Part 2 - Analysing CVE-2024-24942 leading to unauthenticated Path Traversal: blog.0daylabs.com/2024/12/11/jet…

Applications of Large Language Models (LLMs) in Offensive Security: blog.xint.io/offensive-secu…
CVE-2024-0132: Escaping @NVIDIA Container Toolkit allowing attackers to gain full access to the host's filesystem leading to Remote Code Execution (#RCE). Amazing research from @wiz_io 🔥 wiz.io/blog/wiz-resea…
Hacking Kia: Remotely Controlling Cars With Just a License Plate, amazing read from @samwcyo 🔥😎 samcurry.net/hacking-kia
CVE-2024-45489 - Gaining access to anyone's browser without them even visiting a website, fun read from @xyz3va 🔥 kibty.town/blog/arc/

[Must Read] Using #YouTube to steal your files - Crazy writeup by @rebane2001 🔥 lyra.horse/blog/2024/09/u…
![a0xnirudh's tweet image. [Must Read] Using #YouTube to steal your files - Crazy writeup by @rebane2001 🔥
lyra.horse/blog/2024/09/u…](https://pbs.twimg.com/media/GYKVALgXIAATkUj.jpg)
Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from @wunderwuzzi23 embracethered.com/blog/posts/202…

Detailed analysis on #XSS -> #RCE in #electron bypassing the nodeintegration affecting user note app ! Amazing writeup from @retr0reg 🔥 0reg.dev/blog/electron-…
Just released the first part of a multi-part series on analyzing recent #TeamCity vulnerabilities! Part 1 is all about CVE-2024-23917 and how it leads to Authentication Bypass.
Diving deep into Jetbrains #TeamCity Part 1 - Analysing CVE-2024-23917 leading to Authentication Bypass: blog.0daylabs.com/2024/05/27/jet…


Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from @0Xhunterx 🔥 medium.com/@ahmedelmorsy3…

Exploiting CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM 🔥: labs.nettitude.com/blog/cve-2024-…

Race Condition on Changing Email Leading to Arbitrary Email Forgery by @blackarazi 🤠 link.medium.com/jZUVZpf1WIb

An interesting collection of Server-Side Prototype Pollution gadgets found in Node.js, Deno standard libraries, and various third-party NPM packages along with exploits: github.com/KTH-LangSec/se…

[Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty ! "the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣 johnstawinski.com/2024/04/15/fix…
![a0xnirudh's tweet image. [Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty !
"the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣
johnstawinski.com/2024/04/15/fix…](https://pbs.twimg.com/media/GLicXu8XMAECnM1.jpg)
CVE-2023-46851: #Apache Allura (< 1.15.0) Arbitrary File Read via Discussion Import leading to Remote Code Execution (#RCE) via Signed Serialized Session, amazing read from @Sonar_Research 🔥 sonarsource.com/blog/dangerous…
CVE-2024-0333: ZIP embedding attack on Google #Chrome extensions through abusing CRX file format ( Embedding malicious extension inside a valid Chrome extension to create a malicious extension with a valid signature) readme.synack.com/exploits-expla…
Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (@pwnthem0le) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…

Making #PHP Great Again 2.0, or how to use filters with `require_once` ? Fun read from @dustriorg 🔥 dustri.org/b/solution-to-… If you love solving similar PHP challenges, do checkout websec.fr (Extremely fun PHP based challenges)

An Obscure Github Actions Workflow Vulnerability in @Google's Flank leading to leaking Google service account credentials & Github Tokens (write access) with @GoogleVRP awarding $7500 ! A nice read from @adnanthekhan 🔥 adnanthekhan.com/2024/04/15/an-…

United States Тренды
- 1. Cowboys 64.6K posts
- 2. Fred Warner 5,480 posts
- 3. Panthers 64.4K posts
- 4. Ravens 60.9K posts
- 5. Browns 58.8K posts
- 6. #KeepPounding 6,547 posts
- 7. Dolphins 43.6K posts
- 8. Eberflus 8,621 posts
- 9. Colts 53.1K posts
- 10. Steelers 61.2K posts
- 11. Rico Dowdle 8,292 posts
- 12. Drake Maye 19.2K posts
- 13. Chargers 50.6K posts
- 14. James Franklin 47.8K posts
- 15. Penn State 64.6K posts
- 16. Pickens 16.4K posts
- 17. #FTTB 2,533 posts
- 18. Herbert 14.5K posts
- 19. Dillon Gabriel 4,145 posts
- 20. #HereWeGo 6,125 posts
Вам может понравиться
-
pwnmachine 👾
@princechaddha -
Sébastien Morin
@SebMorin1 -
Riyaz Walikar
@riyazwalikar -
Rajanish Pathak
@h4ckologic -
Yogendra Jaiswal
@vulnh0lic -
Ashwin
@0xsilipwn -
Abhijeth D
@abhijeth -
Sahil Ahamad
@ehsahil -
Evan
@evanricafort -
Anshuman Bhartiya
@anshuman_bh -
yappare
@yappare -
Akhil Mahendra
@Akhil_Mahendra -
Himanshu Kumar Das
@mehimansu
Something went wrong.
Something went wrong.