rootsecdev's profile picture. Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.

rootsecdev

@rootsecdev

Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.

مثبتة

Just wanted to remind everyone. Azure Cloud training does not need to be super expensive. You just need to know where to look. Because that is what hackers do. #Azure #Cloud #Hacking Books: amazon.com/Penetration-Te… Labs: github.com/iknowjason/Awe… Free SANS Courses (on demand):…


rootsecdev أعاد

I’ll have the heavy metals and various other tests posted up on the site later today for our supplement lines. The study published showed organic being the most heavy in lead for other brands- check out our report. All of ours have the absolute minimum and well within and below…

HackingDave's tweet image. I’ll have the heavy metals and various other tests posted up on the site later today for our supplement lines. The study published showed organic being the most heavy in lead for other brands- check out our report. All of ours have the absolute minimum and well within and below…

Shall we play a game?

JUST IN: U.S. Army general admits he uses ChatGPT to make "key command decisions"



I loved #TronAres Mix of old and new. I thought it was well done. Go watch if you haven’t. That light cycle scene 💗


rootsecdev أعاد

Service triggers can be a pentester’s secret weapon, letting low-priv users quietly fire up powerful services. In our new blog, @freefirex2 breaks down the types of service triggers that exist and how they can be activated with little to no code required. trustedsec.com/blog/theres-mo…


rootsecdev أعاد

📢 New Chapter: #MicrosoftEntra Attack & Defense Playbook ☁️ 🔑 @samilamppu and I have focused on Application-based Authentication (ABA) in #EntraConnect. Huge thanks to @DrAzureAD and @RobbeVdDaele for reviewing. Check out the new chapter: github.com/Cloud-Architek…

Thomas_Live's tweet image. 📢 New Chapter: #MicrosoftEntra Attack & Defense Playbook ☁️ 🔑 
@samilamppu and I have focused on Application-based Authentication (ABA) in #EntraConnect. Huge thanks to @DrAzureAD and @RobbeVdDaele for reviewing.
Check out the new chapter:
github.com/Cloud-Architek…
Thomas_Live's tweet image. 📢 New Chapter: #MicrosoftEntra Attack & Defense Playbook ☁️ 🔑 
@samilamppu and I have focused on Application-based Authentication (ABA) in #EntraConnect. Huge thanks to @DrAzureAD and @RobbeVdDaele for reviewing.
Check out the new chapter:
github.com/Cloud-Architek…
Thomas_Live's tweet image. 📢 New Chapter: #MicrosoftEntra Attack & Defense Playbook ☁️ 🔑 
@samilamppu and I have focused on Application-based Authentication (ABA) in #EntraConnect. Huge thanks to @DrAzureAD and @RobbeVdDaele for reviewing.
Check out the new chapter:
github.com/Cloud-Architek…
Thomas_Live's tweet image. 📢 New Chapter: #MicrosoftEntra Attack & Defense Playbook ☁️ 🔑 
@samilamppu and I have focused on Application-based Authentication (ABA) in #EntraConnect. Huge thanks to @DrAzureAD and @RobbeVdDaele for reviewing.
Check out the new chapter:
github.com/Cloud-Architek…

I try and keep Thursdays off the hook.

rootsecdev's tweet image. I try and keep Thursdays off the hook.

rootsecdev أعاد

F5 BIG-IP Environment Breached by Nation-State Actor: bit.ly/3WDMncq by Alexander Culafi


rootsecdev أعاد

In early October 2025, Microsoft disrupted a Vanilla Tempest campaign by revoking over 200 certificates that the threat actor had fraudulently signed and used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware. We identified this…

MsftSecIntel's tweet image. In early October 2025, Microsoft disrupted a Vanilla Tempest campaign by revoking over 200 certificates that the threat actor had fraudulently signed and used in fake Teams setup files to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware. 

We identified this…

Fed ex: yells explicative while dropping off some heavy boxes. Me: thanks bro. Then lifts one box at a time into my place like it’s nothing. 😎

rootsecdev's tweet image. Fed ex: yells explicative while dropping off some heavy boxes. 

Me: thanks bro. 

Then lifts one box at a time into my place like it’s nothing.  😎

rootsecdev أعاد

🚨 Nation-state affiliated threat actors have compromised F5’s systems & downloaded portions of its BIG-IP source code—posing serious risk to FCEB agencies. Follow the guidance in ED 26-01 immediately to protect systems from potential exploits. 🔗 go.dhs.gov/isY


rootsecdev أعاد

New blog out! It’s not rocket science, but if an attacker has access to Front Door WAF and Log Analytics, they could be skimming plaintext credentials from users thanks to Front Door’s verbose logging.

nyxgeek's tweet image. New blog out! It’s not rocket science, but if an attacker has access to Front Door WAF and Log Analytics, they could be skimming plaintext credentials from users thanks to Front Door’s verbose logging.

Your Web Application Firewall (WAF) sees EVERYTHING 👁️ In our new blog, @nyxgeek demonstrates how an attacker with access to #Azure Front Door’s WAF and Log Analytics can potentially skim credentials from a site behind the WAF. Read it now! trustedsec.com/blog/skimming-…



rootsecdev أعاد

Only 82 more days until Q4 is over.


rootsecdev أعاد

Your Web Application Firewall (WAF) sees EVERYTHING 👁️ In our new blog, @nyxgeek demonstrates how an attacker with access to #Azure Front Door’s WAF and Log Analytics can potentially skim credentials from a site behind the WAF. Read it now! trustedsec.com/blog/skimming-…


I hear some folks in IT may have a banger of a weekend

rootsecdev's tweet image. I hear some folks in IT may have a banger of a weekend

I really need to amp up my xitter usage. But for now…

rootsecdev's tweet image. I really need to amp up my xitter usage. But for now…

Red Hat Consulting breach puts over 5000 high profile enterprise customers at risk — in detail | by Kevin Beaumont | Oct, 2025 | DoublePulsar doublepulsar.com/red-hat-consul…


rootsecdev أعاد

Attackers appearing to be aligned with the Clop ransomware group have sent emails to Oracle customers seeking extortion payments, claiming they stole data from the tech giant’s E-Business Suite, according to researchers who spoke with CyberScoop. scoopmedia.co/432c7D1

CyberScoopNews's tweet image. Attackers appearing to be aligned with the Clop ransomware group have sent emails to Oracle customers seeking extortion payments, claiming they stole data from the tech giant’s E-Business Suite, according to researchers who spoke with CyberScoop. scoopmedia.co/432c7D1

Loading...

Something went wrong.


Something went wrong.