
rootsecdev
@rootsecdev
Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
내가 좋아할 만한 콘텐츠
Just wanted to remind everyone. Azure Cloud training does not need to be super expensive. You just need to know where to look. Because that is what hackers do. #Azure #Cloud #Hacking Books: amazon.com/Penetration-Te… Labs: github.com/iknowjason/Awe… Free SANS Courses (on demand):…
New blog out! It’s not rocket science, but if an attacker has access to Front Door WAF and Log Analytics, they could be skimming plaintext credentials from users thanks to Front Door’s verbose logging.

Your Web Application Firewall (WAF) sees EVERYTHING 👁️ In our new blog, @nyxgeek demonstrates how an attacker with access to #Azure Front Door’s WAF and Log Analytics can potentially skim credentials from a site behind the WAF. Read it now! trustedsec.com/blog/skimming-…
Your Web Application Firewall (WAF) sees EVERYTHING 👁️ In our new blog, @nyxgeek demonstrates how an attacker with access to #Azure Front Door’s WAF and Log Analytics can potentially skim credentials from a site behind the WAF. Read it now! trustedsec.com/blog/skimming-…
I hear some folks in IT may have a banger of a weekend

Red Hat Consulting breach puts over 5000 high profile enterprise customers at risk — in detail | by Kevin Beaumont | Oct, 2025 | DoublePulsar doublepulsar.com/red-hat-consul…
Attackers appearing to be aligned with the Clop ransomware group have sent emails to Oracle customers seeking extortion payments, claiming they stole data from the tech giant’s E-Business Suite, according to researchers who spoke with CyberScoop. scoopmedia.co/432c7D1

Join @Carlos_Perez for our next webinar on October 15 at 1:00PM. We'll draw from recent, anonymized investigations to expose the most devastating failure patterns our Incident Response team has encountered in the field. Secure your spot now! trustedsec.zoom.us/webinar/regist…

As it turns out AWS not only made changes to their TOS, they are actively enforcing them. Thus, the current public release of TeamFiltration has been rendered more or less useless for enum and spraying EntraId tenants.
I recently ran into this when I was attempting to expose an access token to a container registry. I got denied... then when I get to looking at things... its not on a private endpoint and I should have access to any network to exfil containers. Nope. This is some hotness on…
I heard @_dirkjan is going to be its own Mitre ID in itself. Loving @DrAzureAD talk on Token Theft Protection. youtube.com/watch?v=YlPkCX…

United States 트렌드
- 1. D’Angelo 13.1K posts
- 2. Happy Birthday Charlie 85.5K posts
- 3. #BornOfStarlightHeeseung 53.4K posts
- 4. #csm217 1,495 posts
- 5. #tuesdayvibe 5,059 posts
- 6. Angie Stone N/A
- 7. Alex Jones 19.7K posts
- 8. Sandy Hook 5,948 posts
- 9. Pentagon 85.2K posts
- 10. #NationalDessertDay N/A
- 11. #TheView N/A
- 12. Good Tuesday 38.8K posts
- 13. Taco Tuesday 12.4K posts
- 14. Cheryl Hines 1,658 posts
- 15. Shilo 3,516 posts
- 16. Monad 222K posts
- 17. Masuda 2,366 posts
- 18. Windows 10 24.5K posts
- 19. Dissidia 8,590 posts
- 20. Powell 20.6K posts
내가 좋아할 만한 콘텐츠
-
DirectoryRanger
@DirectoryRanger -
Will Schroeder
@harmj0y -
inversecos
@inversecos -
S3cur3Th1sSh1t
@ShitSecure -
Grzegorz Tworek
@0gtweet -
ςεяβεяμs - мαℓωαяε яεsεαяςнεя
@c3rb3ru5d3d53c -
Sean Metcalf
@PyroTek3 -
5pider
@C5pider -
Dr. Nestori Syynimaa
@DrAzureAD -
Olaf Hartong
@olafhartong -
Charlie Bromberg « Shutdown »
@_nwodtuhs -
mr.d0x
@mrd0x -
Mehmet Ergene
@Cyb3rMonk -
mpgn
@mpgn_x64 -
Chetan Nayak (Brute Ratel C4 Author)
@NinjaParanoid
Something went wrong.
Something went wrong.