Yann
@glyannSOC Analyst, Admin Sys, Cybersecurity Consultant
Similar User
@asso_bzhack
@esd_academy
@Zey_Roxx
@mllejedi
@K_lfaa
@Peter80702224
@VirtualSamuraii
@JeanVivine
@P0lterg1ss
@_croucroute_
@_Bubulle
@EgaliteAcDijon
Cybersecurity is too much. Can I just go get a law degree or something and charge $1000/minute somewhere? 1. No one is shifting left. 2. No one is securing anything by design. 3. Productivity and capitalism will always win. 4. Devs don’t focus on security as much, it’s all…
Oops.
Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital
I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions We all know vulnerabilities exist. This isn't an injection, XSS, or RCE. But the crazy thing about it? It took 2 hours to discover. 🤯 Here's the story of #AutoWarp👇 (1/10)
#ESETresearch discovered a trojanized IDA Pro installer, distributed by the #Lazarus APT group. Attackers bundled the original IDA Pro 7.5 software developed by @HexRaysSA with two malicious components. @cherepanov74 1/5
[thread 🧵] this is a sub-thread about Kerberos Constrained Delegation (KCD) and abuse scenarios.
Fantastic Windows Logon types and Where to Find Credentials in Them, by @chiragsavla94 alteredsecurity.com/post/fantastic…
[thread] Did you know that ssh tries to authenticate with stored keys BEFORE the key specified with -i in the command line ? I just noticed this, the hard way 😐. Let's imagine you have more than 5 keys loaded in your ssh agent. When authenticating to a remote server, you get:
[thread] Tired of using complex payloads to get access to the os module in Server Side Template Injections on jinja2 ? I have new awesome payloads for you 😎 {{ self._TemplateReference__context.cycler.__init__.__globals__.os }} More information ➡️ podalirius.net/en/articles/py…
New Linux kernel bug lets you get root on most modern distros - @serghei bleepingcomputer.com/news/security/…
Un petit doc qui permet de savoir si nous sommes vulnérable.
Le groupe Babuk s’est fait remarquer ce début d'année, par le succès rapide de cyberattaques ciblées via son rançongiciel contre de grandes entreprises. L'analyse de nos experts dans les #CyberSeChronicles : bit.ly/3fpqBU7
Looking for hashes of known good Exchange files? Here are hashes from the Exchange team: github.com/microsoft/CSS-…
New blog post out NOW! Microsoft Exchange Zero Day’s – Mitigations and Detections. blueteamblog.com/microsoft-exch… #infosec #CyberSecurity #security #SOC #Blueteam #cyberdefense #infosecurity #CyberSec #siem
Here's a threat on some overpowered technologies to slow down attackers that you can implement _now_. First, re-implement LAPS (microsoft.com/en-us/download…) at your peril. 1/14
Sysmon for Linux coming ... twitter.com/markrussinovic…
Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital
CVE-2020-16898 (Windows TCP/IP RCE) is beaten by CVE-2020-16952 (SharePoint post auth file inclusion leading to RCE). CVE-2020-16952 has an exploit out and when combined with password spraying/phishing for creds s a threat right now - reddit.com/r/blueteamsec/…
Build your own AD with 0 effort. 1) blog.focal-point.com/how-to-build-a… 2) Populate it github.com/davidprowe/Bad… 3) Add misconfigurations medium.com/@vartaisecurit…
#infosec caption it. I start. When you realize that you are better off with #sysmon + ELK, than with $2M SIEM license quota filled with firewall log data
Good news! Remember that robot dog you saw with a gun!? It was made by @UnitreeRobotics Seems all you need to dump it in the dirt is @flipper_zero The PDB has a 433mhz backdoor. No need for @gnuradio! github.com/flipperdevices… cc/ @UnitreeRobot007 @IrvingRobotics @shunweicapital
If you are bored by breaking software written by underpayed developers or evading security configurations set by overworked administrators - try a new challenge and do the world a favor ...
United States Trends
- 1. #GMMTV2025 1,15 Mn posts
- 2. Good Tuesday 21,7 B posts
- 3. Irene 252 B posts
- 4. MILKLOVE ACTRESSES ERA 267 B posts
- 5. Dayton 6.123 posts
- 6. #26Nov 1.286 posts
- 7. Chargers 58 B posts
- 8. #LikeAFlower_DDAY 28,3 B posts
- 9. Kerr 8.880 posts
- 10. Canada and Mexico 71 B posts
- 11. Mexico and Canada 71 B posts
- 12. Seth Trimble N/A
- 13. Quentin Johnston 6.412 posts
- 14. Buy American 3.852 posts
- 15. Tariffs 123 B posts
- 16. #Dragula N/A
- 17. #BO6Sweepstakes N/A
- 18. Herbert 20,3 B posts
- 19. Alec Baldwin 5.323 posts
- 20. Maui 16,5 B posts
Who to follow
-
BZHack
@asso_bzhack -
ESD Cybersecurity Academy
@esd_academy -
ZeyRoxx
@Zey_Roxx -
Lucie
@mllejedi -
k_lfa 🇫🇷
@K_lfaa -
Pierre_Adams
@Peter80702224 -
VirtualSamurai
@VirtualSamuraii -
jean vivine
@JeanVivine -
Poltergiss
@P0lterg1ss -
croucroute
@_croucroute_ -
Bub
@_Bubulle -
Égalité Discriminations AcDijon
@EgaliteAcDijon
Something went wrong.
Something went wrong.