Yanir Tsarimi (@yanir_) 's Twitter Profile
Yanir Tsarimi

@yanir_

Hacker. I write about security in ways most can understand. Microsoft Most Valuable Researcher ‘22/23/24. @breachproof

ID: 80947228

linkhttps://breachproof.net calendar_today08-10-2009 21:23:38

81 Tweet

3,3K Followers

135 Following

Yanir Tsarimi (@yanir_) 's Twitter Profile Photo

Found a few SSRFs in a Node.js application. Apparently the request package (18M+ Weekly Downloads) allows you to access Unix sockets without needing to change the protocol. http://unix:/var/run/docker.sock 🤨

Scott Piper (@0xdabbad00) 's Twitter Profile Photo

Dan Urson has been the voice of AWS security to many of us. He's the person external researchers interact with when they find issues (or think they find issues) with AWS. Any team would be lucky to have him. linkedin.com/feed/update/ur…

Security Response (@msftsecresponse) 's Twitter Profile Photo

Congratulations to our MSRC 2023 Most Valuable Researchers! Thank you to all the researchers who have helped secure our customers. 👏🎉 Check out our blog for the full list: msft.it/60199yOc9

Congratulations to our MSRC 2023 Most Valuable Researchers! Thank you to all the researchers who have helped secure our customers. 👏🎉

Check out our blog for the full list: msft.it/60199yOc9
sagitz (@sagitz_) 's Twitter Profile Photo

We discovered that by uploading a malicious AI model to @Replicate, a leading AI-as-a-Service platform, we could read and modify prompts of other customers 🤯 Here is exactly how we did it 🧵⬇️

We discovered that by uploading a malicious AI model to @Replicate, a leading AI-as-a-Service platform, we could read and modify prompts of other customers 🤯

Here is exactly how we did it 🧵⬇️
Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

Ever wondered how AI chatbots work? And how can you hack and manipulate their behavior? We (+ Shir) created an AI CTF to highlight security pitfalls we observed in the wild. Think you can hack your way to a flight ticket? 🛩️ 👉 Check it out: promptairlines.com

Ever wondered how AI chatbots work? And how can you hack and manipulate their behavior? 
We (+ <a href="/shirtamari/">Shir</a>) created an AI CTF to highlight security pitfalls we observed in the wild. Think you can hack your way to a flight ticket? 🛩️

👉 Check it out: promptairlines.com
liad eliyahu (@liadeliyahu) 's Twitter Profile Photo

🚨We could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Here’s everything you need to know about the #ALBeast vulnerability discovered by Miggo Security

🚨We could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Here’s everything you need to know about the #ALBeast vulnerability discovered by <a href="/MiggoSecurity/">Miggo Security</a>
Yanir Tsarimi (@yanir_) 's Twitter Profile Photo

Hello to everyone coming from Daniel Boctor's YouTube video. Happy to see you liked my research. Will soon share new AI/cloud research with an even greater impact

liad eliyahu (@liadeliyahu) 's Twitter Profile Photo

1/ 🚨Recently, our research team found CVE-2025-25182, A critical security finding in Government Communications Headquarters (GCHQ), the UK's intelligence and security agency, maintained project, Stroom.

1/ 🚨Recently, our research team found CVE-2025-25182, A critical security finding in Government Communications Headquarters (GCHQ), the UK's intelligence and security agency, maintained project, Stroom.
Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

We (+sagitz Ronen Shustin Hillai Ben-Sasson) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact? From zero permissions ➡️ to complete cluster takeover 🤯 This is the story of #IngressNightmare 🧵⬇️

We (+<a href="/sagitz_/">sagitz</a> <a href="/ronenshh/">Ronen Shustin</a> <a href="/hillai/">Hillai Ben-Sasson</a>) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX".

The impact?

From zero permissions ➡️ to complete cluster takeover 🤯

This is the story of #IngressNightmare 🧵⬇️