
Anirudh Anand
@a0xnirudh
Head of Product Security Engineering at @CRED_club | Application Security ♥ | CTF lover - @teambi0s | Security Trainer - @7asecurity | Tweets are my own.
ID: 115002905
https://blog.0daylabs.com 17-02-2010 08:46:11
437 Tweet
3,3K Takipçi
697 Takip Edilen

An Obscure Github Actions Workflow Vulnerability in Google's Flank leading to leaking Google service account credentials & Github Tokens (write access) with Google VRP (Google Bug Hunters) awarding $7500 ! A nice read from Adnan Khan 🔥 adnanthekhan.com/2024/04/15/an-…



Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (pwnthem0le) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…



CVE-2023-46851: #Apache Allura (< 1.15.0) Arbitrary File Read via Discussion Import leading to Remote Code Execution (#RCE) via Signed Serialized Session, amazing read from Sonar Research 🔥 sonarsource.com/blog/dangerous…



Race Condition on Changing Email Leading to Arbitrary Email Forgery by Azhari Harahap 🤠 link.medium.com/jZUVZpf1WIb



Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from Ahmed Elmorsi 🇵🇸 🔥 medium.com/@ahmedelmorsy3…




Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from Johann Rehberger embracethered.com/blog/posts/202…





