Yuval Avrahami (@yuvalavra) 's Twitter Profile
Yuval Avrahami

@yuvalavra

Container & Cloud Security אבטחת חמגשים

ID: 941267075842101249

calendar_today14-12-2017 11:22:13

153 Tweet

796 Followers

363 Following

Kubesploit (@kubesploit) 's Twitter Profile Photo

RBAC-police is a CLI tool that lets you evaluate the RBAC permissions of service accounts, pods and nodes in Kubernetes clusters through policies written in Rego ➤ github.com/PaloAltoNetwor…

Yuval Avrahami (@yuvalavra) 's Twitter Profile Photo

דחפו לי כדור הרגעה לפני ניתוח לייזר בעיניים כיף גדול וייבים טובים אווירה חשמל שוקל לאמץ ביום יום

gafnit (@gafnitav) 's Twitter Profile Photo

If you could infect any image on AWS ECR Public Gallery, which one would you choose? 👀 blog.lightspin.io/aws-ecr-public…

Yuval Avrahami (@yuvalavra) 's Twitter Profile Photo

Hardly believe it but I won the 2022 GCP VRP prize! Massive THANKS to the Google VRP (Google Bug Hunters) team and my incredible colleagues Palo Alto Networks ❤️ Hats off to all the winners for their fantastic research🎉🎉 security.googleblog.com/2023/06/google…

faulty *ptrrr (@0x_shaq) 's Twitter Profile Photo

when I find a new attack surface but I need to convince my employer to give me time for research even though I have zero evidence whether it’s gonna work or not

Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

We found a new container escape affecting all container runtimes using @NVIDIA GPUs. The crazy part? The exploit is just three lines long 🤯 This is the story of #NVIDIAScape 🧵👇

We found a new container escape affecting all container runtimes using @NVIDIA GPUs.

The crazy part?
The exploit is just three lines long 🤯

This is the story of #NVIDIAScape 🧵👇
sagitz (@sagitz_) 's Twitter Profile Photo

Are you up for a challenge? I authored a container security challenge for the Wiz Ultimate Cloud Security Championship 🤩 Put your skills to the test and try it out! 👇 cloudsecuritychampionship.com/challenge/2

Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

We (+Ronen Shustin) hacked NVIDIA's Triton AI server by abusing a single error message🚨 The result is unauthenticated RCE allowing attackers to compromise the server and steal proprietary AI models🤯 For more details & mitigations check out our blog Wiz wiz.io/blog/nvidia-tr…

We (+<a href="/ronenshh/">Ronen Shustin</a>) hacked NVIDIA's Triton AI server by abusing a single error message🚨

The result is unauthenticated RCE allowing attackers to compromise the server and steal proprietary AI models🤯

For more details &amp; mitigations check out our blog <a href="/wiz_io/">Wiz</a> wiz.io/blog/nvidia-tr…
Wiz (@wiz_io) 's Twitter Profile Photo

Introducing ZERODAY.CLOUD🕵️‍♀️ Be the first to participate in the first-of-its-kind cloud hacking competition. 🤝 WIN PRIZES from our 4.5M$ prize pool. 💰 Register your exploit > zeroday.cloud Microsoft Security Response Center Amazon Web Services Google Cloud