Dave Vieira-Kurz (@secalert) 's Twitter Profile
Dave Vieira-Kurz

@secalert

🇧🇷 Full-time Security Ninja since 2007. I have Shuriken throwing stars in my tool chain. 🇩🇪

ID: 273119401

linkhttps://window.name calendar_today27-03-2011 21:38:17

2,2K Tweet

3,3K Followers

169 Following

Corben Leo (@hacker_) 's Twitter Profile Photo

I hacked a large company (70k+ employees) through social engineering. Legally of course. • I set up the infrastructure • Scraped names & emails with LinkedIn • Sent 200 phishing emails. I had access to their AWS console within 2 minutes. And much more:

Frank Boldewin (@r3c0nst) 's Twitter Profile Photo

github.com/vitoplantamura… => „BugChecker is a SoftICE-like kernel and user mode debugger, supporting Windows versions from XP to 11, both x86 and x64)“ #SoftIce #Debugging #Oldschool

github.com/vitoplantamura…  => „BugChecker is a SoftICE-like kernel and user mode debugger, supporting Windows versions from XP to 11, both x86 and x64)“ #SoftIce #Debugging #Oldschool
Rafay Baloch (@rafaybaloch) 's Twitter Profile Photo

Pleased to share that I'll be delivering the keynote at the 10th Information Security Conference in Greece on Feb 22, 2023. My talk: "The Future of Cyber Security: Preparing for the Unforeseen" #cybersecurity #infosec #futureofsecurity

Pleased to share that I'll be delivering the keynote at the 10th Information Security Conference in Greece on Feb 22, 2023. My talk: "The Future of Cyber Security: Preparing for the Unforeseen"  
#cybersecurity #infosec #futureofsecurity
vx-underground (@vxunderground) 's Twitter Profile Photo

The Department of Justice has announced the arrest of Anatoly Legkodymov. Legkodymov, the Founder and Majority Owner of Bitzlato Ltd, is accused of laundering more than $700,000,000 in illicit funds from ransomware groups and Hydra Marketplace More info: justice.gov/usao-edny/pr/f…

dragosr (@dragosr) 's Twitter Profile Photo

I'm happy to announce the first keynote speaker at CanSecWest in Vancouver on March 22-24 will be Dino Dai Zovi (Dino A. Dai Zovi) who is always amazingly insightful. secwest.net

Dave Vieira-Kurz (@secalert) 's Twitter Profile Photo

The Mailchimp Security team identified an unauthorized actor accessing one of the tools used by Mailchimp customer-facing teams for customer support and account administration. #hacking #infosec #Mailchimp More: mailchimp.com/january-2023-s…

Florian Hansemann (@cyberwarship) 's Twitter Profile Photo

"deepce: Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)" #infosec #pentest #redteam github.com/stealthcopter/…

"deepce: Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)" 

#infosec #pentest #redteam
github.com/stealthcopter/…
vx-underground (@vxunderground) 's Twitter Profile Photo

tl;dr Threat Actors don't need malicious documents, they just need Google ads and a stolen credit card x.com/vxunderground/…

vx-underground (@vxunderground) 's Twitter Profile Photo

Someone criticized us for using "the LGBTQ flag" in this artwork (made by nico n.), and said they would not follow vx-underground if we supported "the homosexual agenda". We have decided to make that our entire theme for the time being.

Tim Blazytko (@mr_phrazer) 's Twitter Profile Photo

New blog post and updated #binaryninja plugin: "Statistical Analysis to Detect Uncommon Code" We use statistics to identify obfuscation in an #Anticheat, a mobile DRM, a #Windows kernel module & malware. Link: synthesis.to/2023/01/26/unc… Code: github.com/mrphrazer/obfu…

New blog post and updated #binaryninja plugin: "Statistical Analysis to Detect Uncommon Code" We use statistics to identify obfuscation in an #Anticheat, a mobile DRM, a #Windows kernel module & malware.

Link: synthesis.to/2023/01/26/unc…

Code: github.com/mrphrazer/obfu…
Ollie Whitehouse (@ollieatnowhere) 's Twitter Profile Photo

A prototype Burp Suite extension for Enterprise/Pro using the new Montoya API. Leverages the Google Safe Browsing API to check that any URLs in the enumerated site map aren't known to be malicious. Help detect those watering holes! Code 👇 gist.github.com/olliewuk/c518e… [1/2]

A prototype <a href="/Burp_Suite/">Burp Suite</a>  extension for Enterprise/Pro using the new Montoya API. Leverages the Google Safe Browsing API to check that any URLs in the enumerated site map aren't known to be malicious.

Help detect those watering holes!

Code 👇
gist.github.com/olliewuk/c518e…

[1/2]
Johnny Fishcake (@johnnyspandex) 's Twitter Profile Photo

DroppedConnection - a fake VPN server that captures credentials and executes code via the Cisco AnyConnect client. research.nccgroup.com/2023/03/01/mak…

LiveOverflow 🔴 (@liveoverflow) 's Twitter Profile Photo

During a recent code review I noticed something in the VSCode Language Server JSONRPC implementation that made my brain tingle. Why not investigate this on stream? Maybe we find nothing, maybe we find something useful. twitch.tv/liveoverflow

During a recent code review I noticed something in the VSCode Language Server JSONRPC implementation that made my brain tingle.
Why not investigate this on stream? Maybe we find nothing, maybe we find something useful.

twitch.tv/liveoverflow