Stefan Kraxberger (@skraxberger) 's Twitter Profile
Stefan Kraxberger

@skraxberger

cyber security & data privacy enthusiast, nature lover #cybersecurity, #infosec

ID: 25474934

linkhttps://www.secinto.com calendar_today20-03-2009 07:17:09

1,1K Tweet

545 Takipçi

3,3K Takip Edilen

A1 (@a1telekom) 's Twitter Profile Photo

***Kundeninfo*** Achtung ❗ Aktuell sind zahlreiche gefälschte SMS mit Links, die zu einer Schadsoftware führen, im Umlauf. Bei Erhalt solcher Nachrichten bitte diese sofort löschen und keinesfalls auf die Links klicken. Mehr dazu im Artikel! 👇🏼

Stefan Kraxberger (@skraxberger) 's Twitter Profile Photo

I need help with #virtualization. Are there any good writeups on how to customize recovery isos with dedicated drive and system configurations, so that they can be run smoothly as a virtual machine? Got the point that recovery has worked but execution is veeery slow! #vm #win10

TU Graz (@tugraz) 's Twitter Profile Photo

Researchers at TU Graz publish #Æpic Leak and #SQUIP, two new attacks that exploit vulnerabilities in computer hardware. tugraz.at/en/tu-graz/ser…

Stefan Kraxberger (@skraxberger) 's Twitter Profile Photo

The First Amendment, freedom of the press, and the life of Julian Assange are at stake. On 20 January, join the @progintl for the fourth sitting of the #BelmarshTribunal. act.progressive.international/belmarsh-tribu…

Joseph Cox (@josephfcox) 's Twitter Profile Photo

New: we proved it could be done. I used an AI replica of my voice to break into my bank account. The AI tricked the bank into thinking it was talking to me. Could access my balances, transactions, etc. Shatters the idea that voice biometrics are foolproof vice.com/en/article/dy7…

Christian Folini (@chrfolini) 's Twitter Profile Photo

.Jorgo Ananiadis 🪠 posted an assessment of the lacking HTTP security headers on xplain.sh - using it as tellsign for the poor security posture of #Xplain as a whole. x.com/JorgoA/status/… Let's look at this in detail - a 🧵.

Mathy Vanhoef (@vanhoefm) 's Twitter Profile Photo

New #TunnelCrack flaw can break a large majority of VPNs: we can trick a VPN into leaking traffic outside the protected VPN tunnel. Our tests indicate that this is a widespread design issue. For a demo, more details, and the USENIX Security paper, see tunnelcrack.mathyvanhoef.com

Daniel Moghimi (@flowyroll) 's Twitter Profile Photo

Dropping #Downfall, exploiting speculative forwarding of 'Gather' instruction to steal data from hardware registers. #MeltdownSequel - Practical to exploit (POC/Demo) - Defeat all isolation boundaries (OS, VM, SGX) - Bypass all Meltdown/MDS mitigations. downfall.page

PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

We've just published 'Smashing the state machine: the true potential of web race conditions' by James Kettle! Dive in to arm yourself with novel techniques & tooling, and help reshape this attack class: portswigger.net/research/smash…

ARCHIVED: Jen Easterly (@cisajen) 's Twitter Profile Photo

🚨NEW: Urging all organizations to review this guidance & take steps to reduce your risk to this widespread vulnerability.🙏Huge Thanks to The Boeing Company for providing key info for this advisory--a terrific example of operational collaboration in action: go.dhs.gov/oHd.

🚨NEW: Urging all organizations to review this guidance &amp; take steps to reduce your risk to this widespread vulnerability.🙏Huge Thanks to <a href="/Boeing/">The Boeing Company</a> for providing key info for this advisory--a terrific example of operational collaboration in action: go.dhs.gov/oHd.
Truffle Security (@trufflesec) 's Twitter Profile Photo

🧐 Recently, we found a GitHub vulnerability exposing private data. 😱 Now, a similar issue in Microsoft Azure DevOps (ADO) might be even worse. 🔓 Commits in Private Forks are actually Public! More details 👉 trufflesecurity.com/blog/you-can-a…

🧐 Recently, we found a GitHub vulnerability exposing private data.

😱 Now, a similar issue in <a href="/Azure/">Microsoft Azure</a> DevOps (ADO) might be even worse.

🔓 Commits in Private Forks are actually Public!

More details 👉 trufflesecurity.com/blog/you-can-a…
Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

Our talk at #BHEU is done! Hope you all enjoyed it. 😉 A detailed blog is on the way, but in the meantime, check out the pre-alpha website worst.fit for early access and the slides! Huge thanks to Black Hat and my awesome co-presenter splitline 👁️🐈‍⬛! 🐈‍