woodspeed (@wucpi) 's Twitter Profile
woodspeed

@wucpi

2019 Jenkins Security MVP |
CAWASP, CARTP, CRT, OSCP, eWPT, eWPTX, eMAPT |
Views and opinions are my own.

ID: 334253995

linkhttp://www.blackwombat.com calendar_today12-07-2011 20:20:18

10,10K Tweet

423 Takipçi

944 Takip Edilen

DefCamp (@defcampro) 's Twitter Profile Photo

At #DefCamp 2024, you’ll dive into the world of Azure Policy with 🎙 Viktor Gazdag and discover how it can be tweaked to create a backdoor in the cloud. Sounds awesome, right? Grab your ticket today 👉 def.camp/tickets/

At #DefCamp 2024, you’ll dive into the world of Azure Policy with 🎙 Viktor Gazdag and discover how it can be tweaked to create a backdoor in the cloud.

Sounds awesome, right? Grab your ticket today 👉 def.camp/tickets/
/r/netsec (@_r_netsec) 's Twitter Profile Photo

I wrote a password spraying tool to use against M365 accounts which relies on the error messaging from Microsoft to gather additional details against a target. github.com/TheresAFewCono…

Clint Gibler (@clintgibler) 's Twitter Profile Photo

🛡️ Mitigating Attack Vectors in GitHub Workflows Covers: - Running untrusted code in privileged workflows - Code injections - Vulnerable Actions - Malicious releases - Tag-Renaming attacks - Imposter commits - Usafe use of caches By OpenSSF openssf.org/blog/2024/08/1…

DEF CON (@defcon) 's Twitter Profile Photo

The #defcon32 presentations are now live and availablle for your perusal on the #DEFCON media server, free of all commercials, data capture and pesky algorithms. We suggest clearing some disk space and personal time this weekend to snatch up some of the many, many jewels our

The #defcon32 presentations are now live and availablle for your perusal on the #DEFCON media server, free of all commercials, data capture and pesky algorithms. We suggest clearing some disk space and personal time this weekend to snatch up some of the many, many jewels our
Clint Gibler (@clintgibler) 's Twitter Profile Photo

🛠️ zizmor A tool for finding security issues in GitHub Actions CI/CD setups Detects template injections, impostor commits, credential leaks, etc. See src/audit for the check implementations. By Trail of Bits' @8x5clPW2 github.com/woodruffw/zizm…

Clint Gibler (@clintgibler) 's Twitter Profile Photo

⛓️ Attestations: A new generation of signatures on PyPI Overview of PyPI's new index-hosted digital attestations, which is enabled by default for packages published to PyPI using Trusted Publishing, automatically providing build provenance By Trail of Bits

DefCamp (@defcampro) 's Twitter Profile Photo

Imagine turning a cloud security tool into a weapon—Viktor Gazdag is currently revealing how Azure Policy, which organizations typically use to enforce compliance, can be twisted to create backdoors in cloud environments.

Imagine turning a cloud security tool into a weapon—Viktor Gazdag is currently revealing how Azure Policy, which organizations typically use to enforce compliance, can be twisted to create backdoors in cloud environments.
Rami McCarthy (@ramimacisabird) 's Twitter Profile Photo

One recent report highlighted that roughly a third of their customers have “at least one cloud workload that is publicly exposed, critically vulnerable and highly privileged.” If you’re this vendor, should I really buy your product? ramimac.me/state-of-cloud…

DefCamp (@defcampro) 's Twitter Profile Photo

Time for a Friday read! 📖 Miss that #DefCamp vibe? Want to relive the best moments? We've got you covered with some epic highlights to take you right back. Dive in and enjoy 👉 def.camp/defcamp-2024-h…

Scott Piper (@0xdabbad00) 's Twitter Profile Photo

I looked at all the AWS OIDC integrations I could find to identify how they might be misconfigured and to understand the variations that different vendors have in how they set these up. wiz.io/blog/avoiding-…

Andy Robbins (@_wald0) 's Twitter Profile Photo

In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attack-…

Cloud Village (@cloudvillage_dc) 's Twitter Profile Photo

woodspeed's talk on "Creating Azure Policy Compliant Backdoor" is now released on YouTube! youtu.be/gdMx3g62NkE Subscribe and stay tuned for more videos! Happy Hacking. #CloudSecurity #DefCon32

BSidesBUD 🇭🇺 (@bsidesbud) 's Twitter Profile Photo

📢ANNOUNCEMENT📢⏳2 months to go! BSidesBUD of Security BSides brings top-tier cybersecurity minds to the stage—don’t miss out! 🔥 🎟 Early bird tickets are still up for grabs! Secure your spot! bsidesbud.com #BSidesBUD2025 #Cybersec #Infosec #securityBSides

📢ANNOUNCEMENT📢⏳2 months to go! BSidesBUD of <a href="/SecurityBSides/">Security BSides</a> brings top-tier cybersecurity minds to the stage—don’t miss out! 🔥 🎟 Early bird tickets are still up for grabs! Secure your spot! bsidesbud.com #BSidesBUD2025 #Cybersec  #Infosec #securityBSides
Ru Campbell (@rucam365) 's Twitter Profile Photo

New video: 1 hour of Conditional Access design deep dive. I always get asked to share Conditional Access templates, so I roped Nate Hutchinson into the first of a few long forms on thinking about robust, scalable, and customizable CA architecture. Watch: youtube.com/watch?v=NSqfUZ…

New video: 1 hour of Conditional Access design deep dive.

I always get asked to share Conditional Access templates, so I roped <a href="/NateHutch365/">Nate Hutchinson</a> into the first of a few long forms on thinking about robust, scalable, and customizable CA architecture.

Watch: youtube.com/watch?v=NSqfUZ…
Cloud Village (@cloudvillage_dc) 's Twitter Profile Photo

The Cloud Village DEF CON 33 schedule is LIVE! ☁ Explore a stacked lineup of comprehensive talks, lightning talks, and tool demos; all focused on real-world cloud security. Line Up: cloud-village.org/dc33#schedule #CloudVillage #DC33 #DEFCON33 #HackerSummerCamp

The Cloud Village <a href="/defcon/">DEF CON</a> 33 schedule is LIVE! ☁

Explore a stacked lineup of comprehensive talks, lightning talks, and tool demos; all focused on real-world cloud security.

Line Up: cloud-village.org/dc33#schedule

#CloudVillage #DC33 #DEFCON33 #HackerSummerCamp