Puneet Thapliyal's Avatar

Puneet Thapliyal

@puneetx.bsky.social

Chief Information Security Officer | Health Care | Startup Advisor | Venture Partner. Advocate for online data privacy rights.

105 Followers  |  704 Following  |  11 Posts  |  Joined: 16.11.2024  |  1.5472

Latest posts by puneetx.bsky.social on Bluesky

The $1.5B Bybit Hack: The Era of Operational Security Failures Has Arrived - The Trail of Bits Blog

blog.trailofbits.com/2025/02/21/t...

23.02.2025 07:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Raw SQL Queries are Actually Better for Security Than ORMs? Have I gone mad? Do I actually recommend not using an ORM and actually gaining a security advantage? Sort of. It's more nuanced but if we're trying to fix SQL injection and related vulnerabilities the...

While ORMs help in preventing SQL Injections , beware of the Mass Assignment security vulnerabilities in ORMs

www.nodejs-security.com/blog/raw-sql...

04.02.2025 18:32 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Backdoor in Chinese-made healthcare monitoring device leaks patient data Functionality in the device firmware sends patient data to a hardcoded IP address that also downloads and executes binary files without the ownerโ€™s knowledge.

Backdoor in Chinese-made healthcare monitoring device leaks patient data (Contec CMS8000 and the Epsimed MN-120)

www.csoonline.com/article/3814...

03.02.2025 18:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
World's First MIDI Shellcode Blog post about a reverse engineering project

Worldโ€™s First MIDI Shellcode psi3.ru/blog/swl01u/

06.01.2025 00:15 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
U.S. Army Soldier Arrested in AT&T, Verizon Extortions Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m, a cybercriminal who has been selling and leaking sensitive customer call records stol...

U.S. Army Soldier Arrested in AT&T, Verizon Extortions

krebsonsecurity.com/2024/12/u-s-...

31.12.2024 09:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
China-backed hackers breached US Treasury workstations | CNN Business The US Treasury Department notified lawmakers on Monday that a China state-sponsored actor infiltrated Treasury workstations in what officials are describing as a โ€œmajor incident.โ€

China-backed hackers breached US Treasury workstations by compromising a key from BeyondTrust PAM solution.

The cybersecurity tools themselves are leading to major hacks.

www.cnn.com/2024/12/30/i...

31.12.2024 00:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Cybersecurity firm's Chrome extension hijacked to steal users' data At least five Chrome extensions were compromised in a coordinated attack where a threat actorย injected code that steals sensitive information from users.

Cybersecurity firm Cyberhaven's Chrome extension hijacked to steal users' data.. smh

www.bleepingcomputer.com/news/securit...

27.12.2024 21:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
From File Upload To LFI: A Journey To Exploitation Recently I had a client that asked for a black-box pentest for a new web app that the company was about to release. The objective of thisโ€ฆ

infosecwriteups.com/from-file-up...

15.12.2024 20:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

go.bsky.app/53iqbXu

26.11.2024 17:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CSDL | IEEE Computer Society

Understanding the Efficacy of Phishing Training in Practice

www.computer.org/csdl/proceed...

20.11.2024 19:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Results about you

TIL: Google has a special tool to help you monitor and remove your personal information (name, address, email address, phone) should it appear in Google search results.

myactivity.google.com/results-abou...

16.11.2024 01:31 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@puneetx is following 20 prominent accounts