Alex Hernandez's Avatar

Alex Hernandez

@alt3kx.bsky.social

Red Teamer | PentTester | Bug Bounty | 0day guy! | Researcher | Lone Wolf...l opinions expressed are mine πŸ‡ͺπŸ‡Ί πŸ΄β€β˜ οΈ πŸ”— https://alt3kx.github.io/

27 Followers  |  98 Following  |  1 Posts  |  Joined: 21.11.2024  |  1.5305

Latest posts by alt3kx.bsky.social on Bluesky


Some great stuff this week!

22.02.2025 01:46 β€” πŸ‘ 6    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
machang-r7's assessment of CVE-2025-27218 | AttackerKB On January 6, 2025, Sitecore published a security bulletin, SC2024-002-624693 , for a critical unauthenticated remote code execution (RCE) vulnerability affect…

Root cause analysis of Sitecore XM + XP remote code execution CVE-2025-27218 via @rapid7.com's pen testing team attackerkb.com/assessments/...

05.03.2025 23:05 β€” πŸ‘ 8    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0

Ok well guess I’m over on here now too. Where’s infosec at?

24.11.2024 08:19 β€” πŸ‘ 24    πŸ” 3    πŸ’¬ 3    πŸ“Œ 0
Preview
Bug bounty hunters & content creators Join the conversation

The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off!

go.bsky.app/GD7hKPX

23.11.2024 16:21 β€” πŸ‘ 87    πŸ” 22    πŸ’¬ 19    πŸ“Œ 4

We see CVE-2024-0012 exploitation attempts since Nov 18th. We are now also observing CVE-2024-9474.
IoCs: unit42.paloaltonetworks.com/cve-2024-001...

Check for signs of compromise and patch:
security.paloaltonetworks.com/CVE-2024-0012
security.paloaltonetworks.com/CVE-2024-9474

19.11.2024 14:26 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
Senior Security Researcher - United Kingdom Rapid7's vulnerability and exploit research team does industry-leading attack research that prioritizes and uncovers risk for organizations worldwide. We’re looking for an experienced vulnerability re...

New platform, must inaugurate with a hiring post. Rapid7's vulnerability research team is expanding! Come join us if you wanna analyze (or find) some Hot Vulnsβ„’, write some exploits, and occasionally reverse engineer attacks our MDR/IR folks see. Remote UK: careers.rapid7.com/jobs/senior-...

22.11.2024 02:40 β€” πŸ‘ 6    πŸ” 6    πŸ’¬ 0    πŸ“Œ 0
Preview
Running GDB in the Browser GDB inside a Linux in a x86 Virtual Machine using Web Assembly running in the browser. Crazy?

blog.wokwi.com/running-gdb-... is pretty cool!

21.11.2024 18:17 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Metasploit Weekly Wrap-Up 11/22/2024 | Rapid7 Blog

Roses are red, the sky is blue β€”
This week's #Metasploit wrap-up has Windows secrets dump improvements (and a JetBrains TeamCity login scanner, too!)

We're bad at poetry but good at shells. Check out the latest. www.rapid7.com/blog/post/20...

22.11.2024 21:01 β€” πŸ‘ 11    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Preview
Security Signals: Making Web Security Posture Measurable At Scale

Happy to publish the effort of my last five years: Security Signals.

research.google/pubs/securit...

17.11.2024 13:02 β€” πŸ‘ 27    πŸ” 7    πŸ’¬ 0    πŸ“Œ 1

yep !

21.11.2024 08:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@alt3kx is following 19 prominent accounts