Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile
Christophe Tafani-Dereeper

@christophetd

302
Location: bsky.app/profile/christ…

ID: 71315033

linkhttps://christophetd.fr calendar_today03-09-2009 17:55:09

10,10K Tweet

5,5K Followers

1,1K Following

Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Just in time for fwd:cloudsec Europe, Stratus Red Team now supports 6 Microsoft Entra ID (Azure AD) attack techniques!🌩️ 😈 stratus-red-team.cloud/attack-techniq… brought to you by my awesome colleague Katie Knowles and yours truly!

Just in time for fwd:cloudsec Europe, Stratus Red Team now supports 6 Microsoft Entra ID (Azure AD) attack techniques!🌩️ 😈

stratus-red-team.cloud/attack-techniq…

brought to you by my awesome colleague <a href="/_sigil/">Katie Knowles</a> and yours truly!
Scott Piper (@0xdabbad00) 's Twitter Profile Photo

Oof, AWS had a bug that allowed Transit Gateway peering requests to be accepted by the requestor, so an attacker could accept their own requests and peer to any gateway. The prevention logic for this was only in the web console UI, not the API. 😞 engineering.doit.com/aws-transit-ga…

fwd:cloudsec (@fwdcloudsec) 's Twitter Profile Photo

We're incredibly excited that fwd:cloudsec Europe is happening tomorrow, in Brussels. All the talks will be livestreamed on YouTube starting from 9 a.m. CEST at youtube.com/live/oD-d9B71y…, don't miss it! Schedule: fwdcloudsec.org/conference/eur…

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

I’ve had this research from Katie Knowles bookmarked for a thorough read through. Excellent technical dive into abusing AU’s in #EntraID, and appreciate the balance of the article in highlighting the benefits of AU’s and their power for good at the same time 1/x #Entra #infosec

Heal.dev (@healdevhq) 's Twitter Profile Photo

Today we’re happy to announce that heal.dev is moving to private Beta. At heal, we’re building an AI-powered software testing tool that lets you automate end-to-end tests from natural language prompts. Here's our demo! youtube.com/watch?v=tjMoJh…

Today we’re happy to announce that heal.dev is moving to private Beta. At heal, we’re building an AI-powered software testing tool that lets you automate end-to-end tests from natural language prompts.

Here's our demo! 
youtube.com/watch?v=tjMoJh…
Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Stratus Red Team now supports an Amazon Bedrock attack technique to simulate LLMjacking, thanks to a contribution from Alessandro Brucato! stratus-red-team.cloud/attack-techniq…

Stratus Red Team now supports an Amazon Bedrock attack technique to simulate LLMjacking, thanks to a contribution from <a href="/_brucedh/">Alessandro Brucato</a>!

stratus-red-team.cloud/attack-techniq…
Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Excited to share some research I've been working on for the past few months, based on real-world data from thousands of environments using AWS, Azure and Google Cloud! datadoghq.com/state-of-cloud…

Eslam Salem (@net_code) 's Twitter Profile Photo

Fresh from the oven 📷 Analysis of NPM malicious packages connected to contagious interview campaign. securitylabs.datadoghq.com/articles/tenac…

Datadog, Inc. (@datadoghq) 's Twitter Profile Photo

Our team created a K8s sidecar container to support cross-cloud access in a multi-cloud environment. It simplifies access to AWS, Azure, and Google Cloud resources w/o needing config changes to apps. Join us on Nov 5 for DD On Cloud Workload Identities: dtdg.co/ddon1124-twitt…

Our team created a K8s sidecar container to support cross-cloud access in a multi-cloud environment. It simplifies access to AWS, Azure, and Google Cloud resources w/o needing config changes to apps. Join us on Nov 5 for DD On Cloud Workload Identities: dtdg.co/ddon1124-twitt…
Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Fun with Google Cloud's default service accounts (and how to leverage them for offensive purposes) securitylabs.datadoghq.com/articles/googl…

Nick Frichette (@frichette_n) 's Twitter Profile Photo

I’m very excited for this to be released! RCPs cover a need to restrict external access to resources across your organization. Plus its a whole new policy type to consider! buff.ly/4fpQpx2

Aidan W Steele (@__steele) 's Twitter Profile Photo

Back in 2022 I started a project I called vpcshark. Since then, AWS has launched three generations of EC2 instances without traffic mirroring support. So I figured I might as well open source it, might be useful to someone. github.com/aidansteele/vp…