phosphore (@lorenzostella) 's Twitter Profile
phosphore

@lorenzostella

Application Security @ wave.com, securing affordable financial infra for Sub-Saharan Africa
ex @Doyensec
Partner @ tumpi.net (AS62233)
@jbzteam member

ID: 1475223672

linkhttps://lorenzostella.it calendar_today01-06-2013 17:23:52

1,1K Tweet

859 Followers

462 Following

Clint Gibler (@clintgibler) 's Twitter Profile Photo

😈 Cloud services as exfiltration mechanisms Exfiltrate info from a network with no permissions, bypassing data perimeter IAM conditions → Make a request to attacker-controlled S3 bucket → Even if denied, info in request is logged (exfiltrated) airwalkreply.com/cloud-services…

😈 Cloud services as exfiltration mechanisms

Exfiltrate info from a network with no permissions, bypassing data perimeter IAM conditions

→  Make a request to attacker-controlled S3 bucket
→  Even if denied, info in request is logged (exfiltrated)

airwalkreply.com/cloud-services…
Doyensec (@doyensec) 's Twitter Profile Photo

Learn more about how having a security-oriented scheduling strategy for #k8s can limit opportunities for lateral movement within your environment in our latest blog post. #doyensec #Kubernetes #security #appsec blog.doyensec.com/2024/01/23/k8s…

Learn more about how having a security-oriented scheduling strategy for #k8s can limit opportunities for lateral movement within your environment in our latest blog post.
#doyensec #Kubernetes #security #appsec

blog.doyensec.com/2024/01/23/k8s…
Doyensec (@doyensec) 's Twitter Profile Photo

🎉PortSwigger 's "Top 10 Web Hacking Techniques" voting is open. #Doyensec has 2 🔥 entries - vote now! 1️⃣ A New Vector For “Dirty” Arbitrary File Write to RCE - Maxence SCHMITT & phosphore 2️⃣ SSRF Cross Protocol Redirect Bypass - Szymon Drosdzol portswigger.net/polls/top-10-w…

Aleandro (@drw0if) 's Twitter Profile Photo

I usually don't like to talk about myself cause I think I have nothing to say. But this could be a lot useful to someone who is starting his/her career in the security field. So thank you to Doyensec for pushing me out of my comfort zone!

phosphore (@lorenzostella) 's Twitter Profile Photo

Vendor-specific implementations are a goldmine for 0 interaction, high-impact bugs. Time for security research to refocus beyond AOSP's already strong security assurances

phosphore (@lorenzostella) 's Twitter Profile Photo

The truth is, a non-negligible part of the infosec crowd lacks a solid understanding of the systems they aim to protect. There's a difference between asking open, constructive questions ('Is it secure? Could it be abused?') and jumping straight to sensational claims about APTs/TI

Shivers (@thinkingshivers) 's Twitter Profile Photo

It's hard to believe, but due to H100 restrictions, DeepSeek was forced to train R1 manually, with thousands of Chinese citizens holding flags to act as logic gates.

It's hard to believe, but due to H100 restrictions, DeepSeek was forced to train R1 manually, with thousands of Chinese citizens holding flags to act as logic gates.
Sterling Crispin 🕊️ (@sterlingcrispin) 's Twitter Profile Photo

This is one of the craziest ideas I've ever seen. He converted a drawing of a bird into a spectrogram (PNG -> Soundwave) then played it to a Starling who sung it back reproducing the PNG. Using the birds brain as a hard drive with 2mbps read write speed. youtube.com/watch?si=HMtVd…

This is one of the craziest ideas I've ever seen. He converted a drawing of a bird into a spectrogram (PNG -> Soundwave) then played it to a Starling who sung it back reproducing the PNG.

Using the birds brain as a hard drive with 2mbps read write speed. 
youtube.com/watch?si=HMtVd…
Denis Laskov 🇮🇱 (@it4sec) 's Twitter Profile Photo

Injecting (or hiding) fire, barcodes, or humans into CCD cameras with electromagnetic shots. 📷 💉🌲🔥🌲 More details on: LinkedIn: linkedin.com/posts/dlaskov_… Substack: it4sec.substack.com/p/injecting-or…

Injecting (or hiding) fire, barcodes, or humans into CCD cameras with electromagnetic shots. 📷 💉🌲🔥🌲

More details on:
LinkedIn: linkedin.com/posts/dlaskov_…
Substack: it4sec.substack.com/p/injecting-or…