Alvaro Muñoz 🇺🇦 (@pwntester) 's Twitter Profile
Alvaro Muñoz 🇺🇦

@pwntester

Security Researcher with @XBOW. CTF #int3pids. Opinions here are mine! bluesky: pwntester.bsky.social

ID: 18075045

linkhttp://www.pwntester.com calendar_today12-12-2008 12:23:38

5,5K Tweet

13,13K Followers

509 Following

Adnan Khan (@adnanthekhan) 's Twitter Profile Photo

You know what else is interesting about Kong? Alvaro Muñoz 🇺🇦 reported an Actions injection (which is probably still viable) that the Kong security team claimed was not a valid report. securitylab.github.com/advisories/GHS…

Alvaro Muñoz 🇺🇦 (@pwntester) 's Twitter Profile Photo

December was my last month at GitHub, and after a refreshing Xmas break, I’m thrilled to announce that I’ll be starting a new adventure at XBOW! 🚀 Grateful for all the memories and experiences at GitHub, and can’t wait to help shaping the future of security testing!

GitHub Security Lab (@ghsecuritylab) 's Twitter Profile Photo

How to secure your GitHub Actions workflows with CodeQL. Dive into this actionable supply chain security research from Alvaro Muñoz 🇺🇦 . This work resulted in dozens of high impact supply chain findings and, most importantly, added CodeQL support for your GitHub workflows!

How to secure your GitHub Actions workflows with CodeQL. Dive into this actionable supply chain security research from <a href="/pwntester/">Alvaro Muñoz 🇺🇦</a> . This work resulted in dozens of high impact supply chain findings and, most importantly, added CodeQL support for your GitHub workflows!
Adnan Khan (@adnanthekhan) 's Twitter Profile Photo

If you maintain GitHub Actions workflows for any open source project of consequence you owe it to yourself and anyone who uses your software to read through and understand this blog post: github.blog/security/appli…

Jaroslav Lobačevski 🇱🇹🇺🇦jaras@infosec.exchange (@yarlob) 's Twitter Profile Photo

The most important takeaway is that CodeQL taint support and a swarm of queries for GitHub Actions by Alvaro Muñoz 🇺🇦 are in Public Review. Be sure to use it! github.blog/changelog/2024…

Ekoparty | Hacking everything (@ekoparty) 's Twitter Profile Photo

¿Cuáles son los desafíos principales de trabajar en #ciberseguridad en GitHub ? 🤔 Alvaro Muñoz 🇺🇦, Security Researcher en GitHub Security Lab, pasó por el Lado B de la #EKO2024 y nos contó todo sobre su trabajo: retos, vulnerabilidades descubiertas, y cómo enfrenta trabajar en un

Leandro Barragan (@lean0x2f) 's Twitter Profile Photo

I’m thrilled to announce that I’ll be joining the brilliant minds at the XBOW team next week! After 10 years of breaking things for a living, it’s time to get back to building… this time, building an AI product that breaks things in a scalable, safe, and automated way 🦾

I’m thrilled to announce that I’ll be joining the brilliant minds at the XBOW team next week!
After 10 years of breaking things for a living, it’s time to get back to building… this time, building an AI product that breaks things in a scalable, safe, and automated way 🦾
Nico Waisman (@nicowaisman) 's Twitter Profile Photo

One of the benefits of working at XBOW, is you get to see first hand some amazing traces on how XBOW autonomously find new zero days. Trust me, Alvaro Muñoz 🇺🇦 is not easy to impress

One of the benefits of working at <a href="/Xbow/">XBOW</a>, is you get to see first hand some amazing traces on how XBOW autonomously find new zero days.
Trust me, <a href="/pwntester/">Alvaro Muñoz 🇺🇦</a> is not easy to impress
XBOW (@xbow) 's Twitter Profile Photo

Real security is POC||GTFO – and XBOW agrees. We’re releasing technical deep-dives on cool findings from our journey to the top of the HackerOne US leaderboard. The first is a zero-day XSS in Palo Alto Networks GlobalProtect by Alvaro Muñoz 🇺🇦 xbow.com/blog/xbow-glob…

Real security is POC||GTFO – and XBOW agrees.
We’re releasing technical deep-dives on cool findings from our journey to the top of the HackerOne US leaderboard.

The first is a zero-day XSS in Palo Alto Networks GlobalProtect by <a href="/pwntester/">Alvaro Muñoz 🇺🇦</a> 

xbow.com/blog/xbow-glob…
Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

One of the things I’m proud of at @XBOW is that we try to be open about the technical details - there’s a lot of AI hype and it’s reasonable to be skeptical! Here’s Nico Waisman going into the details of our climb to the top of the US H1 leaderboard:

Brendan Dolan-Gavitt (@moyix) 's Twitter Profile Photo

We’re doing deep dives on individual, particularly cool vulnerabilities XBOW found in live targets over the next few weeks. The first, Alvaro Muñoz 🇺🇦’s writeup of an XSS that turned out to be a 0day in Palo Alto Networks GlobalProtectVPN, is live now! x.com/xbow/status/19…