
Shir
@shirtamari
Head of Research @wiz_io ๐งโโ๏ธ
ID: 1335908692169003008
07-12-2020 11:27:24
280 Tweet
2,2K Followers
506 Following






๐จWe could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Hereโs everything you need to know about the #ALBeast vulnerability discovered by Miggo Security


Excited to share some big personal news today, I have joined Wiz to enhance their Risk & Threat Exposure Management and build a new disruptive Risk MDR offering. It's been quite a ride working on Shockwave - External Attack Surface Management. for the past couple of years as a solopreneur and as a




Exciting news! Our vulnerability research team Wiz is hiring! ๐คฉ Want to work with incredible researchers like sagitz, Ronen Shustin, Hillai Ben-Sasson, and โ๏ธ Andres Riancho to find bugs, hack the world's largest cloud services, and share your work? Shoot me a message! โฆ



Thrilled to finally share thisโone of the coolest container escapes Iโve seen! ๐ฅ wiz.io/blog/nvidia-aiโฆ A subtle logic bug that lets you break out to the host on ANY NVIDIA GPU-supported container ๐คฏ Canโt believe we had to sit on the technical details for so long! Incredible

We (+sagitz Ronen Shustin Hillai Ben-Sasson) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact? From zero permissions โก๏ธ to complete cluster takeover ๐คฏ This is the story of #IngressNightmare ๐งตโฌ๏ธ




๐ Wiz Research took 1st place in #Pwn2Own's first-ever AI category, competing against global teams targeting critical AI infrastructure. Huge thanks to our incredible research team! Nir Ohfeld, Shir, Ronen Shustin, benny isaacs, sagitz & Nir Brakha!

