Shir (@shirtamari) 's Twitter Profile
Shir

@shirtamari

Head of Research @wiz_io ๐Ÿง™โ€โ™‚๏ธ

ID: 1335908692169003008

calendar_today07-12-2020 11:27:24

280 Tweet

2,2K Followers

506 Following

Tal Be'ery (@talbeerysec) 's Twitter Profile Photo

1/ A world first reverse engineering analysis of AWS Session Tokens. Prior to our research these tokens were a complete black box. Today, we are making it more of a glass box, by sharing code and tools to analyze and modify AWS Session Tokens. medium.com/@TalBeerySec/rโ€ฆ

Rami McCarthy (@ramimacisabird) 's Twitter Profile Photo

Prompt Airlines (by Wiz) was short and fun, highly recommend! In fact, you should sit down any eng team working on practical AI and have everyone work through it together :) promptairlines.com

Prompt Airlines (by <a href="/wiz_io/">Wiz</a>) was short and fun, highly recommend! 

In fact, you should sit down any eng team working on practical AI and have everyone work through it together :)

promptairlines.com
Mati Horowitz (@mati_h) 's Twitter Profile Photo

ืื– ืื™ืš ืคื•ืชืจื™ื ืืช ืืชื’ืจ ื”ื ื“ืกืช ื”ืคืจื•ืžืคื˜ื™ื ืฉืœ Wiz?! ื™ืฉ ื›ืžื” ื“ืจื›ื™ื, ื”ื ื” ืžื” ืฉืขื‘ื“ ืœื™ >>>

ืื– ืื™ืš ืคื•ืชืจื™ื ืืช ืืชื’ืจ ื”ื ื“ืกืช ื”ืคืจื•ืžืคื˜ื™ื ืฉืœ Wiz?!

ื™ืฉ ื›ืžื” ื“ืจื›ื™ื, ื”ื ื” ืžื” ืฉืขื‘ื“ ืœื™ &gt;&gt;&gt;
Sudeep_Singh (@singhsoodeep) 's Twitter Profile Photo

Solved the AI jailbreak challenge by Wiz Goal of the challenge was to manipulate the AI chatbot to get a free flight ticket to the chosen destination Will post a write up soon. Thanks to Nir Ohfeld and Shir for creating this fun challenge AI jailbreaks will

Solved the AI jailbreak challenge by <a href="/wiz_io/">Wiz</a>

Goal of the challenge was to manipulate the AI chatbot to get a free flight ticket to the chosen destination

Will post a write up soon.

Thanks to <a href="/nirohfeld/">Nir Ohfeld</a> and <a href="/shirtamari/">Shir</a> for creating this fun challenge

AI jailbreaks will
liad eliyahu (@liadeliyahu) 's Twitter Profile Photo

๐ŸšจWe could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Hereโ€™s everything you need to know about the #ALBeast vulnerability discovered by Miggo Security

๐ŸšจWe could bypass authentication to thousands of applications by exploiting a configuration-based vulnerability in AWS ALB. Hereโ€™s everything you need to know about the #ALBeast vulnerability discovered by <a href="/MiggoSecurity/">Miggo Security</a>
Nagli (@galnagli) 's Twitter Profile Photo

Excited to share some big personal news today, I have joined Wiz to enhance their Risk & Threat Exposure Management and build a new disruptive Risk MDR offering. It's been quite a ride working on Shockwave - External Attack Surface Management. for the past couple of years as a solopreneur and as a

Ronen Shustin (@ronenshh) 's Twitter Profile Photo

We discovered a container escape vulnerability in the @NVIDIA Container Toolkit. It allows attackers to gain full access to the host's filesystem and achieve Remote Code Execution (RCE). Here's everything you need to know about CVE-2024-0132 ๐Ÿงต๐Ÿ‘‡

Danielle Aminov (@aminovdanielle) 's Twitter Profile Photo

๐Ÿšจ ONGOING: Threat actors are actively exploiting the PAN-OS RCE vulnerability chain (CVE-2024-0012 + CVE-2024-9474) to deploy malware. After observing ongoing exploitation of these vulnerabilities over the past few days, weโ€™re sharing our findings. Details and IOCs ๐Ÿ‘‡

Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

Exciting news! Our vulnerability research team Wiz is hiring! ๐Ÿคฉ Want to work with incredible researchers like sagitz, Ronen Shustin, Hillai Ben-Sasson, and โ˜๏ธ Andres Riancho to find bugs, hack the world's largest cloud services, and share your work? Shoot me a message! โœฆ

Guy Goldenberg (@guygoldenberg) 's Twitter Profile Photo

๐ŸšจCVE ALERT! While working with Nuclei Wiz, I discovered CVE-2024-43405, a vulnerability that bypasses template signature verification, potentially allowing malicious code execution on machines running Nuclei ๐Ÿ›ก๏ธ Hereโ€™s what you need to know: ๐Ÿงต

โ˜๏ธ Andres Riancho (@andresriancho) 's Twitter Profile Photo

NVIDIA Container Escape (CVE-2024-0132) details are out! wiz.io/blog/nvidia-aiโ€ฆ Recommended reading if you're into container security

Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

Thrilled to finally share thisโ€”one of the coolest container escapes Iโ€™ve seen! ๐Ÿ”ฅ wiz.io/blog/nvidia-aiโ€ฆ A subtle logic bug that lets you break out to the host on ANY NVIDIA GPU-supported container ๐Ÿคฏ Canโ€™t believe we had to sit on the technical details for so long! Incredible

Nir Ohfeld (@nirohfeld) 's Twitter Profile Photo

We (+sagitz Ronen Shustin Hillai Ben-Sasson) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX". The impact? From zero permissions โžก๏ธ to complete cluster takeover ๐Ÿคฏ This is the story of #IngressNightmare ๐Ÿงตโฌ‡๏ธ

We (+<a href="/sagitz_/">sagitz</a> <a href="/ronenshh/">Ronen Shustin</a> <a href="/hillai/">Hillai Ben-Sasson</a>) found a series of unauthenticated RCEs in core @KubernetesIO project "Ingress-NGINX".

The impact?

From zero permissions โžก๏ธ to complete cluster takeover ๐Ÿคฏ

This is the story of #IngressNightmare ๐Ÿงตโฌ‡๏ธ
Wiz (@wiz_io) 's Twitter Profile Photo

This. is. massive! ๐Ÿฅ Meet the Wiz Vulnerability Database - for CVEs that *actually matter* in the cloud. AI-powered reports, expert insights & fix guidance. No fluff, just essentials. ๐Ÿ” Explore: wiz.io/vulnerability-โ€ฆ

Jonathan Jacobi (@j0nathanj) 's Twitter Profile Photo

Introducing Multiverse: the first AI-generated multiplayer game. Multiplayer was the missing piece in AI-generated worlds โ€” now itโ€™s here. Players can interact and shape a shared AI-simulated world, in real-time. Training and research cost < $1.5K. Run it on your own PC. We

Wiz (@wiz_io) 's Twitter Profile Photo

๐Ÿ† Wiz Research took 1st place in #Pwn2Own's first-ever AI category, competing against global teams targeting critical AI infrastructure. Huge thanks to our incredible research team! Nir Ohfeld, Shir, Ronen Shustin, benny isaacs, sagitz & Nir Brakha!

๐Ÿ† Wiz Research took 1st place in #Pwn2Own's first-ever AI category, competing against global teams targeting critical AI infrastructure.   

Huge thanks to our incredible research team! <a href="/nirohfeld/">Nir Ohfeld</a>, <a href="/shirtamari/">Shir</a>, <a href="/ronenshh/">Ronen Shustin</a>, <a href="/benny_isaacs/">benny isaacs</a>, <a href="/sagitz_/">sagitz</a> &amp; Nir Brakha!
Staceyโœจ (@sweetdelightss) 's Twitter Profile Photo

๐Ÿงฉโœจ Friday Vibes: CTFs Challenges The Wiz research team has created several pretty cool challenges over the years that are worth peeping. Today I wanted to highlight them๐ŸŒŸ ---- a thread ๐Ÿงต

๐Ÿงฉโœจ Friday Vibes: CTFs Challenges

The <a href="/wiz_io/">Wiz</a> research team has created several pretty cool challenges over the years that are worth peeping. 

Today I wanted to highlight them๐ŸŒŸ
----
a thread ๐Ÿงต