Security Research Manager. Co-Founder @ZenGo acq by @etoro Advisor @ZeroNetworks. x-VP Research Aorato, acq by @Microsoft. 10 times @BlackHatEvents speaker.

Israel
OMG! i'm in RFC! tools.ietf.org/html/rfc7457#… http://t.co/3feTzqWRav
6
4
149
TL;DR: Recycled disk blocks weren't wiped before reassignment, so a malicious container could read leftover data from other tenants on the same host by reading its own raw disk.
Our craziest escape yet: The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc, Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too. We reported this to @Cloudflare, who super quickly fixed it. Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog: blog.cloudflare.com/containe…
1
7
43
3,998
דל״פ: לא ״פרצת אבטחה חמורה״. אוריך עשה אוטומציה לשליחת הודעות וואטסאפ באמצעות ultramsg.com/#whatsapp-api וחשף את פרטי הגישה. מה כבר היה יכול לעשות מי שהיה משתלט על החשבון? לשלוח הודעות? לענ״ד, העיסוק בשטויות מסיט את הדיון ומדלל את העיסוק בבעיות האמיתיות
יונתן אוריך בנה בקלוד כלי ניטור לנתניהו ורעייתו. הקוד נותר חשוף ברשת, עם פרצת אבטחה חמורה ■ עשרות ערוצים נסרקו כל דקה וחצי, התראות על שרה שוגרו לוואטסאפ מיוחד: הקוד חשף את המקורות שמזינים את נתניהו והדחף לשלוט בסיפור מתפרץ חשיפה של @bar_peleg ו @omerbenj haaretz.co.il/news/security/…
2
5
1,215
חזרתי לדעה הפופלרית עם כוכבית
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
175
דל״פ: לא ״פרצת אבטחה משמעותית״. אוריך עשה אוטומציה לשליחת הודעות וואטסאפ באמצעות ultramsg.com/#whatsapp-api וחשף את פרטי הגישה. מה כבר היה יכול לעשות מי שהיה משתלט על החשבון? לשלוח הודעות? לענ״ד, העיסוק בשטויות מסיט את הדיון ומדלל את העיסוק בבעיות האמיתיות
1. העובדה שאוריך בנה כלי ניטור בקלוד קוד לא מעניינת במיוחד. מה שהסיפור הזה מראה, שוב, זה את הרשלנות, חוסר המקצועיות וחוסר האכפתיות של יועצי נתניהו. הקוד היה בגיטהאב, פומבי וחשוף לכל. עד כאן בסדר. אבל בקוד היו מפתחות לקבוצות ווטסאפ, וזו כבר פרצת אבטחה משמעותית.
1
4
1,886
חזרתי לדעה הפופולרית, עם כוכבית
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
172
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
1. העובדה שאוריך בנה כלי ניטור בקלוד קוד לא מעניינת במיוחד. מה שהסיפור הזה מראה, שוב, זה את הרשלנות, חוסר המקצועיות וחוסר האכפתיות של יועצי נתניהו. הקוד היה בגיטהאב, פומבי וחשוף לכל. עד כאן בסדר. אבל בקוד היו מפתחות לקבוצות ווטסאפ, וזו כבר פרצת אבטחה משמעותית.
2
10
1,410
ראה
דל״פ: לא ״פרצת אבטחה משמעותית״. אוריך עשה אוטומציה לשליחת הודעות וואטסאפ באמצעות ultramsg.com/#whatsapp-api וחשף את פרטי הגישה. מה כבר היה יכול לעשות מי שהיה משתלט על החשבון? לשלוח הודעות? לענ״ד, העיסוק בשטויות מסיט את הדיון ומדלל את העיסוק בבעיות האמיתיות
1
2
270
הבדיקה: סקירת מערכות
בוקר טוב לכולם ובמיוחד לטכנאית האולטרסאונד שהתפלאה שהתינוק הגיע "לבד עם אבא שלו"
4
427
For $7 only
I was inspired by the "Hacking OpenAI" blog that Hacktron (@S1r1u5_ , @rootxharsh and @iamnoooob ) published to check how far the current open weight models are from Opus 5, which was the unlock for them TL;DR DeepSeek v4.1 flash, did it in <12 hours (partial ASLR bypass + bf)
4
1,016
Patching faster won't win the Vulnpocalypse. Ships don't stay afloat because their hulls are never breached or instantly patched. They stay afloat because their compartments are watertight. Assume breach. Build compartments: sandboxing, micro-segmentation, isolation.
Replying to @chrisrohlf
The issue goes even deeper than disclosure timelines. Between LLMs being used for bug hunting 24/7 along with the ability to auto create weaponizable exploits, I don't see how any of our current practices related to patching can stand. No real org can keep up with weekly/daily/hourly patches. Our recent incident involved this problem against Chrome and its open source diffs, but the same can be done with binary diffing, including against beta releases containing the bug fixes: volexity.com/blog/2026/09/09…
1
11
1,089
A good magician never reveals his secrets, but a great researcher always do. Beautiful slides, great structure. When / where video?
I put my @UnpromptedAU slides up at justdionysus.github.io/slide… — a bit of reflection on exploit development in the age of AI. My TL;DR is keep pushing to understand complex things, be honest with your own understanding, and use AI as a power tool to increase pace and depth.
1
7
91
8,013
Re-watched @halvarflake's 2017 @BlackHatEvents keynote with this killer quote. The whole talk aged really well. Being pre-AI makes it more "objective": it describes security issues without knowing how AI would expose them. piped.video/watch?v=PLJJY5UF…
“All offensive problems are technical problems, and all defensive problems are political problems” - @halvarflake NCSC Nails the diagnosis. Not convinced by the prescription, though.
3
9
1,530
@halvarflake is there a PDF? BTW, AI (or corp designer?😈) certainly upped your slides game 😅
1
2
200
מנצל מבצע בידיעות ספרים. הייתי מתייג את הגרי"ד אבל נסתפק ב @Avraham_Stav
1
2
3,361
👀
We have discovered a massive, ongoing criminal exploitation campaign using Cairn, an autonomous penetration-testing harness, and other AI agents to target hundreds of organizations and successfully breach and impact tens of them (at least). The image below shows just a few days of activity, with up to 25 organizations being attacked simultaneously at the peak. our intreim report: gambit.security/blog-posts/a…
4
1,130
VMkatz by @Nikaiw is impressive! CC: @gentilkiwi @agsolino @attrc Getting even Kernel secrets as they are all just VM files
On a recent Incident response case, we encountered VMkatz. "It extracts Windows secrets - NTLM hashes, DPAPI master keys, Kerberos tickets, cached domain credentials, LSA secrets, NTDS.dit, BitLocker keys - directly from VM memory snapshots and virtual disks, on the NAS, the hypervisor, wherever the VM files are." [1] Defender detected it with the following signature: VirTool:Win64/Vekesz.A The out-of-the-box release from the GitHub page is also heavily flagged, but one could compile (and obfuscate) the code to stay under the radar. In our case, the attacker just disabled real-time monitoring and added an exclusion: Set-MpPreference -DisableRealtimeMonitoring $true Add-MpPreference -ExclusionPath "C:\" And then pointing it to a directory, "and let it find everything", as pointed out in the documentation. ./vmkatz.exe C:\ClusterStorage\CSV01\node-002\ I think monitoring for AV alerts (and exclusions!) could go a long way. The basics make the difference. ☝️ [1] github.com/nikaiw/VMkatz
1
704
“All offensive problems are technical problems, and all defensive problems are political problems” - @halvarflake NCSC Nails the diagnosis. Not convinced by the prescription, though.
Good piece from the NCSC on agentic defence The difficult part starts when the agent is allowed to actually change things in production. Scope, criticality, confidence and recoverability suddenly matter a lot more than “can the model understand the attack?” Worth a read ncsc.gov.uk/blogs/one-does-n…
9
2,671
The @WEareTROOPERS talks are online, mine included. "WhatsApp View Once: Four Exploits and a Funeral" 🔗 Talk page: troopers.de/troopers26/talks… 📑 Slides: troopers.de/downloads/troope… 🎥 Video: piped.video/watch?v=8_qHT1BM…
7
21
2,650
Offline 24+ hours, came back to find this tweet went viral. Glad I missed arguing with people calling this "old and outdated people who are not following the state of VDP." Personally, I'd rather be on @alexstamos's boomer team any day.
1/ Unpopular opinion: When you find a 0-day in a public service, you do RD (Responsible Disclosure), not LM (Lateral Movement). The GitHub PR in the @OpenAI repo was a bridge too far (IMHO)
2
8
1,924