@NetSPIi
iAccount based inUnited States!
About this account
- Account based in
- United States
- Connected via
- United States App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
The Proactive Security Solution | Securing the most trusted brands on Earth #PenetrationTesting #proactivesecurity
Minneapolis, MN
Joined February 2009
- Tweets6.5K
- Following534
- Followers4.1K
- Likes1.1K
pfBlockerNG flaw (CVE-2026-78902): DNS request stores XSS in logs. Admin views Stats page, malicious JS executes, CSRF token stolen, reverse shell launched as root. Netgate patched in 24 hours. Update now. #Pentesting #CyberSecurity ow.ly/rLQn50ZQzVw
PATCH NOW! CVE-2026-75650 Adobe Commerce / Magento Open Source — Unauthenticated RCE
To learn more, please visit our website:
ow.ly/s9Ku50ZL3pb
Big news: NetSPI and @synack are merging in an exclusive covered by @AxiosPro. Two of the strongest offensive security teams in the industry, combining human expertise with agentic AI for continuous testing and validation. Read the full story: axios.com/pro/enterprise-sof…
Azure has 897 built-in roles & 22,018 permissions. Reviewing by role misses things. Using a permissions-first approach, we found a built-in role that could escalate to Owner with zero ABAC constraints. Reported to MSRC, now fixed. ow.ly/By6F50ZIUhv
NetSPI & @synack are forming the industry’s leading offensive cybersecurity platform. Hear from NetSPI CEO Aaron Shilts on why ⬇️
Read why the future of offensive security isn't a choice between human & machine.
Read his latest: ow.ly/Pp5t50ZIMs0
We are thrilled to announce that NetSPI and @synack have entered into a definitive agreement to merge & form the industry’s leading offensive cybersecurity platform.
Full announcement: ow.ly/FIOC50ZIt9o
#NetSPI #Synack #OffensiveSecurity #ContinuousTesting
Fal.Con 2026 kicks off today, and so does the conversation about what continuous pentesting actually looks like.
Most pentesting gives you a snapshot. Attackers don't work off snapshots.
Stop by booth #2203 to see it in action. ow.ly/3IhP50ZysJy
Heading to Fal.Con 2026? So are we.
Find NetSPI at booth #2203 for live demos of continuous pentesting in action and real conversations about offensive security.
See you next week! ow.ly/20H650ZysGr
AI pentesting benchmarks give you numbers, but none of them tell you what they mean. NetSPI built one and the reference point is humans.
EchoBench: ow.ly/GR9o50ZELb0
#AIpentesting #benchmark #EchoBench
BOFScale runs a full Tailscale daemon inside a C2 implant process. No driver. No service. No disk state. No child processes. Traffic blends in as standard WebSockets through CloudFront or Fastly. YARA rules and detection guidance included for defenders: ow.ly/cCz150ZBEZ3
Detection tells you something might be wrong. Pentesting tells you where you're actually exposed.
If you're at Fal.Con 2026, let's talk about the difference. Visit NetSPI at booth #2203. ow.ly/8C1V50ZysET
Your build pipeline trusts Artifactory. We found 4 chained bugs that let an unauthenticated attacker steal any artifact in it, no login required.
Auth bypass → missing authz → path traversal → router/Tomcat parsing mismatch = full artifact theft.
ow.ly/ipjI50ZzRyc
Black Hat is almost here! If you're going to be in Vegas, let's find time to chat.
Contact us to set up a meeting. ow.ly/6U1750Zmwp8
Designed to help your business validate every finding, test continuously, and fix what matters.
Our expanded offerings are designed with AI in mind. Built continuously, so you can have peace of mind.
learn more: ow.ly/Vur650ZtB1c
#ContinuousTesting #PTaaS
Third-party VM extensions are convenient. That's exactly why attackers like them too.
Part 2 of our Azure extension abuse series: how a rogue Salt Master can push root-level commands to your VMs, and the detection signals that give it away. ow.ly/l4sc50ZtBRR
Connect your AI to NetSPI’s validated pentest data. Auto-create tickets, enrich alerts, and update systems of record, without dumping raw findings.
Learn more: ow.ly/gfQb50Zo111
#ContinuousTesting #MCPintegrations
Join our team at #BlackHatUSA to talk about how modern continuous pentesting works.
Want to compare notes? Contact us and let's put time on the calendar. ow.ly/MgHc50Zmwo1
#BlackHatUSA #continuoustesting #pentesting
NetSPI's Continuous Web App Pentesting is here! Find authentication weaknesses, broken access controls, injection flaws, and API vulnerabilities before they become business problems.
Learn More→ow.ly/UIBW50Zo0PQ
#Pentesting#WebAppSecurity#ContinuousTesting