@exploresecurity

IT security miscellany, commentary and curiosities || the geeky alter ego of @MrJeromeSmith || thoughts are my own (who else's would they be?)

Cambridge, England
Joined March 2013
exploresecurity retweeted
Today, we announced that we crossed $7B in revenue run-rate, growing over 80% year over year in Q2. We also shared: 🚀 $100M+ revenue run-rate for Lakebase 🚀 $1.5B+ revenue run-rate for Lakehouse, growing over 100% year over year 🚀 Continued positive adjusted free cash flow And we raised $5B in our latest fundraise. We’ll use this capital to invest in: 1️⃣ Lakebase, our serverless Postgres database built for AI agents 2️⃣ Genie, our AI coworkers that actually understand your business data 3️⃣ Unity AI Gateway, our multi-AI governance solution that helps control costs @iamVictorDey shares more in @Forbes: forbes.com/sites/victordey/2…
76
243
48
1,012
308,736
SQLi despite 'secure' Prepared Statements! Known to affect mysql and mysql2, nice write-up from @xoreipeip (and with due credit to previous work by other researchers)
Check out our new blogpost: Prepared Statements? Prepared to Be Vulnerable. blog.mantrainfosec.com/blog/…
2
68
2 instances this week of OAuth SaaS integrations where the setup guide says "login as admin". Even with scopes, the connections are overprivileged. Getting flashbacks of software that "needs" to be installed as admin (translation: cos then it just works).
1
53
As a #Salesforce admin or security pro, does it frustrate you that it's impossible to configure an account to have full access to the config of a Salesforce Org as read-only? Upvote ideas.salesforce.com/s/idea/…
48
Interesting compromise of Cyberhaven's Chrome extension with a malicious OAuth app using a genuine OAuth flow cyberhaven.com/engineering-b…
77
exploresecurity retweeted
All I want for Christmas is U(RL handlers not vulnerable to RCE)... AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here: blog.amberwolf.com/blog/2024…
1
9
32
3,184
More awesome work from @buffaloverflow and @johnnyspandex
Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵
3
127
New @Sonos app - yuk. Key features missing. Maybe I've just not found things like how to edit the queue. Best case, unintuitive UI; worst case, something that worked (mostly - has definitely got buggier and slower recently) is undeniably worse. Trust that updates are coming...
113
When there seems to be so much doom and gloom around, this story of innovation + determination + dedication is a ray of hope
Saw this on @BBCLookEast - congrats to all involved including @WeAreRSGroup
1
122
A lot of people will be forgetting @evernote now. I only store text (more or less). I appreciate they have costs and I'd be prepared to bung them a few quid but this drastic change without warning will push many to find an alternative.
Have to say I forgot all about evernote as a thing
1
246
Poor show @evernote - used to be able to export all notebooks at once for back-up, now it seems I have to export each notebook in turn. Why make something so important harder to do?
1
157
Great day @BsidesCambs - nice job everyone
1
142
Calling all infosec students near #Glasgow #DC44141 - a worthy cause and potentially more than a warm glow in return
This quoted post is unavailable.
1
1
2
401
Some fun with AI (trailer at youtube.com/watch?v=VqY0-H9j…)
OUT TODAY!!!!! Please check out my debut feature film, TIM, which is now live on Netflix U.K.! If you like it please spread the word, rate and share - apparently these first 48 hours are incredibly important so the more views we can get the better! #timmovie #Netflix #premiere
1
68
As usual from @PortSwiggerRes and @albinowax, it's not just the theory but the accompanying resources which support the practice - nice job!
2
7
4,554
exploresecurity retweeted
First round of BSides Cambridge tickets are live! We've got some great talks lined up. Get your tickets now. If you're a student, message us or @secmum and we'll sort something out. #bsides #bsidescambs #infosec #cybereast eventbrite.co.uk/e/bsides-ca…
10
2
13
3,777
Is there really no way @JustEatUK that a lost-n-found gift card can be reactivated? I assume it's expired (website only says "invalid" and have triple-checked code). Having to tweet because your "Contact us" page does no such thing.
1
1
105
Excellent customer service from @RicherSounds. Rang to query why 6yr guarantee unavailable on a product I was looking at (when it was on a similar product). 4 hours later - not only do they ring me back to tell me it was a mistake but they've fixed the website. Good job!
68