Senior Security Consultant @TrustedSec | Military grade meme poster, researcher, cloud penetration tester, voider of warranties. My thoughts are my own.
In someone’s cloud
Joined April 2009
- Tweets19.5K
- Following1.3K
- Followers26.9K
- Likes22K
rootsecdev@rootsecdev
11mUnited States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Rookie numbers
United States!
United StatesConnected via WebLocation may be affected by a proxy or VPN.Account-level information, not a live location or per-post device.
BREAKING: OpenAI & Anthropic are reportedly investigating “tens of thousands” of incidents where rogue AI agents took potentially problematic actions.
rootsecdev@rootsecdev
Sep 26United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @cantcomputer
👀
rootsecdev@rootsecdev
Sep 25United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Probably a good time to point you all to a tool I released not to long ago called SecretsStalker. If you have found an exposed client ID and secret to s service principal, SecretsStalker will authenticate you into the environment and recon the exact rights that it has.
github.com/rootsecdev/Secret…
Microsoft Security Research has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob
Two compromised service principals divided discovery, destruction, and credential collection, with timing and overlapping token streams strongly indicating automated or scripted execution that included more than 100 storage account deletion attempts in about seven minutes.
Discovered by Sysdig in July 2026, JADEPUFFER is reported to be the first documented agentic ransomware operation. These new findings expand publicly documented activity associated with Storm-3168 and indicate an evolution in the threat actor's cloud operations.
Read the blog for analysis, Microsoft Defender detections, and mitigation guidance on protecting workload identities, revoking or rotating exposed credentials, and safeguarding backup and recovery resources.
rootsecdev@rootsecdev
Sep 25United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Sounds like fun
‼️ You can commit code to a GitLab repo by emailing it.
Every GitLab user gets a private address for filing issues. Hidden inside is a non-expiring account token. If that address leaks, someone can send a patch that GitLab commits as you and, with your permissions, target main or trigger CI/CD.
Incoming email also bypasses 2FA and IP restrictions.
Read: thehackernews.com/2026/09/a-…
rootsecdev@rootsecdev
Sep 25United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
rootsecdev@rootsecdev
Sep 24United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
I think I may know a guy…
thehackernews.com/2026/09/te…
rootsecdev@rootsecdev
Sep 24United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @HackingDave
👀
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @benhackshealth @hubermanlab
Literally bought this two days ago.
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @HackingDave
I’m sorry this post has been downgraded to opus 4.8
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @_rybaz
👀
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Nail it again this Wednesday. 🤘
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
I’m waiting for models to just release updates themselves
United States!
United StatesConnected via WebLocation may be affected by a proxy or VPN.Account-level information, not a live location or per-post device.
JUST IN: OpenAI warns recursive self-improvement could accelerate “beyond our collective ability to understand progress, assess risks, and maintain meaningful human oversight.”
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Replying to @HackingLZ
👀
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Ruh roh coming soon 👀
I feel like I know this crew.
For our next webinar, we dig into real-world AI security gaps across AWS, Azure, and GCP. Walk away with:
🔎 Common security gaps in AI deployments
🔒 Steps to lock down permissions, data access, and endpoints
✅ Actionable recommendations
Register now! hubs.la/Q04y7Hzd0
rootsecdev@rootsecdev
Sep 23United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Adding this image to the pyramid of despair today.
United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
I just really have no clue what Microsoft is doing anymore in terms of their security.. Just leaving this here. Nothing else to see.
SharePoint + Pre-Auth RCE + MemShell? 👀
We’ve published our technical analysis of CVE-2026-65660, covering the attack chain from an Allow Anonymous site and a pre-auth SharePoint vulnerability to RCE and MemShell.
Take a look:
blog.viettelcybersecurity.co…
rootsecdev retweeted
ClaudeDevs@ClaudeDevs
Sep 22United States
United StatesConnected via WebAccount-level information, not a live location or per-post device.
Opus 5.5 performs at the level of Fable 5.1. It's ~30% faster and ~40% cheaper than Opus 5 per task.
In Claude Code:
- 5-hour session limits increase 20% today
- Opus 5.5 is priced lower, so it goes 25% further within limits
- Pro, Max, and Team users get a reset to use anytime
United States
United StatesConnected via WebAccount-level information, not a live location or per-post device.
Introducing Claude Opus 5.5, the first model in our new Claude 5.5 family.
It performs at the level of Claude Fable 5.1 for most tasks, and costs 40% less to run than Opus 5.
rootsecdev@rootsecdev
Sep 21United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
I just really have no clue what Microsoft is doing anymore in terms of their security.. Just leaving this here. Nothing else to see.
rootsecdev@rootsecdev
Sep 21United States
United StatesConnected via United States App StoreAccount-level information, not a live location or per-post device.
Yes I was at it by 6am this morning. Calorie deficit is going well. It’s a little on the extreme side but still getting all my protein in. Definitely been locked in for the month.