Kaizen

Joined August 2022
59 Photos and videos
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Time for another giveaway! We will pick 6 winners to win one of the following: 1x Annual VIP @hackthebox_eu Licence 5x @PentesterLab 3 Month Licences To enter: 1๏ธโƒฃ Follow us @BugBountyDefcon 2๏ธโƒฃ Like this post โค๏ธ 3๏ธโƒฃ Re-tweet this post ๐Ÿ” Giveaway open until Monday June 15th! GOOD LUCK!
102
368
477
18,220
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Bootcamp Giveaway We're giving away 1 CARTPยฎ Bootcamp seat and 1 CRTPยฎ Bootcamp seat to two participants. Join live, hands-on training in Azure Red Teaming or Active Directory security. How to participate: โ€ข Like & follow us โ€ข Comment your preferred bootcamp and why โ€ข Repost Winners announced June 4, 2026 Limited-Time Bonus: Enroll in CARTPยฎ (Starts June 5) or CRTPยฎ (Starts June 6) and get 10 extra days of lab access (worth $150 ). Applicable for the first 30 purchases only. alteredsecurity.com/bootcampโ€ฆ #CyberSecurity #RedTeaming #InfoSec #AlteredSecurity
72
62
83
4,475
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
New banger from @thefosi: HTTP/2 framing WAF bypasses across six proxies. Use it wisely while you can. :p lab.ctbb.show/research/h2-WAโ€ฆ
2
21
194
8,297
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
i hope my sister gets everything she wants in life.
100
6,183
20,474
300,365
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ณ๐Ÿ‡ฌNigeria - ๐—ก๐—ก๐—ฃ๐—– ๐—›๐—ฒ๐—ฎ๐—น๐˜๐—ต ๐— ๐—ฎ๐—ถ๐—ป๐˜๐—ฒ๐—ป๐—ฎ๐—ป๐—ฐ๐—ฒ ๐—ข๐—ฟ๐—ด๐—ฎ๐—ป๐—ถ๐˜€๐—ฎ๐˜๐—ถ๐—ผ๐—ป XP95 hacking group claims to have breached NNPC Health Maintenance Organisation. Threat actor: XP95 Sector: Financial / Insurance Data exposure (claimed): 200,000 user records Data type: Personal data Observed: Apr 08, 2026 Status: Pending verification ESIXยฉ: 5.73 Full details and impact assessment on HackRisk.io
9
48
139
36,234
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Malware Analysis Tutorials: a Reverse Engineering Approach fumalwareanalysis.blogspot.cโ€ฆ
3
134
654
25,927
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ณ๐Ÿ‡ฌNigeria - ๐—œ๐—ป๐—ฑ๐˜‚๐˜€๐˜๐—ฟ๐—ถ๐—ฎ๐—น ๐—ง๐—ฟ๐—ฎ๐—ถ๐—ป๐—ถ๐—ป๐—ด ๐—™๐˜‚๐—ป๐—ฑ (๐—œ๐—ง๐—™) NormalLeVrai claims to have breached an Industrial Training Fund employeeโ€™s email, allegedly accessing 92 government files including emails, financial records (2019โ€“2026 salaries), budgets, internal documents, and employee/contact data. Threat actor: NormalLeVrai Sector: Gov / Mil / LE Data exposure (claimed): Not specified Data type: Emails, financial records and employee data Observed: Apr 2, 2026 Status: Pending verification ESIXยฉ: 5.79 Full details and impact assessment on HackRisk.io
20
64
186
74,589
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
I finished the Hack the Box COAE cert the day it came out (by about an hour lol) report and all, really was going for first globally. Gonna be close if nothing else! Review coming next week for the cert portion. If youโ€™re interested in a review of the ai red teaming course that is already live on my personal website. I Throughly enjoyed the course and test, saying it opened my mind to a deeper level of systems thinking overall would not be an under statement.
29
15
262
24,245
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
coming here to casually drop that I passed the OSCP exam and maybe the ultimate reason I went offline, I have a lot to write, but first I would like to say thank you to everyone of you, my community for your support, this is by far one of the nicest things to happen to me,
183
105
997
37,320
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
FCMB: Sophisticated API exploitation resulted in the successful siphoning of โ‚ฆ677 million from a โ‚ฆ3.5 billion fraudulent attempt. Sterling Bank: A critical middleware vulnerability enabled the exfiltration of sensitive PII for over 900,000 customers. Remita: A massive cloud misconfiguration exposed 3TB of archival data, including transaction logs and infrastructure blueprints. Here is a clean technical breakdown of these incidents: 1. FCMB: The โ‚ฆ3.5 Billion Heist This was a logic based exploitation of the bank's digital transaction pipeline Attackers identified a flaw in the API reconciliation layer, specifically involving the Payattitude integration By exploiting this vulnerability, hackers initiated transactions that the system validated as successful even though the source accounts were unfunded. This is known as a Zero Balance or Double Spend exploit. While the system eventually flagged the anomaly at the โ‚ฆ3.5 billion mark, the latency in the bank's real-time fraud monitoring allowed โ‚ฆ677 million to be successfully routed to mule accounts and withdrawn before the kill switch was activated. 2. Sterling Bank: The 900k Record Exfiltration This event was kinda like a Network Intrusion targeted at customer identity data, allegedly carried out by the threat actor ByteToBreach. The breach targeted a critical vulnerability in the Oracle WebLogic Server. This middleware sits between the public facing applications and the bankโ€™s private databases. Attackers bypassed authentication to extract roughly 2.2 GB of data. The data contained Personally Identifiable Information (PII) for over 900,000 customers, including names, contact details, and internal Customer Information File (CIF) numbers. This data is highly valuable for "Social Engineering 2.0, where scammers use real account details to trick victims into revealing OTPs or other lateral valuable infos 3. Remita: The 3TB S3 Infrastructure Exposure This was a Critical Cloud Misconfiguration representing one of the largest infrastructure level exposures in the Nigerian fintech space A massive Amazon S3 Bucket (Cloud Storage) was left in a Public Read state. This meant the data was accessible to anyone with the endpoint URL, requiring no hacking tools or passwords to download The volume 3 Terabytes indicates an entire archival Data Lake was exposed. This typically includes millions of individual files and logs accumulated over years 800GB of KYC Documents, Massive troves of sensitive personal data, including Passports, Government IDs, Bank Statements, and Utility Bills Core Databases: Full exports of MySQL and Postgres databases, including three primary databases and over 35,000 password hashes The Master Keys: Exposure of Government HSM (Hardware Security Module) keys, which are used to encrypt and authorize high-level financial transactions Developer Blueprints: Source code, Docker registries, and GitKraken-to-S3 backups, providing a literal how-to guide for attackers to find further vulnerabilities in the system's logic The exposure included transaction archives, RRR (Remita Retrieval Reference) metadata, and internal system logs. Most dangerously, logs of this size often leak secrets such as API keys and session tokens, which provide a roadmap for attackers to move laterally into other connected financial systems what can we do
32
161
401
41,775
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
โ€ผ๏ธ๐Ÿ‡ณ๐Ÿ‡ฌ A massive breach allegedly from Remita, a major Nigerian payment processing platform, has been leaked on a popular cybercrime forum. โ–ช๏ธ Total Size: ~3TB of S3 storage โ–ช๏ธ Data Includes: 800GB of KYC documents (IDs, passports, photos, bank statements, electricity bills), MySQL/Postgres databases, logs, docker registries, source codes, government HSM keys, GitKraken to S3 backups โ–ช๏ธ Source codes, 35,000 password hashes, and three databases
132
654
1,302
479,675
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
๐ŸšจCyber Alert โ€ผ๏ธ ๐Ÿ‡ณ๐Ÿ‡ฌNigeria - ๐—ฆ๐˜๐—ฒ๐—ฟ๐—น๐—ถ๐—ป๐—ด ๐—•๐—ฎ๐—ป๐—ธ ๐—Ÿ๐˜๐—ฑ Threat actor ByteToBreach claims to have breached Sterling Bank Ltd, alleging the compromise of customer and employee data linked to approximately 900,000 accounts and over 3,000 staff. Threat actor: ByteToBreach Sector: Financial / Insurance Data exposure (claimed): 900,000 customer accounts and 3,000 employee records Data type: Banking records, identity documents (BVN, NUBAN, passport and driverโ€™s licence), transaction histories, loan records, credit scores, and employee data Observed: Mar 27, 2026 Status: Pending verification ESIXยฉ: 6.18 Full details and impact assessment on HackRisk.io
47
265
525
128,568
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Cybersecurity is not about what you know, it is about what you can do ๐Ÿ” ๐Ÿ‘‰ Limited-time offers: bit.ly/4bAakbY Build real skills with hands-on labs and certification prep before March 26. #CyberSecurity #InfoSec #TechSkills
1
1
537
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
AV/EDR Lab Environment Setup A curated list of various resources helpful in building own malware-centric research lab. A post by Udayveer Singh (@m4lici0u5) Source: an0nud4y.notion.site/AV-EDR-โ€ฆ #redteam #blueteam #maldev #malwaredevelopment
1
98
351
12,011
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Mar 18
Hi @RaenestApp I am a Security Engineer and a student. The essential Item missing from my setup is a powerstation. An itel 1kWh Power Tank solar panel would help me stay consistent, research more, and keep improving. Thank you๐Ÿฅน fash335200 #RaenestMakeAWish #raenestat
1
21
58
1,633
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Mar 17
๐Ÿšฉ Excited to share that Iโ€™ve earned the @hackthebox_eu CPTS certification. 10 intense days โ€” completed 12/14 objectives and submitted a 100 page commercial-grade report. Tough but incredibly rewarding. ๐Ÿ’ช #CPTS #HackTheBox #PenTesting #OffensiveSecurity
25
16
297
7,067
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Feb 23
Meet Onipede Abdulhakeem Security Engineer & Founder of OSCG. Passionate about Offensive Cybersecurity and empowering students to thrive in tech. Get ready to learn, grow, and level up. ๐Ÿš€ #MeetTheSpeaker #CyberSecurity #OSCG
3
8
138
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Critical: Client-Side Encryption Collapse site.com โ†“ some_javascript.js โ†“ Line no 80519 โ†’ encObj base64 key โ†“ atob(val) โ†’ "Encoded_Password" โ†“ CryptoJS.AES.decrypt(encObj, passphrase) โ†“ 55 configuration properties โ†’ 107 operational secrets exposed โ†’ Azure AD client_secret โ†’ OAuth client_credentials flow โ†’ RSA public keys โ†’ Forge encrypted /enc/ API requests โ†’ HMAC key โ†’ Backend-accepted payload signing โ†’ Direct Line token โ†’ Production chatbot access โ†’ Monitoring / RUM keys โ†’ Telemetry manipulation โ†’ Auth0 reCAPTCHA config โ†’ Auth flow manipulation โ†’ 31 encrypted authentication endpoints mapped โ†“ Use extracted Azure AD credentials โ†“ Request token from Microsoft OAuth endpoint (client_credentials) โ†“ Receive valid JWT with high-privilege role (e.g., AllAccess) โ†“ โ€œSuper tokenโ€ accepted by backend across protected API routes (No user interaction required, role-based authorization granted) โ†“ All sensitive authentication and account endpoints were wrapped in client-side hybrid encryption โ†’ Every request payload encrypted in browser โ†’ AES-256-CBC used for body encryption โ†’ RSA-OAEP used to wrap per-request AES key โ†’ Server accepts any request that decrypts successfully โ†’ Decryption success treated as implicit authorization โ†“ Reverse-engineer encryption module (@**6246) โ†’ Algorithm: AES-256-CBC RSA-OAEP (SHA-512) โ†’ Random 32-byte AES key per request โ†’ IV derived client-side โ†’ AES key wrapped with embedded RSA public key (promocode_pem) โ†’ Final format: { "key": base64(RSA_key), "body": hex(AES_ciphertext) } โ†“ Hook JSON.stringify XMLHttpRequest โ†“ Capture plaintext BEFORE encryption (credentials, OTPs, tokens) Capture encrypted wrapper AFTER encryption Capture correlated server responses โ†“ Analyze MFA implementation โ†“ IP-based rate limiting only (lockout resets on IP change) OTP expiration not strictly enforced server-side Encrypted payload fields trusted after decryption โ†“ Mass takeover method โ†“ 1. Trigger MFA or password reset 2. Rotate IP to bypass rate limiting 3. Reuse or brute-force OTP under weak enforcement 4. Complete password reset flow 5. Authenticate as victim 6. Capture decrypted OTP and auth tokens via runtime hook 7. Reuse valid 2FA tokens for subsequent authenticated requests โ†“ Full attack chain achieved: โ†’ Extract secrets from client bundle โ†’ Generate high-privilege JWT (โ€œsuper tokenโ€) โ†’ Read any plaintext request (credentials, PII, tokens) โ†’ Forge any encrypted request the server will accept โ†’ Bypass MFA protections via IP rotation โ†’ Reset victim passwords โ†’ Decrypt authentication flows in runtime โ†’ Mass account takeover
23
147
961
89,258
Oluwaseun ๐ŸŒ๐Ÿ’ป retweeted
Feb 21
Meet Our Speaker: Nafiu Abdulmalik Offensive Security Engineer & OSCG co-founder, passionate about empowering the next generation of cybersecurity professionals. Bringing real-world experience and practical insights to A Day In The Life Series ๐Ÿ›ก๏ธโœจ
8
16
254