Red Team & Offensive Security Research @AmberWolfSec // @buffaloverflow.rw.md on bsky

Joined May 2011
296 Photos and videos
NSIS 3.12 has been released, which fixes a potential privilege escalation issue: nsis.sourceforge.io/Docs/App… If you read our recent blog post related to NSIS then maybe this might be useful

Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE.. includes PoCs and yara rule to help you find other affected s/w blog.amberwolf.com/blog/2026…
1
20
3,609
Rich Warren retweeted
"You need to be admin to run the installer anyway." A common pushback that misses an entire class of attack. New research from @buffaloverflow on exploiting NSIS installer bugs to escalate from a standard user to SYSTEM in Zscaler Client Connector.
1
4
11
2,424
Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE.. includes PoCs and yara rule to help you find other affected s/w blog.amberwolf.com/blog/2026…
1
77
190
19,590
and a message to vendors:
4
890
here's my writeup for the latest Netskope LPE this was a fun bypass of CVE-2025-0309, and highlights an interesting cloud-based attack surface :) blog.amberwolf.com/blog/2026…
Finishing off the week with a writeup of CVE-2025-0309 - Netskope Windows Client LPE This was one of the bugs we demo’d in our DEF CON #ZeroTrustTotalBust talk. Also releasing a NachoVPN plugin and our 🆙skope PoC. Details on the @AmberWolfSec blog: blog.amberwolf.com/blog/2025…
2
30
67
12,553
So nice they patched it thrice
Delinea protocol handler RCE number 3. blog.amberwolf.com/blog/2026…
2
4
2,122
Rich Warren retweeted
Zero Trust is not a product it is an approach - at the @NCSC we have just released demystifying zero trust which addresses common misconceptions, and provides practical advice on when and how it should be adopted. ncsc.gov.uk/collection/zero-…
1
24
69
13,011
I made a website that lets you generate VBA macro docs in your browser (using rust wasm!): vba.rw.md ^just for fun, inb4 "motw kills macros" etc. 😅
4
29
147
9,079
you can click "Download HTML file" in the footer to try the single-page/offline version :)
1
3
1,100
Had an awesome time at RedTreat. Thanks to the @OutflankNL and @MDSecLabs crew for organising, and all the speakers and attendees for the cool talks and discussions! 🏝️👏
#RedTreat2025 is a wrap @StanHacked @MarcOverIP - thanks to all the speakers and the panel team for an extra awesome con this year 🫶
1
23
3,327
Playing the long game

ALT Emoji Laughing GIF by MOODMAN

3 Sep 2025
Visiting NCC Group’s blogs right now feels like a CTF challenge: decipher the mangled text while dodging XSS pop-ups. Better to use web archive to see the original content but they have even changed the URLs! Example: nccgroup.com/research-blog/b… The fox-it.com etc are also the same. My blog posts there are all ruined for sure which is a shame. I have to repost them all in my own blog.
1
24
2,541
Finishing off the week with a writeup of CVE-2025-0309 - Netskope Windows Client LPE This was one of the bugs we demo’d in our DEF CON #ZeroTrustTotalBust talk. Also releasing a NachoVPN plugin and our 🆙skope PoC. Details on the @AmberWolfSec blog: blog.amberwolf.com/blog/2025…
1
55
159
28,295
There’s also a nice tamper protection bypass for process injection fans 🤭
1,100
What comes after the patch? Bypass of course! 😜 Delinea Protocol Handler RCE - Return of the MSI. By my colleague @johnnyspandex blog.amberwolf.com/blog/2025…
Normalization strikes again 🎯 Delinea Secret Server Protocol Handler RCE: blog.amberwolf.com/blog/2024… By @johnnyspandex
1
20
62
9,387
👀
Someone brought it to my attention that Zscaler is using their 500,000,000,000 daily customer logs to train Artificial Intelligence. ... does this not seem like a problem ... ?
4
14
2,068
Bug bounty platforms can often be misused as NDA as a service. As a general rule, I avoid reporting via bbp for this very reason
17 Aug 2025
why would i report free bugs to bugcrowd vdp just for vendors to say “never disclose”? that disclosure policy is not it. better to go security@ with project zero deadlines, 90 days, then i share it with the community.
1
4
1,408
If you missed the talk, we uploaded the video here: vimeo.com/1109180896
Breaking Into Your Network? Zer0 Effort. - DEF CON 33 Overview and Advisory - Zscaler SAML Authentication Bypass (CVE-2025-54982). Following on from our DEF CON 33 presentation, the first two blog posts in our series on Zero Trust Network access abuse are now live.
20
80
15,294
Just published the writeup for the "Netskope cross-tenant authentication bypass" featured in our #defcon33 talk #ZeroTrustTotalBust Find the full details here 👇 blog.amberwolf.com/blog/2025… ^We also cover another method to leak those not-so-secret OrgKeys 😉
9
21
3,070