Hacker, trainer, and guitarist | Black Hills InfoSec #RedTeam | @BreakForge Training | Produces music to hack to at @N0BANDW1DTH

Joined January 2013
432 Photos and videos
Pinned Tweet
I’m excited to announce my newest training course, Breaching M365, is now available on-demand through @Antisy_Training. For $295, you get a full offensive methodology for attacking Microsoft 365 environments, from unauthenticated recon and initial access to OAuth abuse, persistence, privilege escalation, and data harvesting. If you want to level up your M365 tradecraft, check it out here: antisyphontraining.com/produ…
3
17
104
6,886
Beau Bullock retweeted
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-a…
10
37
98
18,815
Beau Bullock retweeted
2026 BSides Tampa *Unlucky 13* Session Announcement 12pm-1pm | Augmented Cloud Hacking with AI Workflows by Beau Bullock If you haven't already, be sure to get your tickets here: bsidestampa.net/tickets #BSidesTampa2026 #Unlucky13BSides #InfoSecCommunity #Cybersecurity
1
2
7
550
Beau Bullock retweeted
I’m excited to announce my newest training course, Breaching M365, is now available on-demand through @Antisy_Training. For $295, you get a full offensive methodology for attacking Microsoft 365 environments, from unauthenticated recon and initial access to OAuth abuse, persistence, privilege escalation, and data harvesting. If you want to level up your M365 tradecraft, check it out here: antisyphontraining.com/produ…
3
17
104
6,886
Beau Bullock retweeted
Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing
1,985
6,646
44,009
31,424,217
Beau Bullock retweeted
Mar 26
So Microsoft Copilot has its own App-Bound Encryption now. The standalone Copilot app (mscopilot.exe) is a full Chromium browser based on Edge, ships with its own elevation_service.exe, a dedicated COM interface (IElevatorCopilot), and a separate ABE key scope. Decrypting the ABE key gives us some cookies (copilot.microsoft.com auth, MUID, MSAL session, Cloudflare tokens) and the Microsoft Account token from the token_service database. Local Storage also holds MSAL.js cached tokens. An ID token, two access tokens (chatai.readwrite for the Copilot API user.read for Microsoft Graph), and account metadata for the signed-in MSA. These use MSAL's own browser-bound CryptoKey encryption, not ABE. Edge 147 also quietly hardened IElevator2 by switching from oleaut32 to a custom proxy/stub but simultaneously registered IElevatorCopilot with oleautomation. Closed one door, opened another. Next up: decrypting the MSAL tokens? 🤔
8
59
237
21,300
Beau Bullock retweeted
🚨‼️ BREAKING: PyPI package telnyx has been compromised by TeamPCP in yet another supply chain attack. The malware executes immediately upon importing telnyx. It drops a valid WAV audio file and runs an executable embedded within the frames.
63
535
2,909
708,237
Beau Bullock retweeted
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server self-replicate. link below
307
2,241
9,330
5,850,063
Beau Bullock retweeted
Next week at @WWHackinFest I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀
2
30
151
11,288
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
47
376
2,573
413,913
Beau Bullock retweeted
Here's a video PoC for Azure Entra ID SignIn Log Bypass in action. I had to make it to help MSRC replicate it (lol). You'll see how simple this bypass was. No worries admins, Microsoft says that it was only a "Moderate" issue.
12
67
419
41,600
Beau Bullock retweeted
Join @dafthack for his precon training class, "Breaching the Cloud," at Wild West Hackin' Fest - Mile High 2026! Don't ya go missin' it, grab yer tickets to the con today! wildwesthackinfest.com/wild-…
4
6
1,112
Beau Bullock retweeted
17 Sep 2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
903
3,185
475,260
Beau Bullock retweeted
17 Jul 2025
Two opportunities to take my Breaching the Cloud course live are coming up soon. If you want to learn how to hack cloud environments like Azure and AWS this is the course for you. Sep. 23 & 24 - Fully remote and live Oct. 7 & 8 - In-person only at @WWHackinFest Register here: antisyphontraining.com/cours…
2
12
34
3,545
Beau Bullock retweeted
Check out my new blog on nested app authentication and brokered authentication.
13 Aug 2025
Why should Microsoft's Nested App Authentication (NAA) should be on your security team's radar? @Icemoonhsv breaks down NAA and shows how attackers can pivot between Azure resources using brokered authentication. ghst.ly/45h2Zw3
2
17
41
12,843
Beau Bullock retweeted
14 Aug 2025
FIDO downgrades are still possible, in reverse proxy phishing attacks, if you manage to convince the server that your device does not support strong MFA. 🪝🐟 Research from @proofpoint: proofpoint.com/us/blog/threa…
2
28
85
13,322
Beau Bullock retweeted
I've been using Microsoft Teams wrong this entire time
THIS CAN'T BE A REAL MOVIE
7
19
211
17,756