Joined May 2026
3 Photos and videos
Pinned Tweet
I'm now GNA 119 under CIRCL's GCVE system. I have authority to assign vulnerability IDs to my own cloud security findings starting today. I'm choosing not to. Cloud finding validation shouldn't be one person's judgment. Forming a consensus panel of practitioners per cloud platform. Charter coming. olearysec.com/gcve/
536
AI’s deadliest feature isn’t intelligence. It’s the certainty it lends to people who’ve stopped thinking.
AI identified Jalil Richardson - with only 85% accuracy - as person in video who sold someone a stolen car. Police never checked his alibi. Richardson spent months in prison, lost job, home, and custody of two children before police admitted AI was wrong yahoo.com/news/us/articles/a…
121
Justin OLeary retweeted
May 28
Microsoft ridiculed a researcher reporting very serious bugs to them, deleted his account, and no bug bounties were paid. These should be high payouts. Now $MSFT is threatening legal action and speaking as if a researcher’s proof of concept code is illegal. This is because the unappreciated researcher released more zero-day vulnerabilities on his own and had those GitHub/Lab accounts banned. They were serious enough that Microsoft is scrambling to fix them but wasn’t serious enough to be paid or recognized, instead was ridiculed. News of the Nightmare Eclipse exploits are everywhere but read the personal blog of the researcher, Nightmare Eclipse: deadeclipse666.blogspot.com/…

32
288
1,803
70,767
Justin OLeary retweeted

4
18
1,665
$argon2id$v=19$m=64,t=512,p=2$qa5PGzsh73ctUvK7Enp65g$GNb W8w1wbxVehiG7aSISw
1
186
Decentralized identity verification via Keyoxide. This hash cryptographically proves I control this Twitter account, my Mastodon (@olearysec@infosec.exchange), and my PGP key — without trusting any central authority. Verify: keyoxide.org/wkd/contact@ole…

198
Confused deputy is everywhere in cloud infrastructure if you know how to look. Wrote up the full methodology — taxonomy, diagrams, CLI enumeration, 10-question hunting checklist. #cloudsecurity #infosec
1
322
MSRC silently rolled out a custom, cluster-wide code modification specifically tailored to break my exact exploit primitive, all while insisting "no product changes were made". Bespoke customer service right there.
Microsoft rejects critical Azure vulnerability report, no CVE issued bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
411
Schrödinger's vulnerability: simultaneously not a bug and quietly patched.
Researcher @olearysec found privilege-escalation vuln in Azure Backup for AKS and reported to @microsoft. CERT validated it but Microsoft rejected it and asked Mitre not to give it CVE. Then he says Microsoft silently patched it without telling users olearysec.com/research/azure…
291