I hack stuff for living at @orcasec || Ex 81 & 8200

Joined May 2017
4 Photos and videos
The hackerbot-claw campaign. My take: AI is phenomenal in exploitation. Vulnerability research = craftsmanship, but exploitation? A guidebook trial-n-error loop, which agents excel at. Maybe novel threat detection should flag LLM-generated content? 🤖
1
97
I've discovered a new supply-chain vector through @github Codespaces. It is straightforward and easy to follow.
1
1
44
I've been able to use these techniques to 1) Gain full repository control 2) Carry XSS via installed Vscode extension 3) Abuse expensive Premium Copilot models 🤖
1
59
Roi Nisimi retweeted
17 Sep 2024
🇵🇱 Polish Security Experts! 🛡️ We're hiring a Security Researcher for our R&D team. Work with cutting-edge tech (eBPF, Linux, K8s, Malware analysis) to fight cybercrime! join.onthespotdev.com/runtim… RTs appreciated for reach! 🙏 #CloudSecurity #CybersecJobs #PolishTech

2
3
16
1,657
24 Jan 2024
Super excited to share the stage with @yonatankhen! Feb 7 || 11am eastern time - Join us
22 Jan 2024
After uncovering the #DeleFriend Google Workspace design flaw, it's time to protect against it. Join threat researchers @yonatankhen (Axon) and @roinisimi (@orcasec) as they join forces to demonstrate how to detect and prevent an attack Register here: hubs.li/Q02hgydx0
1
111
Roi Nisimi retweeted
Cloud Threat Researcher @roinisimi from @Orcasec discovered a critical design flaw in the #GoogleCloud Build service that creates a significant #supplychainrisk. orca.security/resources/blog…
3
2
228
Roi Nisimi retweeted
Azure admins warned to disable shared key access as backdoor attack detailed reg.cx/486G?utm_source=twitt…

7
13
4,516
Roi Nisimi retweeted
🛡️ New flaw in #Microsoft Azure Uncovered! Hackers could exploit this weakness to gain access to storage accounts, move laterally and execute remote code 🕵️‍♂️ 📰 Learn about this "by-design flaw" & how to protect your data: thehackernews.com/2023/04/ne… #CyberSecurity #DataSecurity

38
64
26,527
Roi Nisimi retweeted
Microsoft To Tighten Azure Storage Default Permissions after @Orcasec discovery -- Redmondmag.com redmondmag.com/articles/2023…

1
1
127
13 Apr 2023
Hi #twitter Published on Tuesday, my research and our blog at @orcasec was featured on @TheHackersNews, @TheRegister, @thecyberwire, Redmondmag.com and much more. Thanks for covering this. Getting this final result together with @msftsecresponse was a great pleasure.

11 Apr 2023
Our team of researchers continually push the limits to find #securityrisks before bad actors do.🔎 Learn how we discovered a critical exploitation path, utilizing Microsoft #Azure shared key authorization, and how to mitigate this: tryorca.co/43j5hrl
3
377