Partial bypass of the login rate limiting in the AWS Consolesecuritylabs.datadoghq.com·2 pts·christophetd·0
Investigating a backdoored PyPI package targeting FastAPI applicationssecuritylabs.datadoghq.com·12 pts·christophetd·0
Identify malicious PyPI packages using static analysis and metadata heuristicsgithub.com·2 pts·christophetd·0
Demystifying the OpenSSL punycode vulnerability and exploitation walk-throughsecuritylabs.datadoghq.com·3 pts·christophetd·0
"Stratus Red Team", an open-source adversary emulation tool for the cloudgithub.com·2 pts·christophetd·0
Using Twitter to notify careless developers – the unorthodox wayincognitatech.medium.com·5 pts·christophetd·2
GitHub taking down tools allowing defenders to reproduce the Log4j vulnerabilitytwitter.com·212 pts·christophetd·94
Phishing for AWS credentials via AWS SSO device code authenticationblog.christophetd.fr·3 pts·christophetd·0
Exploiting the code execution engine powering InterviewCake, CodeWars and othersblog.christophetd.fr·3 pts·christophetd·0