RSS Parrot

BETA

🦜 AmberWolf / @AmberWolfSec

@nitter.poast.org.amberwolfsec@rss-parrot.net

I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline! Brought to you by the RSS Parrot.

---

Twitter feed for: @AmberWolfSec. Generated by https://nitter.poast.org

Your feed and you don't want it here? Just e-mail the birb.

Site URL: nitter.poast.org/AmberWolfSec

Feed URL: nitter.poast.org/amberwolfsec/rss

Posts: 20

Followers: 1

RT by @AmberWolfSec: Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - new research from @craigsblackie and @R3n5k1 from @AmberWolfSec https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

Published: July 10, 2026 10:54

Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - new research from @craigsblackie and @R3n5k1 from @AmberWolfSec mdsec.co.uk/2026/07/dell-bio…

R to @AmberWolfSec: You can read the full write up at: https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

Published: July 10, 2026 10:41

You can read the full write up at: blog.amberwolf.com/blog/2026…

R to @AmberWolfSec: The research was carried out by Darren McDonald (@R3n5k1) of AmberWolf and Craig Blackie (@craigsblackie) of MDSec, disclosed to Dell under coordinated disclosure, and is published today alongside a recovery tool and a full technical write-up.

Published: July 10, 2026 10:41

The research was carried out by Darren McDonald (@R3n5k1) of AmberWolf and Craig Blackie (@craigsblackie) of MDSec, disclosed to Dell under coordinated disclosure, and is published today alongside a recovery tool and a full technical write-up.

R to @AmberWolfSec: The affected firmware stores BIOS administrator and user passwords XOR-encrypted on the SPI flash rather than hashing them, and the encryption key is leaked by the encryption process. An attacker able to read the flash can recover the key and decrypt the password.

Published: July 10, 2026 10:41

The affected firmware stores BIOS administrator and user passwords XOR-encrypted on the SPI flash rather than hashing them, and the encryption key is leaked by the encryption process. An attacker able to read the flash can recover the key and decrypt the…

AmberWolf and @MDSecLabs are jointly disclosing technical details on CVE-2026-40639, a weakness found in how some Dell platforms store BIOS passwords.

Published: July 10, 2026 10:41

AmberWolf and @MDSecLabs are jointly disclosing technical details on CVE-2026-40639, a weakness found in how some Dell platforms store BIOS passwords.

R to @AmberWolfSec: Full writeup, exploitation walkthroughs, and PoC on the blog: https://blog.amberwolf.com/blog/2026/april/next-next-system/

Published: April 9, 2026 15:50

Full writeup, exploitation walkthroughs, and PoC on the blog: blog.amberwolf.com/blog/2026…

R to @AmberWolfSec: NSIS is embedded in thousands of products. Any that launch a vulnerable installer from a privileged service could be affected. Both CVEs are patched - but silent patching from vendors means most customers never knew they were exposed.

Published: April 9, 2026 15:50

NSIS is embedded in thousands of products. Any that launch a vulnerable installer from a privileged service could be affected. Both CVEs are patched - but silent patching from vendors means most customers never knew they were exposed.

R to @AmberWolfSec: The trick: you don't run the installer yourself. Privileged services do it for you. Zscaler's tray process communicates with a SYSTEM-level backend via ALPC - inject into it, trigger an installer action, and the attack surface opens up.

Published: April 9, 2026 15:50

The trick: you don't run the installer yourself. Privileged services do it for you. Zscaler's tray process communicates with a SYSTEM-level backend via ALPC - inject into it, trigger an installer action, and the attack surface opens up.

R to @AmberWolfSec: Two NSIS CVEs in play: CVE-2023-37378 - weak ACLs on the uninstaller temp directory, exploitable via DotLocal redirection or NTFS junction swaps CVE-2025-43715 - race condition in plugin directory creation, letting an attacker hijack $PLUGINSDIR before it's locked down

Published: April 9, 2026 15:50

Two NSIS CVEs in play: CVE-2023-37378 - weak ACLs on the uninstaller temp directory, exploitable via DotLocal redirection or NTFS junction swaps CVE-2025-43715 - race condition in plugin directory creation, letting an attacker hijack $PLUGINSDIR before…

"You need to be admin to run the installer anyway." A common pushback that misses an entire class of attack. New research from @buffaloverflow on exploiting NSIS installer bugs to escalate from a standard user to SYSTEM in Zscaler Client Connector.

Published: April 9, 2026 15:50

"You need to be admin to run the installer anyway." A common pushback that misses an entire class of attack. New research from @buffaloverflow on exploiting NSIS installer bugs to escalate from a standard user to SYSTEM in Zscaler Client Connector.

RT by @AmberWolfSec: Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE.. includes PoCs and yara rule to help you find other affected s/w https://blog.amberwolf.com/blog/2026/april/next-next-system/

Published: April 9, 2026 13:09

Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE.. includes PoCs and yara rule to help you find other affected s/w …

R to @AmberWolfSec: We reported this in September 2025. Netskope restricted the unauthenticated routes in November 2025. Full write-up: https://blog.amberwolf.com/blog/2026/march/patch-bypass---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/ (6/6)

Published: March 24, 2026 18:19

We reported this in September 2025. Netskope restricted the unauthenticated routes in November 2025. Full write-up: blog.amberwolf.com/blog/2026… (6/6)

R to @AmberWolfSec: Spin up a NachoVPN server on Azure App Service, reach it via rproxy, supply the hostname over IPC, and the allowlist check passes. SYSTEM shell in ~30 seconds. No changes to the original exploit chain required. (5/6)

Published: March 24, 2026 18:19

Spin up a NachoVPN server on Azure App Service, reach it via rproxy, supply the hostname over IPC, and the allowlist check passes. SYSTEM shell in ~30 seconds. No changes to the original exploit chain required. (5/6)

R to @AmberWolfSec: Netskope patched it in R129 with a domain allowlist, restricting enrolment to subdomains of *.goskope.com. Seemed reasonable. (3/6)

Published: March 24, 2026 18:19

Netskope patched it in R129 with a domain allowlist, restricting enrolment to subdomains of *.goskope.com. Seemed reasonable. (3/6)

R to @AmberWolfSec: Netskope's own reverse proxy broke the fix. Their rproxy service at *.rproxy.goskope.com proxies external domains on behalf of the client — and at the time of testing, *.azurewebsites.net required no authentication. (4/6)

Published: March 24, 2026 18:19

Netskope's own reverse proxy broke the fix. Their rproxy service at *.rproxy.goskope.com proxies external domains on behalf of the client — and at the time of testing, *.azurewebsites.net required no authentication. (4/6)

R to @AmberWolfSec: In August 2025 we disclosed CVE-2025-0309: a local privilege escalation in the Netskope Windows client via rogue server enrolment. (You can read more at https://blog.amberwolf.com/blog/2025/august/advisory---netskope-client-for-windows---local-privilege-escalation-via-rogue-server/) (2/6)

Published: March 24, 2026 18:19

In August 2025 we disclosed CVE-2025-0309: a local privilege escalation in the Netskope Windows client via rogue server enrolment. (You can read more at blog.amberwolf.com/blog/2025…) (2/6)

This weekend at @BSidesLondon , Darren McDonald delivered a workshop teaching attendees how to work with our DIY high-powered IR "death lasers" and trigger IR door exit sensors from outside the building!

Published: December 17, 2025 09:13

This weekend at @BSidesLondon , Darren McDonald delivered a workshop teaching attendees how to work with our DIY high-powered IR "death lasers" and trigger IR door exit sensors from outside the building!

R to @AmberWolfSec: If you recognise any of these sensors from your own building, and they are visible from outside the building - you might want to reach out to us for a chat.

Published: December 17, 2025 09:13

If you recognise any of these sensors from your own building, and they are visible from outside the building - you might want to reach out to us for a chat.

RT by @AmberWolfSec: It is our pleasure to announce the first Platinum Sponsor and our Opening Keynote Speakers for Securi-Tay 2026 - AmberWolf!

Published: November 29, 2025 16:56

It is our pleasure to announce the first Platinum Sponsor and our Opening Keynote Speakers for Securi-Tay 2026 - AmberWolf!