Sign in

AmberWolf

@amberwolfsec.bsky.social
63 followers 1 following 12 posts

Offensive Cyber, Risk Management & Governance, Vulnerability Research and Technical Due Diligence

PostsRepliesMedia
AmberWolf @amberwolfsec.bsky.social · 04/06/2025
AmberWolf has published technical details on CVE-2025-32752, a vulnerability affecting Dell ThinOS. Security researcher Darren McDonald discovered that when the troubleshooting feature “Create Core Dump” is used, ThinOS saves core dumps to an unencrypted partition.
110
AmberWolf @amberwolfsec.bsky.social · 17/01/2025
The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog.
134
AmberWolf @amberwolfsec.bsky.social · 28/12/2024
All I want for Christmas is U(RL handlers not vulnerable to RCE)... AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here: blog.amberwolf.com/blog/2024/de...
blog.amberwolf.com
Delinea Protocol Handler - Remote Code Execution via Update Process (CVE-2024-12908)
AmberWolf Security Research Blog
032
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵
165