Sign in

AmberWolf

@amberwolfsec.bsky.social
63 followers 1 following 12 posts

Offensive Cyber, Risk Management & Governance, Vulnerability Research and Technical Due Diligence

PostsRepliesMedia
AmberWolf @amberwolfsec.bsky.social · 04/06/2025
Read our full analysis of the vulnerability and its potential exploitation here: blog.amberwolf.com/blog/2025/ju...
blog.amberwolf.com
ThinOS - Unencrypted Memory Dumps (CVE-2025-32752)
AmberWolf Security Research Blog
000
AmberWolf @amberwolfsec.bsky.social · 04/06/2025
These core dumps may contain sensitive data and compromise the integrity of ThinOS’s storage encryption, directly contradicting Dell’s documentation, which states that all partitions except the boot partition are encrypted.
100
AmberWolf @amberwolfsec.bsky.social · 04/06/2025
If the device configuration allows it, this option can be accessed by unauthenticated users. In addition, previously generated core dumps may be accessible to unauthenticated attackers.
100
AmberWolf @amberwolfsec.bsky.social · 04/06/2025
AmberWolf has published technical details on CVE-2025-32752, a vulnerability affecting Dell ThinOS. Security researcher Darren McDonald discovered that when the troubleshooting feature “Create Core Dump” is used, ThinOS saves core dumps to an unencrypted partition.
110
AmberWolf @amberwolfsec.bsky.social · 17/01/2025
You can read our latest blog at blog.amberwolf.com/blog/2025/ja...
blog.amberwolf.com
Reproducing CVE-2024-9042: Command Injection in Windows Kubernetes Nodes
AmberWolf Security Research Blog
020
AmberWolf @amberwolfsec.bsky.social · 17/01/2025
The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog.
134
AmberWolf @amberwolfsec.bsky.social · 28/12/2024
All I want for Christmas is U(RL handlers not vulnerable to RCE)... AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here: blog.amberwolf.com/blog/2024/de...
blog.amberwolf.com
Delinea Protocol Handler - Remote Code Execution via Update Process (CVE-2024-12908)
AmberWolf Security Research Blog
032
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
CVE-2024-5921 is a Remote Code Execution and Privilege Escalation vulnerability in Palo Alto Global Protect, which is also exploitable using NachoVPN. Our full technical write up is available here: blog.amberwolf.com/blog/2024/no...
blog.amberwolf.com
Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)
Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)
110
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
CVE-2024-29014 is an RCE as SYSTEM vulnerability in SonicWall NetExtender that is exploitable using NachoVPN. Full technical details of the vulnerability are available in out blog: blog.amberwolf.com/blog/2024/no...
blog.amberwolf.com
SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)
SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)
100
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
You can get the code, the prebuilt container or contribute modules on GitHub: github.com/AmberWolfCyb...
github.com
GitHub - AmberWolfCyber/NachoVPN: A tasty, but malicious SSL-VPN server 🌮
A tasty, but malicious SSL-VPN server 🌮. Contribute to AmberWolfCyber/NachoVPN development by creating an account on GitHub.
100
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
NachoVPN is a modular server that allows for the automatic exploitation of VPN clients when they connect. It currently supports Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect and Pulse/Ivanti Connect Secure) across a multiple platforms. blog.amberwolf.com/blog/2024/no...
blog.amberwolf.com
Introducing NachoVPN: One VPN Server to Pwn Them All
AmberWolf Security Research Blog
100
AmberWolf @amberwolfsec.bsky.social · 26/11/2024
Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵
165