Rich Warren @buffaloverflow.rw.md · 29/07/2025Clearing out the research queue in time for DEFCON, and dropping some new NachoVPN updates! 🌮🔓 Part 1: Ivanti SYSTEM RCE/LPE: blog.amberwolf.com/blog/2025/ju...blog.amberwolf.com 020
Reposted by Rich Warrenjohnnyspandex.bsky.social @johnnyspandex.bsky.social · 26/12/2024Some Christmas cheer with @buffaloverflow.rw.md . A nice bug in the URL handler for Delinea Secret Server. blog.amberwolf.com/blog/2024/de...blog.amberwolf.comDelinea Protocol Handler - Remote Code Execution via Update Process (CVE-2024-12908)AmberWolf Security Research Blog 033
Rich Warren @buffaloverflow.rw.md · 27/11/2024d3bfdeed17448756d36a326f0b7972162b7f67951df6d2004faa196444b6c5aa 🙃 010
Rich Warren @buffaloverflow.rw.md · 26/11/2024For anyone mad at Palo Alto for pushing out a limited fix, just remember that other vendors (*cough* Ivanti) consider 1-click RCE from a browser .. a feature 😜 www.reddit.com/r/paloaltone... 210
Rich Warren @buffaloverflow.rw.md · 26/11/2024New platform, who dis? It me, and @johnnyspandex.bsky.social dropping some VPN client exploit freshness! 🌮🔒 Today, we're releasing NachoVPN, our VPN client exploitation tool, as presented at SANS HackFest Hollywood. Get it on the @amberwolfsec.bsky.social blog: blog.amberwolf.com/blog/2024/no...blog.amberwolf.comIntroducing NachoVPN: One VPN Server to Pwn Them AllAmberWolf Security Research Blog 01311