AmberWolfSec Profile Banner
AmberWolf Profile
AmberWolf

@AmberWolfSec

Followers
345
Following
0
Media
3
Statuses
27

Offensive Cyber, Risk Management & Governance, Vulnerability Research and Technical Due Diligence

UK
Joined February 2024
Don't wanna be here? Send us removal request.
@AmberWolfSec
AmberWolf
5 days
This talk builds on our previous SSL VPN work (NachoVPN) - and surprise surprise: Zero Trust still isn’t Zero Risk. If you’re in Vegas, swing by, or hit us up. #DEFCON33 #ZTNA #SASE #ZeroTrust #RedTeam #AmberWolf #VEGAS #DEFCON.
0
0
1
@AmberWolfSec
AmberWolf
5 days
What to expect:.🔓 Bypassing auth and posture checks.📈 Privilege escalation.🔁 Inter-process comms abuse.🚨 Previously undisclosed vulns.🎯 Real-world tradecraft.
1
0
0
@AmberWolfSec
AmberWolf
5 days
We’re dropping fresh research into ZTNA and SASE platforms like ZScaler, Netskope, and Check Point - and showing how “next-gen” cloud VPNs are still vulnerable to some old-school bugs… and a few nasty new ones.
1
0
0
@AmberWolfSec
AmberWolf
5 days
🎤 #DEFCON33 - We’re Presenting!.Big news: AmberWolf is hitting the DEF CON 33 stage this August. Our very own Rich Warren and David Cash (@buffaoverflow and @jonnyspandex respectively) will be presenting Zero Trust, Total Bust – Breaking into thousands of cloud VPNs with one bug.
1
6
16
@AmberWolfSec
AmberWolf
2 months
Read our full analysis of the vulnerability and its potential exploitation here:
blog.amberwolf.com
AmberWolf Security Research Blog
0
0
0
@AmberWolfSec
AmberWolf
2 months
These core dumps may contain sensitive data and compromise the integrity of ThinOS’s storage encryption, directly contradicting Dell’s documentation, which states that all partitions except the boot partition are encrypted.
1
0
0
@AmberWolfSec
AmberWolf
2 months
If the device configuration allows it, this option can be accessed by unauthenticated users. In addition, previously generated core dumps may be accessible to unauthenticated attackers.
1
0
0
@AmberWolfSec
AmberWolf
2 months
AmberWolf has published technical details on CVE-2025-32752, a vulnerability affecting Dell ThinOS. Security researcher @R3n5k1 discovered that when the troubleshooting feature “Create Core Dump” is used, ThinOS saves core dumps to an unencrypted partition.
1
2
5
@AmberWolfSec
AmberWolf
6 months
You can read our latest blog at
blog.amberwolf.com
AmberWolf Security Research Blog
0
0
3
@AmberWolfSec
AmberWolf
6 months
The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog.
1
4
8
@AmberWolfSec
AmberWolf
7 months
All I want for Christmas is U(RL handlers not vulnerable to RCE). AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here:.
blog.amberwolf.com
AmberWolf Security Research Blog
1
9
33
@AmberWolfSec
AmberWolf
8 months
CVE-2024-5921 is a Remote Code Execution and Privilege Escalation vulnerability in Palo Alto Global Protect, which is also exploitable using NachoVPN. Our full technical write up is available here:
blog.amberwolf.com
AmberWolf Security Research Blog
0
4
7
@AmberWolfSec
AmberWolf
8 months
CVE-2024-29014 is an RCE as SYSTEM vulnerability in SonicWall NetExtender that is exploitable using NachoVPN. Full technical details of the vulnerability are available in out blog:
blog.amberwolf.com
AmberWolf Security Research Blog
1
4
13
@AmberWolfSec
AmberWolf
8 months
You can get the code, the prebuilt container or contribute modules on GitHub:
Tweet media one
1
3
5
@AmberWolfSec
AmberWolf
8 months
NachoVPN is a modular server that allows for the automatic exploitation of VPN clients when they connect. It currently supports Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect and Pulse/Ivanti Connect Secure) across a multiple platforms.
Tweet media one
1
1
6
@AmberWolfSec
AmberWolf
8 months
Today, AmberWolf released two blog posts and our tool "NachoVPN" to target vulnerabilities in major VPNs, including CVE-2024-29014 (SonicWall NetExtender SYSTEM RCE) and CVE-2024-5921 (Palo Alto GlobalProtect RCE and Priv Esc), after our SANS HackFest presentation.🧵.
1
23
48
@AmberWolfSec
AmberWolf
9 months
RT @buffaloverflow: Heres the slides from our HackFest Hollywood talk. We shared details on a new Palo Alto 0day and provide some tips on….
0
1
0
@AmberWolfSec
AmberWolf
9 months
AmberWolf is hiring experienced Red Team operators! Join our fun, supportive team if you have (or have had) CCSAS/CCSAM certs and a passion for delivering world-class engagements. Apply now: #hiring #RedTeam.
linkedin.com
Today’s top 12,000+ Logistics Operator jobs in United States. Leverage your professional network, and get hired. New Logistics Operator jobs added daily.
0
3
6
@AmberWolfSec
AmberWolf
9 months
The slides for @buffaloverflow and @johnnyspandex's "Very Pwnable Networks: Exploiting the Top Corporate VPN Clients for Remote Root and SYSTEM Shells" are now available on our GitHub: #hackfest.
Tweet card summary image
github.com
Public presentations by AmberWolf. Contribute to AmberWolfCyber/presentations development by creating an account on GitHub.
0
47
106
@AmberWolfSec
AmberWolf
9 months
RT @jon__reiter: Richard and David from @AmberWolfSec speaking about Very Pwnable Networks: Exploiting the Top Corporate VPN Clients for R….
0
2
0