
AmberWolf
@AmberWolfSec
Followers
345
Following
0
Media
3
Statuses
27
Offensive Cyber, Risk Management & Governance, Vulnerability Research and Technical Due Diligence
UK
Joined February 2024
This talk builds on our previous SSL VPN work (NachoVPN) - and surprise surprise: Zero Trust still isn’t Zero Risk. If you’re in Vegas, swing by, or hit us up. #DEFCON33 #ZTNA #SASE #ZeroTrust #RedTeam #AmberWolf #VEGAS #DEFCON.
0
0
1
🎤 #DEFCON33 - We’re Presenting!.Big news: AmberWolf is hitting the DEF CON 33 stage this August. Our very own Rich Warren and David Cash (@buffaoverflow and @jonnyspandex respectively) will be presenting Zero Trust, Total Bust – Breaking into thousands of cloud VPNs with one bug.
1
6
16
Read our full analysis of the vulnerability and its potential exploitation here:
blog.amberwolf.com
AmberWolf Security Research Blog
0
0
0
AmberWolf has published technical details on CVE-2025-32752, a vulnerability affecting Dell ThinOS. Security researcher @R3n5k1 discovered that when the troubleshooting feature “Create Core Dump” is used, ThinOS saves core dumps to an unencrypted partition.
1
2
5
All I want for Christmas is U(RL handlers not vulnerable to RCE). AmberWolf has published information about CVE-2024-12908, a Remote Code Execution vulnerability in the Delinea Secret Server Protocol Handler. You can read our blog & PoC here:.
blog.amberwolf.com
AmberWolf Security Research Blog
1
9
33
CVE-2024-5921 is a Remote Code Execution and Privilege Escalation vulnerability in Palo Alto Global Protect, which is also exploitable using NachoVPN. Our full technical write up is available here:
blog.amberwolf.com
AmberWolf Security Research Blog
0
4
7
CVE-2024-29014 is an RCE as SYSTEM vulnerability in SonicWall NetExtender that is exploitable using NachoVPN. Full technical details of the vulnerability are available in out blog:
blog.amberwolf.com
AmberWolf Security Research Blog
1
4
13
RT @buffaloverflow: Heres the slides from our HackFest Hollywood talk. We shared details on a new Palo Alto 0day and provide some tips on….
0
1
0
AmberWolf is hiring experienced Red Team operators! Join our fun, supportive team if you have (or have had) CCSAS/CCSAM certs and a passion for delivering world-class engagements. Apply now: #hiring #RedTeam.
linkedin.com
Today’s top 12,000+ Logistics Operator jobs in United States. Leverage your professional network, and get hired. New Logistics Operator jobs added daily.
0
3
6
The slides for @buffaloverflow and @johnnyspandex's "Very Pwnable Networks: Exploiting the Top Corporate VPN Clients for Remote Root and SYSTEM Shells" are now available on our GitHub: #hackfest.
github.com
Public presentations by AmberWolf. Contribute to AmberWolfCyber/presentations development by creating an account on GitHub.
0
47
106
RT @jon__reiter: Richard and David from @AmberWolfSec speaking about Very Pwnable Networks: Exploiting the Top Corporate VPN Clients for R….
0
2
0