AmitaiCo Profile Banner
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ Profile
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ

@AmitaiCo

Followers
2K
Following
8K
Media
111
Statuses
1K

โœฆ researching threats @wiz_io ๐Ÿž maintaining vulns @cloudvulndb ๐ŸŽ™๏ธ casting pods @ https://t.co/9Jsah9BjbO

Tel Aviv, Israel
Joined August 2011
Don't wanna be here? Send us removal request.
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 year
Happy to introduce "Pivot Atlas", a digital pivoting handbook for cyber threat intel analysts. I've been working on this as a personal project with the goal of graphing the "pivotability" of threat intel artifacts and providing real-world examples and reference material. (1/2)๐Ÿงต
Tweet media one
Tweet media two
Tweet media three
Tweet media four
12
85
319
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
5 hours
Very curious to see how this plays out but I'm optimistic - while there's a risk of media overhyping early disclosures ("There's an iOS 0day but you'll need to wait 90 days to be protected!!111"), ZDI has had a similar policy for a while now and it's been fine.
@natashenka
Natalie Silvanovich
19 hours
While most vendors ship timely patches for vulnerabilities reported by Project Zero, they donโ€™t always reach users. Today, weโ€™re announcing Reporting Transparency, a new policy to encourage downstream fixes.
0
0
1
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
19 hours
RT @galnagli: I hacked a popular vibe coding platform with a simple, straight-forward logic flaw - allowing access to private applicationsโ€ฆ.
0
120
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
2 days
Check out @merav_br's great in-depth writeup on TraderTraitor's tradecraft (traitcraft?) and history of operations:.
@wiz_io
Wiz
2 days
๐Ÿšจ TraderTraitor: North Korea's cyber "traitor" inside the crypto world. This hacking crew hijacks dev workflows, poisons open-source, and compromises cloud environments โ€” all to steal billions in crypto. Here's how they do it ๐Ÿงต
Tweet media one
0
2
5
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
7 days
RT @wiz_io: ๐Ÿšจ New research: A cryptomining campaign is hijacking exposed PostgreSQL, hiding payloads in fake 404 pages, and abusing legit iโ€ฆ.
0
10
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
7 days
RT @leak_ix: Just a heads-up, attackers found a way to leak information, including keys entirely from memory. Checking for "the file" is noโ€ฆ.
0
62
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
7 days
RT @cloudvillage_dc: โšก๏ธExcited to have @AminovDanielle & Yaara Shrike at Cloud Village @DEFCON 33 presenting:.โ€œAuths Gone Wild: When โ€˜Autheโ€ฆ.
0
5
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
9 days
RT @wiz_io: ๐Ÿšจ Research update: #ToolShell is back, and it just leveled up. Two new vulnerabilities in Microsoft SharePoint Server, CVE-202โ€ฆ.
0
5
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
13 days
RT @nirohfeld: We found a new container escape affecting all container runtimes using @NVIDIA GPUs. The crazy part?.The exploit is just thโ€ฆ.
0
133
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
15 days
RT @wiz_io: ๐Ÿ’ก Eden hosts @sherrod_im, @IssaUrbanGirl & @41thexplorer . Cloud chaos, career confessions & the future of cybersecurity. Thisโ€ฆ.
0
4
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
20 days
RT @sweetdelightss: I love when people share their screen. You instantly have all my attention. How many tabs are open?.Whatโ€™s the icon siโ€ฆ.
0
6
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
21 days
RT @wiz_io: ๐ŸŽ™๏ธ Scattered Spider's new target? Airlines. Eden & @AmitaiCo break down the latest in the cloud >> .1. Help desk hacks .2. AI'โ€ฆ.
0
3
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
23 days
RT @wiz_io: ๐Ÿšจ New vulnerabilities in #NetScaler (incl. a 0-day) are now exploited in the wild. 2 enable admin access via session theft. 3.5โ€ฆ.
Tweet card summary image
wiz.io
Detect and mitigate CVE-2025-5349, CVE-2025-5777, and CVE-2025-6543, Citrix Netscaler ADC and Gateway vulnerabilities being exploited in the wild. Organizations should patch urgently.
0
6
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
24 days
RT @Horizon3Attack: Indicators of Compromise:.๐Ÿ”น Depending on logging configurations, log entries in ns.log with non-printable characters arโ€ฆ.
0
3
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
28 days
RT @wiz_io: ๐Ÿšจ Wiz spotted a JDWP RCE attack deploying a stealthy cryptominer within hours. Custom XMRig, no CLI flags, deep persistence. Dโ€ฆ.
Tweet card summary image
wiz.io
Understanding the risks and impact of deploying dev-mode in production environments.
0
1
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 month
RT @AwsSecDigest: Tracking Cloud-Fluent Threat Actors โ€“ Part Two: Behavioral Cloud IOCs.By Merav Bar & Gili Tikochinski. Sophisticated attaโ€ฆ.
0
3
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 month
RT @nirohfeld: Something Iโ€™m incredibly proud of is finally live. We've launched the Cloud Security Championship: a 12-month series of deeโ€ฆ.
Tweet card summary image
cloudsecuritychampionship.com
Join our monthly cloud security CTF challenge, built by top Wiz researchers. Solve real-world scenarios and rise to the top of the leaderboard.
0
11
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 month
RT @wiz_io: ๐ŸŽ™๏ธ New drop: @DavidJBianco joins Crying Out Cloud to talk threat hunting, the Pyramid of Pain, and more. Don't miss this cybโ€ฆ.
0
1
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 month
RT @merav_br: Check out Gili and my BSidesSF talk before Taylorโ€™s team takes it down for copyright infringement (which would be an honor) โœจโ€ฆ.
0
2
0
@AmitaiCo
Amitai Cohen ๐ŸŽ—๏ธ๐ŸคŸ
1 month
Check out @AminovDanielle and @GiliTikochinki's recent talk at @DistrictCon about exploitation in the wild of application misconfigurations - this category of risk is well known to threat actors but often ignored by defenders:
0
4
12