
Aaron Costello
@ConspiracyProof
Followers
2K
Following
2K
Media
4
Statuses
304
🇮🇪 ✝️ Chief of SaaS Security Research @ AppOmni Opinions may be that of James Joyce or Samuel Beckett who occasionally channel their spirits through me.
Ireland, Capital of Europe
Joined January 2012
RT @jamescox91: Spoke to @ConspiracyProof about his discovery of 1.1 million NHS employees' records being leaked online, Aaron previously d….
0
1
0
Want to know how you can hack Microsoft Power Page websites? How I was able to access (and later secure) PII of 1.1 MILLION #NHS employees? With my latest blog post, you can learn how to pentest a Power Page site for data leaks in as little as 2 minutes. Check it out below:.
0
8
46
RT @CRN: More than 1,000 ServiceNow instances have been discovered to be exposing potentially sensitive Knowledge Base data, according to @….
crn.com
A researcher from security vendor AppOmni uncovered more than 1,000 ServiceNow instances that have been exposing Knowledge Base data.
0
1
0
RT @jamescox91: Spoke to @ConspiracyProof about his discovery of the HSE vaccine data of one million people being exposed, and how he publi….
0
1
0
It really concerns me that the HSE are claiming it requires 'deep technical expertise'. They'd be right. if I hadn't published a step-by-step guide on how to manually find, exploit, and secure these kinds of issues in Salesforce systems a year prior:
enumerated.ie
Read about my recent disclosure on how vaccination details for 1m+ users were exposed in a GOV implementation of Salesforce Health Cloud. My own blog post will be published to the @AppOmniSecurity site tomorrow! . #salesforce #hse #saas #saassecurity #cybersecurity #sfdc.
0
0
11
Other publications available on: .
independent.ie
The HSE suffered an IT glitch that weakened security around the vaccination details of more than one million people, the agency has admitted.
0
0
3
Read about my recent disclosure on how vaccination details for 1m+ users were exposed in a GOV implementation of Salesforce Health Cloud. My own blog post will be published to the @AppOmniSecurity site tomorrow! . #salesforce #hse #saas #saassecurity #cybersecurity #sfdc.
The Health Service Executive has said it "misconfigured" a database containing the vaccination information of more than one million people
1
2
9
You may have received this communication as a result of my recent publication which analysed the remediation efforts by ServiceNow and discussed a few oversights that may be cause for concern. Let me provide some details within this thread /1. #servicenow #saas #cybersecurity
2
6
27
Check out my analysis and timeline of the changes made by ServiceNow, topped with my own skepticism regarding the comprehensiveness of the fixes, and a final dash of data security recommendations for the future. #saas #servicenow #cybersecurity #sspm.
appomni.com
Learn more about the ServiceNow updates to mitigate ACL misconfiguration risks and how to avoid regressing your organization’s data security posture moving forward.
0
3
11
Fantastic coverage of my ServiceNow research by .@TheRegister ! A great explanation for individuals whom may not be super technical but wish to gain a basic understanding of how thousands of organisations were exposing sensitive data in #ServiceNow. #saas #cybersecurity.
0
0
5
140k+ URLs, that's the potential blast wave of this issue. Tonnes of the Fortune 500 affected and I've got many open dialogues with Fortune 50 companies that are leaking data such as:.- Entire CMDB.- Email Content .- File Content.- Internal KB articles.- Internal tickets. #saas.
@nullenc0de @AlphaRingo It’s insane the quantity of instances, a fast check and I saw +140k urls.
2
2
22
For those who haven't read my research, it's not too late. It's making waves! 🌊🌊. #saas #bugbountytips #CyberSecurity #servicenow.
🪳👀🚨DEVELOPING: A potential data exposure issue within ServiceNow's built-in capability has been identified. This could allow unauthenticated users to extract data from records.
1
7
25