
Ophion Security
@OphionSecurity
Followers
249
Following
10
Media
13
Statuses
54
Your offensive security partner. Unleash an automated hacker against your attack surface with Orion.
Los Angeles, CA
Joined October 2022
RT @uraniumhacker: Presenting on some fun stuff with @OphionSecurity this year at @_kernelcon_ and @bsidesseattle. Come for the talk, stay….
0
2
0
Live chat histories contain treasure trove of data. From answers to security questions to credentials and more. We found a way to access it all in Cisco's Webex Connect. Read here: #vulnerability #vulnerabilitydisclosure #attacksurfacemanagement.
ophionsecurity.com
In July 2024, we identified a vulnerability that resulted in access to millions of live customer support messages for organizations using Cisco Webex Connect.
0
1
2
We are actively scanning Microsoft's GitHub organization and more than 150k repositories and 5k users. You can do the same for your organization starting today. Check out the demo: #githubactions #githubsecurity #attacksurfacemanagement.
0
0
1
Thanks for the shout! We love all the episodes coming out! Looking forward to sharing more research blogs in coming months.
New Episode is live covering the craziness with Zendesk and the nuances of how "informative" report disclosure should be handled. Also, some badass write-ups from @OphionSecurity and a new song drop from @realytcracker!.
0
1
2
Endless security reviews, questionnaires, and compliance can be a nightmare when selling to enterprises. 🛡️ What if you could handle it all in one platform? Pentests, Questionnaires, & more. Check it out: #Cybersecurity #SaaS #SecurityCompliance
0
1
6
A simple cookie value allowed disclosing chats of hundreds to thousands of users through a Live Chat integration. Learn more on blog one of two from our Live Chat security research. #vulnerabilitydisclosure #livechat #ophionsecuritylab.
ophionsecurity.com
A misconfiguration in an organizations' setup of their live chat system allowed unauthenticated access to user chat histories with customer support agents.
0
0
0
RT @mallocsys: Yay, I was awarded a $37,500 bounty on @Hacker0x01! Had a fun time hacking AWS at @HackerOne's LHE….
hackerone.com
- https://ophionsecurity.com
0
21
0
How should at-scale offensive scanning work? What values do they provide to companies? Checkout a recent podcast @mallocsys did with FireTail's Jeremy Snyder about it:
0
0
0
That’s what we call 0 bullshit, no FUD hacking. Research ➡️ find vulns ➡️ write exploits ➡️ report.
Flight from Vegas after Defcon got delayed…hacked for 2 hours during the delay…reported a P2 on Square…got paid. I love hacking. #bugbounty #hacking
0
0
0
RT @mallocsys: Flight from Vegas after Defcon got delayed…hacked for 2 hours during the delay…reported a P2 on Square…got paid. I love hack….
0
11
0
Increase your sticker game with these stickers next week at BlackHat and DEF CON. #hackersummercamp #defcon #blackhat2024.
0
0
0
There is no such thing as too much data when building context based scanners. More data -> more knowledge -> more research -> more vulnerabilities to identify and resolve 💻.
Currently monitoring almost 1million+ records and assets through automation in one of our test deployments. Might have automated too hard.
10
0
2
Orion in the real world 🤩.
🛡️ Vulnerability of the Week: Going from High to Critical in 5 Minutes to get millions of customers' PII. When testing a company, I found a vuln where authenticated users could pass enumerable account tokens to access another user's PII: DoB, Address, Phone, Transaction history,.
0
0
0
We had an amazing time at BSides SF meeting with everyone and discussing pain points with traditional attack surface management. Thank you for having us @BSidesSF! #attacksurfacemanagement #bsidessf
0
1
3
RT @uraniumhacker: Nothing better than when a product you have been developing for past few months finds another critical on a Monday eveni….
0
1
0
Attack Surface Management should be proactive not reactive. Meet the Ophion team at BSides SF to learn how Orion can help you identify and monitor for vulnerabilities in your assets including supply-chain dependencies, SaaS deployments, on-premise applications and more. #bsidessf
0
0
0