Iain Smart
@smarticu5
Followers
938
Following
4K
Media
197
Statuses
3K
Hacker, coffee drinker, film watcher. Former secretary of @AbertayHackers, now I break into containers and pipelines for @controlplaneio
In a cluster stealing secrets
Joined June 2009
That 'Project Hail Mary' trailer really does come out swinging with spoilers for the book's plot twists in the first 10 seconds, huh?
0
0
1
I was about to celebrate and say that everyone has behaved when booking tickets, but then found the one who hadn't paid attention to the rules. Those tickets have been cancelled and so that puts back on sale a Playing with Pipelines ticket if anyone was after one.
0
2
5
That CI workshop thingy looks particularly fun.
We have a list of all our speakers and workshop who have confirmed so far up on our site: https://t.co/VNHRl9nJt8
https://t.co/t9Ba12b0MP If any of these excite you (they excite us) then the last ticket drop will be this Friday, May 2nd. https://t.co/a3WPHIL53M
1
1
5
Digging into how the latest Windows Kubernetes vuln works was a fun way to spend a couple of hours. We've just published some of my notes here:
blog.amberwolf.com
AmberWolf Security Research Blog
The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog.
0
12
21
The Kubernetes Security Response Committee has published an advisory for CVE-2024-9042, affecting Windows worker nodes querying the /logs endpoint. Iain Smart, Principal Security Consultant at AmberWolf, reproduced the issue & shared detection insights in our latest blog.
1
4
8
Today, we're releasing NachoVPN, our VPN client exploitation tool, as presented at SANS #HackfestHollywood 2024 🌮🔒 Find the details on the @AmberWolfSec blog, along with the individual advisories, including a not-yet-fully fixed PaloAlto GlobalProtect client RCE👀
10
56
150
🗓️SAVE THE DATE!🗓️ The 13th edition of Securi-Tay will be happening on the 28th of February 2025
0
7
30
I'll be running one of @controlplaneio's CTF scenarios at Cloud Native and Kubernetes Edinburgh this Wednesday (18th) at 18:00. Bring a laptop, hack some chatbots, get some flags! Also probably pizza.
meetup.com
September's meetup is graciously sponsored by the awesome folks at [ControlPlane](https://control-plane.io)! We'll do the usual with doors opening at 6pm for food and drink
0
1
1
If I'm reading the email right, Docker Pro just went from $5/mo to $9/mo and now gets you less than it used to. Admittedly I probably have ~200 image pulls per YEAR so nowhere near the limits, but a doubling of price will probably have me moving from Docker Hub and Desktop soon.
0
0
1
The National Gallery in London is renovating its Sainsbury Wing and they’ve just found a secret letter from one of the original donors, sunk into a concrete column, saying that he hates the columns and is glad they’re being demolished. 10/10 unhinged rich man behaviour, no notes
184
8K
71K
Carrying on Datadog's #Kubernetes #security video series, by starting to take a look at how Kubernetes handles authentication. In this video we're looking at some of the possible pitfalls with client certificate authentication. https://t.co/fHavuECEEt
1
9
23
A customer reached out asking for video tutorials. We obviously have a Lindy handling this, and I was delighted to see that she sent a video. But then I remembered we don't have a video tutorial and realized Lindy is literally fucking rickrolling our customers.
112
743
7K
Another excellent set of challenges from @CtfSecurity. Just got to work out their magical mystery bonus flag now.
Good Morning #defcon32! Registration is still open for the DC Kubernetes CTF. The non-competitive Learning CTF runs Friday and Saturday. The competitive CTF runs Saturday. The Learning CTF will start soon. More information can be found at
0
0
0
Dependency is replaced by one-liner, weekly traffic is reduced by 440GB
163
700
9K
Kicking off tonight’s Cloud Native Edinburgh with the first talk courtesy of Kate Gawron from @doitint
0
2
3
Happy @Steel_Con day to everyone who celebrates! Gutted to be missing it this year, I’ll wave on the way past.
0
0
4