
Liv Matan
@terminatorLM
Followers
721
Following
254
Media
41
Statuses
133
Recently I discovered a one-click RCE vulnerability in #Azure that affects Function apps, App services, and Logic apps. The vulnerability enables attackers to fully take over the targeted victim's application and managed identity token. This is the story of #EmojiDeploy ._. 🧵
10
52
166
With 𝐚 𝐭𝐨𝐭𝐚𝐥 𝐨𝐟 ~18 vulnerability reports across popular Google Cloud products, including several critical and high-severity issues, I’m excited to share that I earned 2nd place in the latest Google LHE! . Huge thanks to the @GoogleVRP team and all the researchers.
8
4
134
Recently got back from Google’s bugSWAT LHE event in Tokyo 🇯🇵 - focused on AI, and what an experience!.Met old friends, made new ones, and even found some valid vulns in Gemini and other AI products. Can’t wait to the next Cloud bugSWAT in a month!.A big thanks to @GoogleVRP
2
0
30
RT @sivaneshashok: Published a write up on a couple of RCEs @kl_sree @asterfiester and I found in Google Cloud products. We got a $10k bou….
0
28
0
Say hi to ConfusedComposer😵💫- a fresh GCP privilege escalation vuln I discovered in Cloud Composer. This one is a variant of ConfusedFunction, which some of you might remember from my previous blog and recent talks. Shoutout to the @GoogleVRP team :).
1
5
19
🏃♂️Meet ImageRunner: A privilege escalation vulnerability I discovered in GCP Cloud Run. Thank you for the @GoogleVRP team for working closely with us on this one. *Stay tuned for more blogs to come!.
0
4
23
RT @shellyraban: Thanks for featuring my DSLs attack techniques research!.Read all about it in our blog-.
0
2
0
Feel free to read the full research story in the CloudImposer blog: (11/11)🧵.@TenableSecurity .
0
1
9
Dependency Confusion was first discovered by @alxbrsn and allows attackers to hijack a package installation process by uploading a package with the same name and a higher version to the public registry (4/11)🧵
1
0
3