I am retiring this social media account. Find me as @hal_pomeranz@infosec.exchange

Orlando, FL
Joined November 2008
Hal Pomeranz retweeted
Our latest blog post covers how our services team detected and then investigated a 0day vulnerability being exploited in Sophos firewalls #DFIR #infosec
✅ Exploitation of 0⃣ day at the time? ✅ Web🐚s involved? ✅ DNS MiTM? 👨‍🏭 It can only mean one thing. Volexity blog: volexity.com/blog/2022/06/15… #threatintel #cve20221040 #apt
3
13
Looking back is just nostalgia without learning & growing from the past. I’m planning to cover the lessons of the past & introduce evolutionary revelations for the future of bug bounties, labor rights, & the world we want to build. I hope to see you there. blackhat.com/us-22/briefings…
1
3
17
$60K bug bounty and thank you Tzah for not selling this on the black market where you likely could have made much more.
I was able to access thousands of companies’ passwords on #Azure and run code on their VMs. This includes access to Microsoft’s own credentials… 💣 Here’s HOW I did it. This is the story of #SynLapse. (1/11)
2
2
23
Replying to @fwiles
I was getting my Solaris admin certs almost 30 years ago. Sigh.
1
1
Hal Pomeranz retweeted
What I had to say about AI in 2018, and pretty much what I say today.
128
5,991
614
23,128
Replying to @falconsview
Oldest— competitive gymnastics, later diving Middle—drum line, marching band, jazz band I feel you, brother
1
1
Hal Pomeranz retweeted
Researchers on Palo Alto's Unit 42 team analyse PingPull, a remote access trojan used by the GALLIUM APT group (also known as Softcell). PingPull has the capability to leverage three protocols (ICMP, HTTP(S) and raw TCP) for command and control. unit42.paloaltonetworks.com/…
14
2
30
In this blog, Microsoft provides details about the BlackCat ransomware, also known as ALPHV, techniques and capabilities. They also take a deep dive into two incidents they’ve observed where BlackCat was deployed | microsoft.com/security/blog/… @MsftSecIntel
15
1
24
Replying to @elpie
Marmite expires?! Geez I thought that stuff would outlast the planet.
1
Hal Pomeranz retweeted
You deserve to live your authentic gender expression, and it’s profoundly wrong of people to take that from you.
3
34
179
Hal Pomeranz retweeted
Let’s internalize this for a second.
1,004
67,940
1,208
345,191
Replying to @webjedi
“The rose goes in the front, big guy.”
1
1
Replying to @k8em0
Your mother's contributions will continue to create new lives long after her passing, and that means she will never truly be gone. And she will always live on in the hearts of you and your family. May her memory be a blessing.
1
2
If we ever get solid "right to repair" laws in this country, make sure they also include the "right to refill" to stop the greedy bloodsuckers like @HP and @Keurig
1
2
8
Replying to @agtmadcat
Don’t make that dirty! :-D
1
I would gladly eat your brisket
1
Hal Pomeranz retweeted
Louder for the people in the back! Very few things survive full forensic analysis, but that's not the goal. Even if your "one cool trick" does, entire (useful) attack chains do not. The goal is (and always has been) bypassing real time alerting. Anything else is gravy.
Replying to @NotMedic
Note that we’re not fully trying to bypass forensic data, but just alerts that get sent to a SOC analyst for triage.
3
27
Hal Pomeranz retweeted
Some asshat from NASA called me Joe’s “PR girl” at the rocket launch today, and I’ve spent the day trying to talk myself down from quitting rocketry forever. I’m 25, I’ve been dealing with this shit for over a decade in STEM, and it STILL gets to me sometimes. A thread 👇
270
628
107
5,015