Security Research Manager. Co-Founder @ZenGo acq by @etoro Advisor @ZeroNetworks. x-VP Research Aorato, acq by @Microsoft. 10 times @BlackHatEvents speaker.

Israel
OMG! i'm in RFC! tools.ietf.org/html/rfc7457#… http://t.co/3feTzqWRav
6
4
150
מוזר שהמדור של @gontarzn שרד את העדכון של הארץ. הפורמט מיצה את עצמו מזמן. הגיע הזמן לחדש.
1
366
תודה על הברכות @Haaretz! חג שמח גם לכם
3
369
Death by a thousand AI slops
📢 PSA for open-source bug hunters We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program. Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027. bughunters.google.com/about/…
9
1,220
לְמִי שֶׁאֵינוֹ מַאֲמִין קָשֶׁה לִחְיוֹת הַשָּׁנָה
2
339
איפה בעולם יש עוד עם כזה, שבו אזרחים משתלטים בקור רוח על מפגע חמוש בגובה אלפי מטרים כשהמטוס בצלילה, ומצילים את חייהם של 180 בני אדם? עם ישראל כולו גאה בכם ומצדיע לכם על הגבורה והתושייה. מחכים לכם בבית ❤️🇮🇱
577
1,890
20,269
413,358
Tal Be'ery retweeted
Geez @nytimes. Here is an alt headline “Brave Israelis subdue Muslim Terrorist Pilot and save over 100 passengers averting worst airplane terror incident since 9-11.
16
59
683
20,747
מי כעמך ישראל
A passenger on the Dubai–Tel Aviv flight recounts: “We are currently in Saudi Arabia. One of the crew members attacked the pilot with a knife and disabled the aircraft’s systems. Yaniv (pictured?) and another passenger stormed the cockpit and subdued the attacker. Luckily, there were two more pilots on board. They were the ones who managed to land the plane.” Well, yes. Overall, the probability that a plane full of Israelis will contain a trained assault team, two additional pilots, and, statistically, at least one cardiac surgeon, psychologist, lawyer, and diamond dealer is substantially higher than 50%.
4
628
Is this only "half" of the attack? @bitget's @graceybitget said "breach... of the hot wallet and warm wallet layers." @SlowMist_Team says it was "invited by Bitget to investigate the theft of assets from its hot wallets." What about "warm" wallets? maybe that's @Mandiant's?
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft. As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly customized withdrawal tool used by the attacker. 🔎 Key findings include: 1. Malicious activity on a certain third-party product involving exploitation of a zero-day vulnerability. 2. Unauthorized access to a certain third-party products management platform on September 25 using an internal employee identity. 3. Recovery of a customized withdrawal tool designed to interact with the wallet system’s withdrawal logic. 4. On-chain activity begins at 02:31 on September 25, with transfers across multiple blockchains over approximately 2 hours and 52 minutes. 5. Subsequent attempts to manipulate withdrawal records and trigger additional BTC withdrawals. We are continuing to investigate how the attacker moved between the affected systems. All date references are to UTC+8. 📄 Read the details of the investigation: github.com/slowmist/Knowledg…
2
416
It would be interesting to learn if the "third-party security products" were abused as they contained relevant information per-se, or just as stepping stone in order to abuse their high permissions and access @ImposeCost @dinodaizovi
@bitget has engaged SlowMist’s security team to investigate the September 25 hot wallet asset theft. As of September 29, our investigation has identified malicious activity involving certain third-party security products and a wallet application host, as well as a highly customized withdrawal tool used by the attacker. 🔎 Key findings include: 1. Malicious activity on a certain third-party product involving exploitation of a zero-day vulnerability. 2. Unauthorized access to a certain third-party products management platform on September 25 using an internal employee identity. 3. Recovery of a customized withdrawal tool designed to interact with the wallet system’s withdrawal logic. 4. On-chain activity begins at 02:31 on September 25, with transfers across multiple blockchains over approximately 2 hours and 52 minutes. 5. Subsequent attempts to manipulate withdrawal records and trigger additional BTC withdrawals. We are continuing to investigate how the attacker moved between the affected systems. All date references are to UTC+8. 📄 Read the details of the investigation: github.com/slowmist/Knowledg…
2
369
Pre-quantum issues @LindellYehuda @matthew_d_green
We discovered a complete forgery of a post-quantum signature candidate: Shipovnik, submitted to TC26. A valid signature for any message can be built from the public key alone, in a fraction of a second on a laptop. With the post-quantum transition on the horizon, the Fireblocks cryptography team started assessing the security of post-quantum signature schemes. The good news is that it's a candidate and not a standard, and it isn't used to authorize blockchain transactions today, so no funds are at risk. It's also a testament to the important role of the years-long processes that national standardisation bodies undertake to develop and choose the cryptographic schemes we all rely on in our daily lives. Our research is part of that process, the public review, where researchers from around the world can audit and try to find breaks in cryptographic schemes before they become standards and start being heavily used. For the full technical breakdown, see the Fireblocks blog post in the comments.
604
🎶 Part-Time Founder🎶 We are undercover startup on the run Chased by VC funding up against the sun We are strangers by day, founders by night Knowing it's so wrong, but feeling so right
חשפנו הערב בגלובס - מייסדי פאראגון יחד עם סא"ל ד', קצין ביחידה טכנולוגית שהקים את קרן נץ-גאיה ועומד להשתחרר בקרוב - יקימו חברת סייבר חדשה. בין המשקיעים: @sequoia ועומרי כספי. ובאיזה שווי מוכנים משקיעים זרים להיכנס בחברה שעדיין לא הוקמה ומייסדיה עובדים במקומות עבודה אחרים?הלינק:
10
4,251
"The attacker exploited vulnerabilities from third-party products to steal internal credentials, then used those credentials to send fraudulent withdrawal commands that bypassed our risk controls."
Quick recap from today's livestream: 1. Withdrawals BTC live on Bitcoin Mainnet & BSC — 9,585 orders, 4,098.036 BTC processed as of 17:00 UTC+8. ETH, USDT, others follow in phases starting tomorrow. 2. What happened Full trace-back complete. The attacker exploited vulnerabilities from third-party products to steal internal credentials, then used those credentials to send fraudulent withdrawal commands that bypassed our risk controls. Private keys were not compromised, and cold wallets were not affected. 3. Security measures taken -The incident has been contained. Affected systems were isolated and the vulnerability has been remediated. -Relevant servers were isolated to prevent further compromise and preserve forensic evidence. -Internal credentials were revoked and reissued, with access to highly sensitive systems restructured. -We notified the relevant third-party vendor, shared details of the vulnerability and disabled the affected functionality pending a fix. -Mandiant and SlowMist continue to support the independent forensic investigation and asset-tracing efforts. 4. Your funds 100% covered by the Bitget Protection Fund. No user impact. Fund will be topped back up to >$300M with our own capital within the week. 5. Bitget Project Stand Together We’re launching Project Stand Together for our retail, VIP and professional users, including a trading-fee reward pool and additional benefits and protections for eligible VIP, PRO and market-maker participants. Details can be found in the links below: Retail & VIP: bitget.com/support/articles/… PRO & institutional: bitget.com/support/articles/… This is our first security incident of this nature in eight years. We take it seriously, and our focus now is on recovery, stronger safeguards and transparency about what we learn. Thank you to our users and industry partners for standing with us.
1
1
832
מישהו יודע כמה אחוזים יש לו? תרומתו תשתקף בזה. אם יש לו משמעותית פחות מהאחרים זה סיפור שונה לגמרי מאשר אם הוא באחוזים דומים. @doritsos
שאלת תם (על אמת): כמה זמן צריך מישהו להשקיע כדי להיחשב מייסד בחברה כמו דקארט? האם סביר שיש זמן פנוי בכמות כזו בזמן שירות בצבא ביחידה כזו (שהשירות בה הוא במידה רבה פריבילגיה)?
3
1,886
👀
The 0-click research continues. Last year Signal, this year @telegram! Looking forward to sharing our research with everyone @BlackHatEvents #BHEU
2
1,112
אפילו את איליה סוצקובר העירו ב 7 באוקטובר ב 4:10
if you value intelligence above all other human qualities, you’re gonna have a bad time
1
13
3,449
האם באמת הבעיה של נשים בסייבר היא שהן לא יכולות לשתות קפה עם לקוח בלי שיחשדו בכוונות רומנטיות?
"לא פשוט להיות גיי בעולם הסייבר אבל יותר קשה להיות אישה" #פגישה פותחת עונה עם אסף רפפורט, הערב בכאן 11 ובכאן BOX @ronikuban @assaf_rappaport
7
12
4,462
TL;DR: Recycled disk blocks weren't wiped before reassignment, so a malicious container could read leftover data from other tenants on the same host by reading its own raw disk.
Our craziest escape yet: The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc, Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too. We reported this to @Cloudflare, who super quickly fixed it. Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog: blog.cloudflare.com/containe…
1
7
44
4,690
דל״פ: לא ״פרצת אבטחה חמורה״. אוריך עשה אוטומציה לשליחת הודעות וואטסאפ באמצעות ultramsg.com/#whatsapp-api וחשף את פרטי הגישה. מה כבר היה יכול לעשות מי שהיה משתלט על החשבון? לשלוח הודעות? לענ״ד, העיסוק בשטויות מסיט את הדיון ומדלל את העיסוק בבעיות האמיתיות
יונתן אוריך בנה בקלוד כלי ניטור לנתניהו ורעייתו. הקוד נותר חשוף ברשת, עם פרצת אבטחה חמורה ■ עשרות ערוצים נסרקו כל דקה וחצי, התראות על שרה שוגרו לוואטסאפ מיוחד: הקוד חשף את המקורות שמזינים את נתניהו והדחף לשלוט בסיפור מתפרץ חשיפה של @bar_peleg ו @omerbenj haaretz.co.il/news/security/…
2
5
1,276
חזרתי לדעה הפופלרית עם כוכבית
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
189
דל״פ: לא ״פרצת אבטחה משמעותית״. אוריך עשה אוטומציה לשליחת הודעות וואטסאפ באמצעות ultramsg.com/#whatsapp-api וחשף את פרטי הגישה. מה כבר היה יכול לעשות מי שהיה משתלט על החשבון? לשלוח הודעות? לענ״ד, העיסוק בשטויות מסיט את הדיון ומדלל את העיסוק בבעיות האמיתיות
1. העובדה שאוריך בנה כלי ניטור בקלוד קוד לא מעניינת במיוחד. מה שהסיפור הזה מראה, שוב, זה את הרשלנות, חוסר המקצועיות וחוסר האכפתיות של יועצי נתניהו. הקוד היה בגיטהאב, פומבי וחשוף לכל. עד כאן בסדר. אבל בקוד היו מפתחות לקבוצות ווטסאפ, וזו כבר פרצת אבטחה משמעותית.
1
4
1,984
חזרתי לדעה הפופולרית, עם כוכבית
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
192
טוב, שיניתי את דעתי. זה השטן*! כדי להשתמש ב ultramsg המשתמש צריך לחבר את המכשיר שלו. כלומר כל תכולת הוואטסאפפ של החשבון שאוריך חיבר* (הסטוריה, אנשי קשר) הסתנכרנה לשרתים עלומים , שיכלו לנטר בזמן אמת כל פעילות שלו ואף לשלוח בשמו. *אם אוריך עשה את זה עם החשבון שלו זה אכן חמור מאד. אם הוא עשה את זה עם חשבון יעודי אז לא. במאמר מוסגר: לא ברור לי למה זה לא כתוב בכתבה אלא כל מיני דברים מוזרים אחרים.
1. העובדה שאוריך בנה כלי ניטור בקלוד קוד לא מעניינת במיוחד. מה שהסיפור הזה מראה, שוב, זה את הרשלנות, חוסר המקצועיות וחוסר האכפתיות של יועצי נתניהו. הקוד היה בגיטהאב, פומבי וחשוף לכל. עד כאן בסדר. אבל בקוד היו מפתחות לקבוצות ווטסאפ, וזו כבר פרצת אבטחה משמעותית.
2
10
1,517