Eslam Salem
@netcodex.bsky.social
300 followers 56 following 33 posts
Manager, security research @ Datadog | he/him | Chess lover | Blackhat speaker | ex Sqreen.io, Shieldfy.io | my website: https://eslam.io
Posts Media Videos Starter Packs
netcodex.bsky.social
I still didn't install bat yet but looks very good. I will do it now.
netcodex.bsky.social
I'm in love with claude code. The way it handles code writing and automates bash tasks is amazing and so convenient to me.
if you are an experienced developer, know what you are doing, the tasks that usually take Weeks. You will be able to do it in Hours 🤯🤯 #claudecode #ai
netcodex.bsky.social
Q for developers. Do you love/hate mandatory security training? And why?
#security #training #developers
netcodex.bsky.social
🚨 The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions!

Deep dive analysis in this obfuscated campaign including (PowerShell & VBS scripts, PE malware, Malicious browser extensions even stegomalware)

Enjoy reading securitylabs.datadoghq.com/articles/mut...
The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions | Datadog Security Labs
Analysis of a threat actor campaign targeting Solidity developers via three malicious VS Code extensions
securitylabs.datadoghq.com
netcodex.bsky.social
Pretty interesting threat campaign have been discovered by our research team.
We will be disclosing it in couple of hours , stay tuned 😉
#threats #malicious #security_research #datadog
netcodex.bsky.social
Recognizing employees for a job well done is just as important as giving constructive feedback when they underperform. Balance builds growth. #Leadership #Feedback
netcodex.bsky.social
I don't like threat actors attribution that much because in most cases it's wrong and so easily to be forged. We still should cluster campaigns but there is no "high confidence" attribution IMHO.
Reposted by Eslam Salem
tib3rius.bsky.social
I have been told there will be a special announcement at 10am CET (that's 4am EDT btw) regarding this.

I will release the info I have at that time also. Thank you for the support.
tib3rius.bsky.social
BREAKING.

From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
netcodex.bsky.social
Any idea what will happen to the CVE program after MITRE
x.com/0xTib3rius/s...
x.com
Reposted by Eslam Salem
mccune.org.uk
It’s the tutorial room at #kubecon where we’ll be hacking up a storm in just over 30 minutes!
Picture of the tutorial room in Kubecon eu 2025
netcodex.bsky.social
I think it's time for me to start digging into AI and LLMs. I'm not sure where to start, any advice?
netcodex.bsky.social
Seeing phrack magazine brings so much good memories. Good old days.
Reposted by Eslam Salem
mccune.org.uk
It's amazing how important one Phrack article from 27 years ago has been for web application security.

Covering what we now call SQL Injection and SSRF (amongst other things) problems we're still trying to handle today laid out in a couple of paragraphs

phrack.org/issues/54/8#...
.:: Phrack Magazine ::.
Phrack staff website.
phrack.org
netcodex.bsky.social
I love it when some people tells me that's is your limit, this is your ceiling. This is when I feel fire within me reignite!
netcodex.bsky.social
Amazing presentation about supply chain security and the amazing work we do by our leaders @techy.detectionengineering.net
(Director of research) and Andrewkrug (Manager of advocacy) youtu.be/1b0RIi19qrw?...
AWS re:Invent 2024 - Beyond just observing, protecting your whole software supply chain (SEC406)
YouTube video by AWS Events
youtu.be
Reposted by Eslam Salem
christophetd.fr
Supply-chain attack in the ultralytics PyPI package: github.com/ultralytics/...

An attacker opened a pull request and pushed a commit with a malicious name, leading to CI code injection.

They then backdoored versions 8.3.41 and 8.3.42 with code downloading a second-stage binary from GitHub
netcodex.bsky.social
Awesome, Stratus Red Team v2.20.0 is now available 🎉
christophetd.fr
Stratus Red Team v2.20.0 is now available, with great contributions from @flekyy90.bsky.social allowing you to reproduce AWS TTPs seen in the wild!

➔ Use GetFederationToken to generate temporary credentials

➔ Use SendSerialConsoleSSHPublicKey to pivot to EC2 instances

github.com/DataDog/stra...
netcodex.bsky.social
My Blackhat MEA arsenal presentation: "Detect Malicious Packages with Guarddog"
drive.google.com/file/d/11SAN...