Amit Serper

Software and hardware hacker, (in)security researcher, musician,MTB/Gravel cyclist,politics nerd. Not necessarily in that order. ▪️Security Research Lead at Crowdstrike🦅▪️ BsidesTLV review board. Ex gov/Cybereason/Guardicore/Akamai/Sternum

Currently focused on Cloud computing and Linux (low and high level) security research
עברית/English/Poco Español

2026-02-21

Lmao. Delusional regime.

2026-02-21

Finally moved my mini-pc servers to the "under the basement stairs data center". I still have two kubernetes nodes left in my office upstairs, but they're silent (mini pcs as well), so eventually they'll move downstairs as well. But right now it's so quiet here without the drone of the enterprise grade HDDs gnawing my brain

2026-01-29

Imagine looking at the Grey zone as a reliable news source lmao

2026-01-26

For the first time since 2014 there are no Israeli hostages, alive or dead, being held in Gaza. Those yellow ribbons can come off now 🎗️

2026-01-26

@Viss Yeah, I don't go on mastodon as often as I used to. I actually made some pulled chuck roast with bulgogi sauce today, slow cooked, delish stuff, kimchi and all.

2026-01-26

Morphine was such a brilliant band. Man, I can't stop listening to them, especially in this weather.

2026-01-26

@Viss Oof. I missed that kind of content.

2026-01-26

The concept of ClawdBot is cool, but people buy entire Mac minis just for that and I find it completely insane.

2026-01-25

@infoseclogger I'm a tokyo night kinda guy

2026-01-25

@zcutlip yikes

2026-01-25

I friggin love my framework laptop

2026-01-23

@dannotdaniel unfortunately battlefield won't run on linux

2026-01-23

On the rare occasion I boot up my Windows machine, I’m instantly reminded why it’s such a rare occasion

2026-01-21

Now we wait

Severity

9.1/10
CVSS v3 base metrics
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None
Learn more about base metrics
2026-01-21

Trump saying that the iron dome is solely based on American technology is an insane lie

2026-01-17

@zcutlip they actually fixed it pretty quickly but they're refusing to acknowledge a low severity vulnerability and pushing back on everything. This is taking to much of too many people's time.

2026-01-17

Some people are willing to die on the dumbest hill for a low impact vulnerability instead of just admitting it. The amount of time and energy this ridiculous back-and-forth with a certain open source project about a truly, stupid, input validation vulnerability (THAT THEY HAD ALREADY FIXED!) is really too much. This isn't the first time with those folks. It's incredibly frustrating. I am sure that they are frustrated with me as well. This honestly is not worth my time.

2026-01-15

Re yesterday vulnerability drama: we've got a cve id today. We're working out on getting the advisory out and get it published

2026-01-15

Yesterday my team member and I disclosed our first vulnerability for 2026. It's in a VERY well known kubernetes infrastructure, an open source project. In an unsurprising turn of events (they did the exact thing to us a year ago) they immediately rejected the issue being a security vulnerability and categorized it as a bug, they've already pushed a PR with a fix. I explained that this was a security vulnerability and not just a bug, since you can bypass their entire solution in a stealthy way by injecting malicious, unsanitized user controlled strings. In their book this isn't a vulnerability, which it obviously is. I've reached out to mitre this morning to get a CVE id

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst