Imre Rad·Apr 23, 2025GitHub artifact immutability is a lieRecently I’ve been involved in a security incident where an attacker was able to gain control over an unprivileged GitHub Actions job…
Imre Rad·Jul 8, 2024Sneaky write hook: git clone to root on k8s nodeKubernetes supports the concept of volumes (aka storage drivers). This concept makes it possible to extend or facilitate providing data to…
Imre Rad·Feb 16, 2024GitHub Enterprise Server vulnsThis is the follow up of my previous write up titled GitHub Bug bounty experiences: actions and CLI. I kept looking for GitHub…
Imre Rad·Sep 7, 2023Github bug bounty experiences — Actions and CLIGithub bug bounty program has celebrated its 9th birth day recently and I decided to try myself in that space.
Imre Rad·Apr 13, 2023DVB-D (DVB over DLNA)Disclaimer: the project I’m outlining here, is highly experimental —kind of a PoC. Also, DVB-D is not a consortium standard for broadcast…
Imre Rad·Mar 25, 2022Clipboard hazard with Google SheetsThis is an advisory about an interesting attack vector against Google Sheets that abuses embedded Sheets documents to exfiltrate content…
Imre Rad·Oct 18, 2021The Speckle Umbrella story — part 2Back then in January, I reported a vulnerability to Google that let me spawn a remote shell on Cloud SQL instances, both MySQL and…
Imre Rad·Sep 1, 2021Google Cloud Build — under the hoodThis story began shortly after I published an advisory about a DHCP related flaw that affected Google’s Compute Engine. Dávid Schütz…
Imre Rad·Aug 24, 2021The Nomulus riftIn the middle of 2020, I decided to look for vulnerabilities in some open source products of Google. They have many such projects, a public…