RhinoSecurity Profile Banner
Rhino Security Labs Profile
Rhino Security Labs

@RhinoSecurity

Followers
7K
Following
2K
Statuses
4K

Rhino Security Labs is a top penetration testing and security assessment firm with a focus on cloud (AWS, GCP, Azure), network, and web application pentesting.

Seattle, WA
Joined February 2013
Don't wanna be here? Send us removal request.
@RhinoSecurity
Rhino Security Labs
2 years
New Blog from @RhinoSecurity! IAMActionHunter: Query AWS IAM permission policies with ease
5
5
33
@RhinoSecurity
Rhino Security Labs
10 days
New Rhino Blog Post: CVE-2024-46506: Unauthenticated RCE in NetAlertx
1
2
5
@RhinoSecurity
Rhino Security Labs
11 days
New Rhino Blog Post: CVE-2024-46507: Yeti Platform Server-Side Template Injection (SSTI)
0
5
14
@RhinoSecurity
Rhino Security Labs
1 month
@MrHasanabas just caught this, sorry for the delay. DMd to chat
0
0
1
@RhinoSecurity
Rhino Security Labs
1 month
@tobalotv This research was actually released back in 2017 (we were bit ahead of the curve). Great there's interest in it again!
1
0
1
@RhinoSecurity
Rhino Security Labs
2 months
New Rhino Blog Post: CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’
0
3
9
@RhinoSecurity
Rhino Security Labs
4 months
New Blog Post: CloudGoat: New Scenario and Walkthrough (sns_secrets)
0
27
52
@RhinoSecurity
Rhino Security Labs
5 months
New Blog Post: CloudGoat Official Walkthrough Series: ‘glue_privesc’
1
3
15
@RhinoSecurity
Rhino Security Labs
5 months
Cloudgoat: We've created scenario guidelines and example template scenario to help the community build new scenarios. Get started today -
0
1
8
@RhinoSecurity
Rhino Security Labs
6 months
New Blog Post: Vestaboard: Exploring Broken Access Controls and Privilege Escalation
0
5
18
@RhinoSecurity
Rhino Security Labs
8 months
Now hiring: Associate Application Pentester Does this sound like you? Now accepting applications!
1
4
10
@RhinoSecurity
Rhino Security Labs
10 months
New Blog Post: CVE-2024-2389: Command Injection Vulnerability In Progress Flowmon
1
19
41
@RhinoSecurity
Rhino Security Labs
10 months
New Blog Post: CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster
0
14
29
@RhinoSecurity
Rhino Security Labs
11 months
New Blog Post: CVE-2024-1212: Unauthenticated Command Injection In Progress Kemp LoadMaster
2
22
66
@RhinoSecurity
Rhino Security Labs
1 year
Big thanks to @dayzerosec for featuring Rhino CVE-2024-23724, Stored XSS in Ghost CMS leading to "Owner" takeover, on their most recent podcast. Day[0] reviews the full vulnerability details and provide expert analysis:
0
0
3
@RhinoSecurity
Rhino Security Labs
1 year
The best way to learn AWS Pentesting is with hands-on practice which is why we created CloudGoat - a free vulnerable by design AWS deployment tool. This video walks you through creating a free tier AWS account and launching the first scenario.
0
22
57
@RhinoSecurity
Rhino Security Labs
1 year
After reviewing 90+ candidates, we have selected Jason Taylor as the winner of our career coaching package! Jason will receive a full resume review, a technical interview, and personalized feedback from our penetration testing team.
0
1
6
@RhinoSecurity
Rhino Security Labs
1 year
New Blog Post: CVE-2024-23724: Ghost CMS Stored XSS Leading to Owner Takeover
0
4
9
@RhinoSecurity
Rhino Security Labs
1 year
Security research is key to quality penetration testing. In 2023 alone, we discovered & responsibly disclosed 12 CVEs. Stay tuned for new research dropping in 2024.
0
0
2
@RhinoSecurity
Rhino Security Labs
1 year
Spring 2024 Career Coaching applications are now closed, with 100+ submissions received! We will review all applications, and the selected candidate will be announced on February 26th.
0
0
1