Skip to main content

Emilio Gallegos

Offensive security researcher and adversarial operator at Bishop Fox specializing in application security and vulnerability research.

Sep 26, 2026

34:54
Did you, did you initially kind of look for some type of chain, like a exploit chain, or is that something that just kind of emerged as you dug deeper?
35:05
Yeah.
35:05
I mean, I, I'm assuming and I'm hoping that pretty much everyone has a different, um, way to tackle a problem when it comes to reverse engineering.
35:16
But in this particular case what happened was that I didn't even wanted to, um, start with the vulnerability itself, um, because again, the, the big news was that there was supposedly active compromises.
35:31
You know, it was happening, it was, um, a done thing.
35:35
So my initial concern was if any of our customers were already impacted, right? Um, and so essentially what I did first was just building a ...
35:46
Well, the, the question that I wanted answered was can I safely check for vulnerability or for the indicators of this vulnerability, uh, within our, uh, customers' attack surfaces without, you know, having to do any sort of exploits or, uh, more of a, an active testing, right? So I just built a, a, a little sort of like probe to sort of tell, um, just how it, it happens, SSH, how it authenticates a user.
37:02
But just from a high level, could you kinda talk about the microtrick attack and, like, how that works?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.