smaury
@smaury.bsky.social
📤 942
📥 321
📝 48
Co-Founder
@shielder.com
CTF Player jbz.team Cliff Jumping Lover (23mt max so far)
reposted by
smaury
Shielder
3 days ago
Happy New Year, Hackers! 🎆 We’re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens.
0
2
1
What's the Bobby Tables equivalent in
#AI
era?
25 days ago
1
2
0
Join us tomorrow to learn more about this cool audit!
add a skeleton here at some point
about 1 month ago
0
0
0
reposted by
smaury
Shielder
about 1 month ago
Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP:
luma.com/ostif-meetup...
add a skeleton here at some point
0
2
4
👋🏿 Hackers! Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge?
@shielder.com
is hiring a Red Teaming Lead to join our crew! More info ⬇️ (share appreciated)
#hiring
#redteaming
romhack.io/job-opportun...
loading . . .
RomHack - Job opportunities
Check for RomHack sponsor's job opportunities
https://romhack.io/job-opportunities/
5 months ago
0
2
3
Working with folks from
@lucasfilm.bsky.social
,
@ilmvfx.bsky.social
, and Apple to secure some of the OSS foundations the movie and entertainment industries rely on was so cool! Big shout-out 📣 to the
@ostifofficial.bsky.social
and ASWF for making this possible.
add a skeleton here at some point
5 months ago
0
4
1
reposted by
smaury
TumpiCon
6 months ago
The TumpiCon experience will start tomorrow! Can't wait to meet y'all in Pinerolo 🏞️ Schedule is out:
tumpicon.org
1
7
2
Woah - thanks Nestlè and
@intigriti.com
!
7 months ago
0
6
0
It's so cool working with the GoogleVRP team - folks over there are amazing. I love the concept of "you report something, then we work together with you to escalate it as much as possible". High bounties are also a nice addendum :)
#BugBounty
#bugbountytips
8 months ago
2
7
0
Romhack is coming up and the CfP is still open! Got novel research you’d love to present in front of an eager audience, with the stunning Roman landscape as your backdrop, and on the same stage where
@jameskettle.com
will deliver the keynote? Submit now!
cfp.romhack.io/romhack-2025/
loading . . .
RomHack Conference 2025
Schedule, talks and talk submissions for RomHack Conference 2025
https://cfp.romhack.io/romhack-2025/
8 months ago
0
2
1
reposted by
smaury
9 months ago
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF,
@thephpf.bsky.social
, and
@quarkslab.bsky.social
with funding provided by
@sovereign.tech
. For the report and further links, check out
ostif.org/php-audit-co...
0
5
3
Is there a way I can wipe this from my brain? Jim Carrey any recommendations?
mobapc.it/prodotto/sha...
9 months ago
0
2
0
reposted by
smaury
TumpiCon
9 months ago
Just published some talks on
tumpicon.org
Wanna join us? Follow the trail 🥾
add a skeleton here at some point
0
6
4
reposted by
smaury
Shielder
9 months ago
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability
@suidpit.bsky.social
exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref:
support.apple.com/en-us/122373
0
9
5
Woah -- more Google Chrome VRP swag in my mailbox today! Wondering how to get some yourself? Find vulnerabilities in Chrome! More info here:
bughunters.google.com/about/rules/...
9 months ago
0
4
1
One of my old Google VRP reports just went public -- check it out if you want to see an example of CEF exploitation.
bughunters.google.com/reports/vrp/...
loading . . .
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
https://bughunters.google.com/reports/vrp/qMhY4nw9i
10 months ago
0
8
1
reposted by
smaury
10 months ago
Our next meetup is a presentation from our friends at X41 D-Sec GmbH. Join us next Wednesday, March 26th, at 14:00 CDT for a presentation and discussion with Markus Vervier and Eric Sesterhenn on their audit of
@mullvad.bsky.social
. We can't wait for this one! RSVP at
lu.ma/wreregye
loading . . .
Security Code Audit of Mullvad VPN · Zoom · Luma
Join us for a presentation and meetup with Markus Vervier and Eric Sesterhenn of X41 D-Sec GmbH around their company's audit of Mullvad VPN. Markus Vervier is…
https://lu.ma/wreregye
0
3
3
reposted by
smaury
Osservatorio Nessuno OdV
10 months ago
We recently analyzed the latest Cellebrite device support matrix published in February 2025. The reality is worrisome. It can be used to unlock most of the mobile devices we use every day. Read our report: (ENG)
osservatorionessuno.org/blog/2025/03...
(ITA)
osservatorionessuno.org/it/blog/2025...
loading . . .
A deep dive into Cellebrite: Android support as of February 2025
A deep dive into Cellebrite: Android support as of February 2025
https://osservatorionessuno.org/blog/2025/03/a-deep-dive-into-cellebrite-android-support-as-of-february-2025/
0
6
8
Swag day -- thanks ChromeVRP and
@amyre.bsky.social
10 months ago
1
7
0
reposted by
smaury
Shielder
10 months ago
In Lausanne for
@1ns0mn1h4ck.bsky.social
? Don’t miss the chance to meet our very own
@not4nhacker.bsky.social
! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
0
7
5
reposted by
smaury
TumpiCon
11 months ago
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!
1
11
8
tmux and chill
10 months ago
1
2
0
🗣️
add a skeleton here at some point
11 months ago
0
2
1
On my way to
@fosdem.bsky.social
! If you are into securing open source code then we should definitely have a chat -- looking forward to meeting y'all!
11 months ago
0
0
0
reposted by
smaury
Gareth Heyes
11 months ago
Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique.
portswigger.net/research/byp...
0
39
22
reposted by
smaury
Shielder
12 months ago
🚨 New Open Source Audit Alert! 🚨 Shielder, with
@ostifofficial.bsky.social
&
@cncf.io
, audited karmada-io: 🔍 6 issues found (1 high, 1 medium, 2 low, 2 info) ✔️ Most fixed, others planned. 🗣️ to
@suidpit.bsky.social
and
@thezero.org
Full details in the blog post!
www.shielder.com/blog/2025/01...
loading . . .
Shielder - Karmada Security Audit
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
https://www.shielder.com/blog/2025/01/karmada-security-audit/
0
6
7
Love when we can publish the results of our effort!
add a skeleton here at some point
12 months ago
0
2
0
reposted by
smaury
TumpiCon
12 months ago
The second edition of TumpiCon is here! 📅 June 27-28, 2025 📍 Somewhere near Turin, Italy 🔒 Invite-only No flashy stages. No fluff. Just raw, technical, and unfiltered hacking. More details? If you know, you know. Follow the trail:
tumpicon.org
1
6
8
Looking for a chill, invite-only, and uncensored conference? Then you are in the right place :)
add a skeleton here at some point
12 months ago
0
3
0
reposted by
smaury
Mastering Burp Suite
about 1 year ago
Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍
0
20
8
reposted by
smaury
Freddy
about 1 year ago
I have discount codes for *annuals plans* of Mozilla VPN, Firefox Relay Premium Email Masking and Monitor Plus (US only). Message me in private. Happy to hook you up, if we know each other :)
#ad
0
1
1
reposted by
smaury
Jorian
about 1 year ago
Have you tried my december XSS challenge? The solution's public now in this writeup! It includes two vulnerabilities in CodeIgniter that abuse the cache storage format and bypass its builtin XSS filter. Merry Christmas! 🎄
add a skeleton here at some point
0
5
1
reposted by
smaury
Johan Carlsson
about 1 year ago
⚠️Challenge time again⚠️ It is based on a real-world situation. Use the HTML injection to leak the flag to an external domain ☃️ This time, send solutions in DM; we don't want to spoil the fun. I also might want to patch any obvious blunder I made creating it
joaxcar.com/xss/outer.ht...
2
18
5
reposted by
smaury
Gareth Heyes
about 1 year ago
TIL: Array.fromAsync([1],alert)
0
12
5
reposted by
smaury
renniepak
about 1 year ago
Some cool new additions on
cspbypass.com
for skype.[com] and x.[com]/ twitter.[com]
loading . . .
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
https://cspbypass.com
0
14
2
reposted by
smaury
s1r1us | Mohan Sri Rama Krishna Pedhapati
about 1 year ago
Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earned a $5,000 bounty for it. Here's the story and a beginner-friendly deep dive into V8 exploit development. watch:
youtu.be/R3SE4VKj678?...
loading . . .
Hacking Discord for $5000 Bounty
YouTube video by Mrgavyadha
https://youtu.be/R3SE4VKj678?si=Ab1haaEemxiWM1Oz
1
18
9
reposted by
smaury
Matthew Green
about 1 year ago
You wake up. It’s 2013. Some language platform has chosen to use an insecure algorithm for its random() function, and HN is blaming the numerous security flaws that resulted from this decision on individual software developers.
www.zellic.io/blog/proton-...
loading . . .
Far From Random: Three Mistakes From Dart/Flutter's Weak PRNG | Zellic — Research
A look into how an unexpectedly weak PRNG in Dart led to Zellic's discovery of multiple vulnerabilities
https://www.zellic.io/blog/proton-dart-flutter-csprng-prng/
2
38
8
reposted by
smaury
about 1 year ago
Our 2024 collaboration report with the
@cncf.io
is available to read at
ostif.org/2024-cncf-os...
! Learn about our ongoing work managing security audits for CNCF projects, dive into specifics about Notary's second OSTIF audit, and see how funding is spent to improve security.
loading . . .
2024 CNCF/OSTIF Independent Security Audit Impact Report – OSTIF.org
https://ostif.org/2024-cncf-ostif-impactreport/
0
1
1
reposted by
smaury
daniel:// stenberg://
about 1 year ago
Welcome to
#curl
8.11.1
daniel.haxx.se/blog/2024/12...
loading . . .
curl 8.11.1
Welcome to another curl release. This time we do a bugfix only release, five weeks since the previous version shipped. Release Presentation https://www.youtube.com/watch?v=9SgOsDr4KDE Numbers the 263r...
https://daniel.haxx.se/blog/2024/12/11/curl-8-11-1/
0
13
1
reposted by
smaury
shubs
about 1 year ago
This is really great research by
@ryotak.net
- I appreciated that he covered some of his experiments along the way, and how he landed on a finely tuned way of finding a 12-char hash collision with a command injection payload at the end.
flatt.tech/research/pos...
loading . . .
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/
1
18
5
Awesome research! It's always crazy how many vulnerabilities you can still find by just reading RFCs 🔥
add a skeleton here at some point
about 1 year ago
0
7
2
reposted by
smaury
Gareth Heyes
about 1 year ago
Sweeet a unicode table is now in Shazzer!
shazzer.co.uk/unicode-tabl...
loading . . .
Shazzer - Shared online fuzzing
An app to enable to fuzz all sorts of browser behaviour. Share your fuzz results with the world and discover new bugs!
https://shazzer.co.uk/unicode-table?defaultFromTo=0-128
0
9
2
Wow -
@nastystereo.com
Is on fire! Are you doing some kind of infosec advent calendar in your blog? It's amazing to see such great content each day! 🔥
about 1 year ago
1
4
0
reposted by
smaury
Luke Jahnke
about 1 year ago
My latest blog post is live 🔥 Read it to learn what SafeMarshal is and *two* very different ways to escape and get RCE! Read it to find out why Date is *not* a safe class in Ruby or how to leverage serialized strings being constructed with string concatenation!
nastystereo.com/security/rub...
1
20
8
0xbro.red/writeups/web...
loading . . .
Pentesting Salesforce Communities
This blog post shows a recent penetration test I performed for some customers’ Salesforce applications (also called Salesforce Communities), in which I exploited some common and other lesser-known fla...
https://0xbro.red/writeups/web-hacking/salesforce-hacking/
about 1 year ago
0
9
3
reposted by
smaury
Luke Jahnke
about 1 year ago
New blog post is up! Shiny Vulnerabilities in R's Most Popular Web Framework
nastystereo.com/security/r-s...
Turns out the programming language R is used for more than statistics, including web apps!
2
12
2
reposted by
smaury
about 1 year ago
Knock knock! Anybody home? We're pumped to be on (yet another) social media platform. Follow us for
#opensource
security, meetups, and opportunities to get involved with the Open Source Technology Improvement Fund!
0
4
1
reposted by
smaury
Alex Plaskett
about 1 year ago
2
37
12
reposted by
smaury
PentesterLab
about 1 year ago
Encoding isn't magic ✨: It doesn’t bypass filters or hack systems unless something decodes it. Learn how to avoid this common security misconception:
pentesterlab.com/blog/encodin...
#AppSec
#CyberSecurity
#BugBounty
loading . . .
PentesterLab Blog: Encoding Is Not Magic
When talking with aspiring hackers, bug bounty hunters, or application security engineers, it often feels that there’s some misunderstanding around encoding. ...
https://pentesterlab.com/blog/encoding_is_not_magic
1
9
4
Load more
feeds!
log in