We took a Philips Hue Bridge firmware update from encrypted FW2 blob to a working MIPS QEMU lab.
This write-up walks through:
• parsing and decrypting the FW2 firmware format
• rebuilding the extracted root filesystem
• fixing init/startup issues for emulation
• booting bridge services under QEMU with SSH access
Useful if you’re into firmware analysis, embedded Linux, IoT security, or just enjoy making awkward vendor firmware run somewhere it was never meant to.
Full write-up:
https://t.co/amO35LeGPn
An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, and GenAI penetration testing. https://t.co/MFtZngbrJx
LiteLLM has been getting a lot of attention lately, so we took a closer look too, and found two high-severity paths to RCE: Jinja2 SSTI in prompt testing and a Unicode NFKC sandbox bypass in guardrails.
We broke down the root cause, the exploit paths, and why admin-only features still need serious security scrutiny.
Full write-up:
https://t.co/CzeU2xNtEF
🎤 Speaker Spotlight — Meet @Adrian__T at #BSidesBUD2026! 20+ years of pentesting. Co-Founder of FORTBRIDGE. BlueHat IL speaker. 🔥
Talk: "Concrete Evidence: Two Races, One RCE"
Real vulns. Real bypasses. Live breakdown. 👀
#BSidesBUD2026#WebSec#RCE #OffensiveSec#InfoSec
"Ignore all previous instructions and..."
If your AI app follows that, you have a prompt injection problem. And unlike SQL injection, there's no parameterised query equivalent to fix it.
We wrote the guide we wish existed when we started testing LLM applications — covering direct injection, indirect injection via RAG and tool use, jailbreaking techniques, and the defence strategies we actually see working.
Full guide: https://t.co/LHSUa7IUFu
#PromptInjection #LLMSecurity #AIPentesting #OWASP #CyberSecurity
Critical RCE in SGLang AI Framework
Pickle deserialization exploit, no auth, CVSS 9.8
SGLang unresponsive to patches - isolate networks now
https://t.co/BHdLmS3LOZ
#CyberSecurity#AI#RCE
We red-teamed an enterprise LLM web app with @promptfoo - but the 4-step API broke every built-in provider.
So we wrote a custom one from scratch: session mgmt, polling, Burp proxy at socket level for auto token refresh.
Full write-up with code: https://t.co/zIcOqDjqNM
#LLMSecurity #RedTeaming #PenTesting #AIRedTeaming
Many thanks to @Adrian__T for presenting his talk: "Vesta Admin Takeover - Exploiting reduced seed entropy in bash $RANDOM" at our Feb 26th meetup!
The video recording of the talk is now available on the #OWASPLondon YouTube Channel [PLEASE SUBSCRIBE!]
👇
https://t.co/rx2LO3JpGl
Our February event continues with @Adrian__T taking the stage speaking about the VESTA Control Panel Takeover vulnerability.
Watch the live-stream 📺 here:
👇
https://t.co/XcDmC30yVa
Our February Meetup has started and right now we have Mriya Hristova (@mariya_e_h) on stage speaking about North Korean Spies trying to get a job in your organisation!
Watch the live-stream 📺 here:
👇
https://t.co/ROKRej4hgK
The next OWASP London Chapter in-person meetup will take place on February 26th, 2026 kindly hosted by Civo Tech Junction and kindly sponsored by @curityio
Additional raffle prize is kindly sponsored by
@FORTBRIDGE
Register to attend here:
👇
https://t.co/Iu7Km7khfu
> be Sammy Azdoufal, software engineer
> spend $2000 on DJI Romo vacuum
> decide to control it with xbox controller like a chad
> use Claude to reverse engineer the API
> It works because Claude is the GOAT
> just need to grab auth token from their cloud servers
> token works... Claude is unbeaten
> wait why is he authenticated as 7000 devices
> ohno.jpg
> backend trusted any valid token for any device, no ownership verification
> mfw Sammy has live camera feeds from vacuums in 24 countries
> watching some german dude eat cereal at 3am
> can pull SLAM data and get floor plans of everyone's house
> could be the world's most efficient burglar
> could be the world's most at scale pervert
> Sammy just wanted to drive his vacuum bro
> reports it like a responsible adult
> DJI patches in 2 days
> back to being a normal guy with overpriced roomba
> mfw the entire IoT industry treats auth like it's 2005
This is a Claude Code Skill, a refined security knowledge base based on 88,636 real vulnerability cases collected by WooYun from 2010 to 2016.
After installing this Skill, Claude can think about vulnerability issues like a senior security expert. #AiSecurity
https://t.co/tE0dICZ0zb
2025 in review at @FORTBRIDGE
A year of original security research, community, and sharing knowledge - across three continents.
👇 𝗛𝗶𝗴𝗵𝗹𝗶𝗴𝗵𝘁𝘀 𝗳𝗿𝗼𝗺 𝟮𝟬𝟮𝟱
🔬 𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵
This year we published and presented three original research projects , including:
• 𝗙𝗲𝗲𝗹𝗱 𝗱𝗮𝘁𝗶𝗻𝗴 𝗮𝗽𝗽 - critical issues exposing highly sensitive user data
• 𝗩𝗲𝘀𝘁𝗮 𝗔𝗱𝗺𝗶𝗻 𝗧𝗮𝗸𝗲𝗼𝘃𝗲𝗿 - exploiting reduced seed entropy in bash RANDOM to achieve full control panel compromise
• 𝗖𝗼𝗻𝗰𝗿𝗲𝘁𝗲 𝗖𝗠𝗦: Two races, one RCE - two race conditions leading to remote code execution.
Our work on Vesta was also nominated for PortSwigger Top 10 Web Hacking Techniques of 2025, which we’re particularly proud of.
Our work was also covered by @guardian and @TheRegister , helping bring responsible security research into the mainstream.
🌍 𝗖𝗼𝗻𝗳𝗲𝗿𝗲𝗻𝗰𝗲𝘀 & 𝗰𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝘆
We had the chance to present our research across the US, Canada, Europe, and Asia including:
• 𝗘𝘂𝗿𝗼𝗽𝗲: APIDays London, BSides Kent, BSides Bournemouth, BSides Bristol, SteelCon & DotNetSheff (Sheffield), BSides Budapest, BSides Dresden, BSides Galway, Pass the SALT Lille, Owasp Porto
• 𝗡𝗼𝗿𝘁𝗵 𝗔𝗺𝗲𝗿𝗶𝗰𝗮: BSides Calgary, HackMiami, DEF CON 33 (Las Vegas)
• 𝗠𝗶𝗱𝗱𝗹𝗲 𝗘𝗮𝘀𝘁: BlueHat (Tel Aviv)
🎓 𝗚𝗶𝘃𝗶𝗻𝗴 𝗯𝗮𝗰𝗸 & 𝗚𝗿𝗼𝘄𝗶𝗻𝗴 𝘁𝗵𝗲 𝗻𝗲𝘅𝘁 𝗴𝗲𝗻𝗲𝗿𝗮𝘁𝗶𝗼𝗻
We worked with three interns this year, focusing on hands-on offensive security, real-world tooling, and research workflows.
As part of giving back to the community, we also sponsored @BSidesDresden , supporting independent, community-driven security events in Europe.
Thanks to everyone who attended our talks, asked tough questions, reviewed our research, or collaborated with us along the way - and to the organisations who trusted us with responsible disclosure and remediation.
Looking forward to building on this in 2026.
—
FORTBRIDGE
#CyberSecurity #SecurityResearch #InfoSec #PenetrationTesting #APISecurity
Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: https://t.co/gt0bIlqyX5
This year’s @BSidesDresden was an incredible experience, and I’m genuinely grateful we had the chance to be part of it in more ways than one.
@FORTBRIDGE was honored to sponsor and contribute to the event, and it’s been inspiring to support a conference that brings so much value to the cybersecurity community.
A huge thank you to the BSides Dresden team for the flawless organization, the welcoming atmosphere, and the continuous effort to make this event grow year after year. Your work truly shows.
I also want to appreciate and thank all the speakers who shared their research, insights, and real-world experience on stage. I genuinely enjoyed the talks delivered by @Ari_MaccariTA , Evgen Blohm, Georg Ph E Heise, Eva Pleger, Dr. Alexander Noack, Waseem Ajrab, Julian Petersohn, @roinisimi , and Stuart McMurray. Each session brought a unique perspective and sparked meaningful discussions throughout the day.
Beyond the talks, the conversations with everyone I met were a highlight on their own. From hallway discussions to in-depth technical chats and the many questions exchanged, it all reminded me why this community is so strong and collaborative.
Thank you again to the organizers, speakers, and everyone who took the time to connect.
Already looking forward to BSides Dresden 2026!
#Cybersecurity #BSidesDresden
Great to attend the @OWASPLondon Agentic AI Security Summit, marking the official launch of the OWASP Top 10 for Agentic Applications.
This is an important milestone for the security community. Agentic and autonomous AI systems introduce a new class of risks that traditional application security models are not fully equipped to handle, and seeing OWASP address this gap with a community-driven, practitioner-backed framework is a big step forward.
The launch was led by Scott Clinton, John Sotiropoulos, and Keren Katz, and set the tone for an afternoon of strong, practical discussions around:
• The evolving national and global AI security landscape
• Emerging threats and defense strategies for agentic AI and LLM-based systems
• Red teaming and operational testing challenges for modern AI applications
• Policy, compliance, and responsible enterprise adoption
• Cutting-edge research from leading AI security and public-sector institutions
What stood out most was how grounded and actionable the conversations were. This was not theoretical AI hype, but real-world security considerations for teams already building, deploying, and defending AI systems.
A big thank you to the hosts and organizers Keren Katz, John Sotiropoulos, Matthew Hopkins, Venkata Sai Kishore Modalavalasa, and Adam Mobsby for putting together such a strong and timely event, and to everyone involved in the OWASP GenAI Security Project for driving this work forward.
And, as always, thank you to @securestep9 for his continued involvement and for helping make OWASP London events happen.
The OWASP Top 10 for Agentic Applications will likely become a key reference point for securing autonomous and agent-driven architectures.
#OWASP #Cybersecurity #ArtificialIntelligence