๐ ๏ธ ๐๐ง๐ญ๐ข๐๐๐๐
New secure-by-default library by @msftsecurity that prevents SSRF attacks.
Currently supports .NET and Node.js.
The original "Showstopper!: The breakneck race to create Windows NT and the next generation at Microsoft " from 1994 was one of those books that fundamentally changed how I think about software development.
Reading about Dave Cutler's team building Windows NT from the ground up โ the engineering culture, the technical decisions under pressure, the relentless focus on architecture โ that influenced how I approach development and security.
When I first read it, I was earlier in my security journey. While the book wasn't specifically about security, seeing how they thought about system design from the ground up, the importance of getting the foundation right, that was a lightbulb moment.
This new edition reminds us that great software comes from great engineering culture and disciplined architecture decisions. In security, we talk a lot about "shifting left," but really we're talking about the same thing - getting the fundamentals right from the start.
What book fundamentally changed how you approach your craft?
#ApplicationSecurity #SoftwareEngineering #BookRecommendation #Engineering
Async IO in Python: A Complete Walkthrough โ Real Python
The content titled "Async IO in Python: A Complete Walkthrough" on Real Python likely provides a comprehensive guide on asynโฆ
https://t.co/4guVsTVZ0A #appsec#Python
I've been building the iOS companion to https://t.co/sbPJaXAqjw โ bringing those 3,000+ curated application security resources to your phone.
It's done!
Mobile-first features:
โข Offline access to all articles and tools
โข Interactive topic explorer with 75+ connections
โข Built-in security glossary (48 terms)
โข Browse by 25+ topics (XSS, SQLi, SSRF, IDOR, RCE, etc.)
โข Background sync for new content
Grab it here - https://t.co/qpDSRUTPpu
I've been building https://t.co/ecDm9BIyZ7 โ a free curated library of application security resources.
2,600+ articles, tools, and writeups across 22 topics (XSS, SQLi, SSRF, IDOR, RCE, and more).
Just added search + 6 new topics. Submissions welcome.
https://t.co/MNWpwG8dBb
I built csp-toolkit to parse and analyze Content Security Policy headers at scale. 21 checks, 79 bypass domains, full CLI + #Python API.
pip install csp-toolkit
Read more at - https://t.co/VmnjzMHzsZ
#infosec#bugbounty#appsec#opensourcesecurity#csp
New post: Use-After-Free vulnerabilities โ what they are, how they're exploited, and how to find them with ASan, libFuzzer, and CodeQL. Includes real CVEs from Chrome and the Linux kernel.
https://t.co/DPwJWou1PB
#appsec#security#memorysafety
New post: CVE-2026-27696 โ SSRF in https://t.co/PFlHAQFAYI via URL validation bypass. Default installs have no auth, and the server will happily fetch your AWS metadata endpoint. Root cause, attack scenario, and the TOCTOU problem most URL validators miss.
https://t.co/7dINtUCOMz
I met @wtm_offensi years ago and so glad to see him getting a spotlight blog post. Heโs a super talented researcher and overall great person to have a convo with. I highly suggest giving the blogpost a read!
โYou donโt pick the bugs. The bugs pick you.โ
Meet Wouter (@wtm_offensi), Microsoft MVR and Zero Day Quest 2026 qualifier, and read his security research journey: https://t.co/f7jIhnNVXQ
Day FOUR of FIVE days of celebrating our 2 year ARCANUM-VERSARY! @arcanuminfosec
5th Giveaway = FOUR seats to our ONE OF A KIND course on using AI to scale you as a Red, Blue, or Purple Teamer:
!! Red Blue Purple AI !!
๐ 1 Like = 1 Entry!
โป๏ธ 1 Share = 2 Entries!
Winners announced 1/21! Syllabus link below ๐
Day TWO of FIVE days of celebrating our 2 year ARCANUM-VERSARY! @arcanuminfosec
3rd Giveaway = FOUR seats to our new course by @the_IDORminator "Zero to [BAC] Hero" !
๐ 1 Like = 1 Entry!
โป๏ธ 1 Share = 2 Entries!
Winners announced 1/21! Syllabus link below ๐
To help celebrate @arcanuminfosec Information Security's two-year anniversary, @Jhaddix gave me 5 codes good for any Arcanum course to give away!
Winners will be announced on 1/22.
๐ 1 Like = 1 Entry!
โป๏ธ 1 Share = 2 Entries!
Any chance of getting a picture with you at AmericaFest, @JesseBWatters? Itโs my wifeโs birthday this weekend and she chose for us all to go to Phoenix for her birthday! Would be a great birthday present. :)