If you're around Bergamo 🇮🇹 this weekend, join numerous members of the Doyensec team for @BITM_HACKLAB's 🚫🎩No Hat 🚫🎩conference! DM us if you want to chat (fun/tech/work/jobs) or just to have an espresso!
https://t.co/kTGngjQXap
#doyensec#appsec#nohat#security
Our idea of a team🍕 party? A Mediterranean cruise ⛴️from Rome to the world 🍕 capital, Naples 🇮🇹! Plus dancing in Mykonos 🕺💃, the views in Santorini 🇬🇷 and the ruins in Ephesus 🇹🇷 . We also hacked 👨💻 , played 🏀 ⚽️ & relaxed🧘 💆♂️. Can't wait for our next retreat!
#doyensec
Next up from @owasp's Global AppSec is our @maxenceschmitt. His talk shows how CSRF can still be found in modern applications which utilize typical defensive mechanisms, by leveraging Client-Side Path Traversal!
https://t.co/WxwfchpcSh
#doyensec#appsec#cspt2csrf#owasp
Missed @owasp's Global AppSec? Check out our talks online now!
First up, our @viktorot Dives into race conditions and how they impact your AppSec:
https://t.co/IkWGiHaYI7
#doyensec#appsec#owasp
We're proud our testing helps ensure the security of @ThinkstCanary's OSS Canary Tokens! As part of their transparency efforts, you can read the results of our latest round of testing here:
https://t.co/JlzxQ6uEOO
#doyensec#appsec#security#thinkst
Our latest blog post from @a_denkiewicz discloses an unpatched local privilege escalation vulnerability, impacting Windows 11. Learn how Custom Actions can be leveraged to exploit the Windows Installer Service!
https://t.co/qzyAK81Fnm
#doyensec#appsec#security
Just posted! Check out our @viktorot's presentation on DB race conditions from @owasp's Global AppSec. Our latest post gives all the details, slides and a playground to test your skills at finding these issues!
https://t.co/DaZLAoFqfK
#doyensec#appsec#owasp#security
CSRF in modern web apps? It's still possible! Our latest research by @maxenceschmitt dives into using Client-Side Path Traversal to perform CSRF. Check out our latest blogpost and brand new #Burp extension for finding bugs.
#doyensec#appsec#CSPT2CSRF
https://t.co/9XUicACBRI
Does it make sense to stake your organization's security on a crowdsourced model? Our latest post contrasts the pros and cons of product security audits versus bug bounty programs.
#doyensec#appsec#security
https://t.co/axLcrBGe9O
We're happy to announce that we're an official sponsor of @BSidesSF ! Come join us at this great conference in San Francisco, 05/04-05/05! See you there!
#bsidesf#bsides#doyensec#appsec#security
https://t.co/GdJLBMa9vF
We've officially partnered w/ @Google to review plugin submissions for the #Tsunami network (and now #AI) scanner! As part of their Patch Rewards program, it rewards people for contributions. Check out the details and contribute soon! #Doyensec#AppSec
https://t.co/RIQP9k0EJS
Always glad to hear such great reviews from one of our clients! Doyensec aims to be a trusted advisor for all aspects of @goteleport & all our clients' AppSec needs. Contact us today to see how we can help.
https://t.co/chdkfbKoMz
#doyensec#appsec#security#observa#teleport
New blog post on our new Server Side Prototype Pollution Gadgets Scanner plugin for #BurpSuite! It features a modern detection approach and a focus on real-world exploitation. Download it today!
https://t.co/qG3I3G6b9y
https://t.co/N2DJK05Ywz
#Doyensec#AppSec#websecurity
PoIEx, a new #Doyensec tool, identifies "Points of Intersection" where code & IaC definitions meet. Visualize & explore IaC, plus create & share real-time notes w/ teammates in VS Code. Try it out today‼️
https://t.co/Z0ekdlATFQ
https://t.co/rBqOlBUEjU
#CloudSecurity#appsec
Learn more about how having a security-oriented scheduling strategy for #k8s can limit opportunities for lateral movement within your environment in our latest blog post.
#doyensec#Kubernetes#security#appsec
https://t.co/B6ou4SaeL8