Tanto Security is a leading provider of advanced offensive cyber security services to leading organisations across Australia, New Zealand and North America.
Our brilliant and talented Sam picked up a 4G industrial router from a second hand store, and as they say in the biz, what he found will shock you.
Check out the blow-by-blow as he wound up logged in to a "fake" root account. Full dets over on the blog: https://t.co/nENmrqb1C9
π₯βππππͺ π₯π ππ£πππ π₯ππ π€π₯πππ πππ π‘π¨π π₯ππ ππππ‘?
Corelan Stack (Feb 3-6) + Heap (Feb 9-12) in Melbourne π¦πΊ β the ultimate exploit dev combo, back to back π₯
Do both = earn your shot at CCED π
Seats π https://t.co/DckcMarpVWΒ
π Sharing = caring
Are you going to be in or around Wellington on the 7th-8th November? Are you a student or currently unwaged? TantoSec wants to get you to Kawaiiconβ€οΈ
We have tickets to give away. They cover entry to the con only. Travel & accom aren't included. Send us a DM if you can make itπ
π¨BBOT Security Advisoryπ¨
4 fresh CVEs (2 CRITICAL RCE) can give a clever defender RCE on your attack box if youβre on BBOT <2.7.0.
Hat tip to @justinsteven of @TantoSecurity for the catch. π
Details πBLS Blog https://t.co/mo9BO00gyB
#infosec#CVE
@BSidesCbr is just around the corner and we've got six talks booked in. Starting tomorrow with CrestCon then 5 spots at BSides from Thursday to Saturday. If you are coming along come say hi and we'll have stickers and t-shirts to give away!
We think @DownUnderCTF does incredible work, and Tanto Security is proud to have been a sponsor since 2023. Thank you friends for letting us pentest your new scoreboard, and we'll see you for DownUnderCTF 7 in 2026 π«‘
Tanto Security β€οΈ @DownUnderCTF - and when they asked us if we could do a pentest of their new brand new CTF scoreboard we knew we had to say yes.
With their permission we are proud to release the full pentest report today! π
@DownUnderCTF have published their annual infra writeup at https://t.co/LEmHDa7Kc6 and today's an extra special day, because they're open sourcing their scoreboard, noCTF! π we think it's pretty dang good (and probably pretty secure)
πππ ππ€οΈππ
Training Alert!
We are partnering with @corelanc0d3r to bring his amazing exploit dev workshop to Melbourne for the first time. Want to take your exploit dev to the next level? Check out https://t.co/MUYhX0W98C Early Bird Discounts if you get in before October 1
A big thank you to Silver sponsor & long-time friend, @TantoSecurity.
Theyβre back for their third year supporting BSides Canberra and the community, and have also contributed accepted talks to this yearβs conference.
More at: https://t.co/9Cetsvf4i1
Our Technical Director and co-founder @marcioalm will be at the Melbourne AppSec & DevSecOps Summit next week! He'll be pondering the changing nature of software assurance alongside @jksdua and friends of TantoSec @volvent and @pamoshea
He ends up delivering a perfectly spoofed email, indistinguishable from one that would have been sent from within the victim organisation. Some of the tricks have been patched π₯³ some tricks haven't π so grab a cup of tea and get busy reading π
https://t.co/X76yKr5Vyk
It's blog post day! π Our email whisperer Ben Wilson has distilled his Outlook email spoofing journey from @BSidesCbr 2024 into a terrific post, walking you through the process of exploring niche email tricks that bypass anti-spoofing controls π
"Navigating Bug Bounties: From NAs to P1s"
Animesh Acharya shares the real story behind the stats, the quiet lessons between frustration and breakthrough. For anyone stuck, starting out, or seeking practical tips to level up their bug bounty game.
https://t.co/Ej8sUtStfl