What started as a team of 5 high school students in 2018, is now a top 10 international team with members from all over the world.
1st place: 8 CTFs
Single-digit place: 18 CTFs
Attended on-site finals: 10
Organized CTFs: 3
Wishing you all a Happy and Blessed 2024!
I'll never forget the indescribable joy of capturing my first flag and will cherish for life the brotherhood, the memories and adventures that CTFs gave me. Still surreal that after 8 consecutive years of playing DefCon CTF, I sat out this time. #PwnThyBytes#WreckItRalph@WreckTheLine #Zer0RocketWrecks
🚨BREAKING: AISafe Labs discovered Remote Code Execution on @langfuse with a single OTel trace request.
The flaw in the OpenTelemetry dotted-attribute expansion allowed unauthorized access to LLM traces belonging to other projects and system compromise via prototype pollution💣
AISafe Labs found a 🔥 Stored XSS in Immich's 360° panorama viewer (CVE-2026-35455) 🔥
Any user can upload a panorama with text in it. OCR reads the text, then the viewer renders that text as raw HTML. Attacker JS runs against any victim who views the photo.
More details 👇🧵
As the official launch of AISafe draws near, we’re excited to select up to 4 projects for a free Code Audit 🚀
If you're interested, join the waitlist and drop us an email at [email protected] with your project.
For more information, visit https://t.co/L5NLZe5y5X 👈
We teamed up with @WreckTheLine & @redrocket_ctf and secured 🥇1st place at @LakeCtf! Huge thanks to @polygl0ts for putting together an awesome CTF - it was an incredible experience!🇨🇭🔥
I'm releasing fontleak: a new CSS injection technique to quickly exfiltrate text nodes (and yes, that includes inline scripts).
Works on Chrome/Firefox and Safari*. You can use it to escalate the impact of your HTML injection payloads and to solve CTF challenges.
We’re tossing an extra $10k into the prize pool if this tweet gets 100 retweets or we hit 1k teams signed up for The Remedy CTF.
This could be the biggest web3 CTF yet (Jan. 24–26). Let’s make it real—just hit that retweet button 🔁
Register your team here: https://t.co/HAXEz9oQWn
LakeCTF qualifications are now over!
🥇 @smiley_ctf
🥈 @WreckTheLine
🥉 @dicegangctf
Congratulations to the winners, see you in Lausanne for the finals! 📷