20 years ago, I started working on Wapiti almost as an experiment.
Today, it’s still alive, still evolving, and still helping people secure websites around the world.
Two decades of open source, cybersecurity research, bug hunting, late nights, and countless commits.
20 years ago, I started working on Wapiti almost as an experiment.
Today, it’s still alive, still evolving, and still helping people secure websites around the world.
Two decades of open source, cybersecurity research, bug hunting, late nights, and countless commits.
Extremely hot take: it's better now and more alive than ever
In the 90s and 2000s, computer exploitation and malware development was perceived as this ancient dark art, like it was a forbidden knowledge that only a select few, hand chosen by God, could bare witness to.
Hell, some of the old writings from the 80s and 90s, computer nerds would write things like they were some kind of martial arts master or wizard of the dark arts. It was so silly and goofy.
Now in 2025 there are hundreds of websites, educational courses, university lectures, conferences, social media platform nerds, and more, despite exploitation and malware development being significantly more difficult than it was historically.
Every single day I see super cool research. This sort of information flow was unimaginable to me 20 years ago.
The aesthetic has changed though. Not everyone wants to release a zine, distribute it on an IRC server, and wait 6 months for an email response. Technology has improved, the culture has shifted, things have changed. It's way better now.
Fuck dial up btw, I don't miss the slow ass internet, waiting 45 minutes to download a 5mb file
While the #OBS vulnerability made headlines, claims of "millions impacted" are overstated. Due to OBS’s #container isolation & layered #defenses, the actual impact was far more limited. Get more info here. https://t.co/SezfRbKTze
#EndofWindows10 is near! Don't get locked into upgrades you don’t need. #FreeYourPC with #Linux and keep your hardware running with #openSUSE! 💻🐧
🔗 https://t.co/H40KSKIhp8
Hyped for the new version of GOAD with full support for 🏟️Ludus as a provider!
@M4yFly's new interactive builder handles all the setup of GOAD on Ludus for you, just feed it an API key.
Now you can go from fresh installed Debian 12 -> deployed GOAD with 3 commands! 💪
We see RED 😡
With all the new #redteaming scenarios soon arriving on #HackTheBox, you will too! Catering to both beginners and pros, the total 15+ real-world scenarios will help you gain familiarity with attacking #enterprise infrastructures. Learn more: https://t.co/dWXsjmJ1YM
uBlock Origin has been flagged by Google as 'not following best practices' from the Google Chrome web store — sparking concern it may be removed. Internet nerds are moving to Firefox or Brave.
Some are stragglers and are using uBlock Origin Lite on strict mode to combat ads.
Omg … reading this report by
@Horizon3Attack
on PaloAlto‘s Expedition RCE CVE-2024-9464 (and others) seriously shakes any remaining trust in their software. Every chapter feels like a slap in their face.
https://t.co/LOg490bfEL
🚨 Tool Release!
Announcing 4oFour, a command-line utility tool written in Go that helps enumerate technology stacks used by a target based on the unique 404 error pages they generate and that too blazingly fast! ✨
Repo: https://t.co/mBHLeJfSkJ
EvilCUPS dropped on @hackthebox_eu this morning. It's a simple box from @ippsec showcasing the latest CUPS vulnerabilities. Go play it for free! My writeup is up as well.
https://t.co/SbcJOPfRmd