Sometimes a stupid idea get stuck in your head. And will not disappear after a while.
Anyway, here is a new blogpost, just a little hoax this time.
https://t.co/rLQOdom7GS
incredibly excited to share that my research 'Playing with HTTP/2 CONNECT' made the final @PortSwigger Top 10 Web Hacking Techniques of 2025!
A huge thank you to everyone who voted. It’s a privilege to be featured alongside such talented researchers.
https://t.co/JNIq91CclQ
👼GatewayToHeaven (CVE-2025-13292).
I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users).
Below is the full breakdown of the exploit chain⛓️
You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post by @0xor_solo about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 https://t.co/qTobSqOjrY
Honored to be nominated for the @PortSwigger Top 10 Web Hacking Techniques 2025 with my research "Playing with HTTP/2 CONNECT".
Make sure to check out the full list and cast your vote!
https://t.co/O6WjecM8sv
Our 2024 applicants challenge is officially #roasted: the full BeanBeat × Maultaschenfabrikle walkthrough is now online. Unwrap the write-up at https://t.co/FOspfgRmRc and revisit the hacks that escalated from cold brew to full breach.
Latest ≠ Greatest? A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS from our very own @mwulftange who loves converting n-days to 0-days https://t.co/2ev64hf2Ng
CODE WHITE proudly presents #ULMageddon which is our newest applicants challenge at https://t.co/25hlvHXiGW packaged as a metal festival. Have fun 🤘 and #applyIfYouCan
Just out of stealth mode last week, @TeamCyata reports on their "deliberate, weeks-long effort [...] to uncover logic-level vulnerabilities" in HashiCorp Vault and CyberArk Conjur. And uncover they did.
https://t.co/G401swEgwn
https://t.co/r8zpmnW2qJ
New writeup:
Early last month, @samwcyo, @sshell_, and I found a Django ORM injection in an online shooter game that let us steal cryptocurrency from the game's wallet.
Read the blog post here:
https://t.co/YjkIlEPX9q
Here is a really cool blog post by wasamasa whos is a past student of our FSWA class: https://t.co/EUX7B6bNTy. You can find them on Mastodon: https://t.co/FKRWxJ2kWE
"Funky chunks: abusing ambiguous chunk line terminators for request smuggling" - quality research by @__w4ke! Also thankfully it doesn't overlap with my upcoming presentation 😅
https://t.co/FG91EzTdO1
Three unexpected attack scenarios:
1. Marshaling private data with misconfigured tags
2. Parser differentials in a microservices architecture
3. Cross-format confusion attacks (JSON→XML)
https://t.co/2IpN8pvVI0
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM#Ivanti https://t.co/weWtiB72Dv