The Hacking APIs Conference is back for 2026!
HAC NYC returns May 14th. CFP is open.
Got a live API hack? A breach case study? Research that made a security team sweat? Submit it.
Vulnerabilities that shipped. Exploits that worked. Defenses that held.
Today we are releasing a 1 page version of “Hacking Your Career”
https://t.co/Ca8AUDayJ9
We get a bunch of students and early career-seekers looking for resources and advice of getting their 1st gig.
This resource gives all those and more; free trainings, free certificates for your résumé, advice on résumé design, information on career verticals, small sections on interviewing and the hiring process, and more! 🫶🫶
Hermes now has first-class support in Omarchy, @DHH’s Arch-based agentic Linux distribution.
Install the desktop app from the AI menu, or make Hermes your default terminal agent. Your Omarchy theme sets the colors in the desktop app, the TUI and the CLI.
https://t.co/mFClENLA62
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). https://t.co/Ll3axMWy9T
Cyber is having a moment
Across 21 major software companies, including Apple, AWS, Microsoft, and Google:
- Reported critical vulnerabilities never cleared 100 per month in four years
- Since spring they've jumped to over 600 per month
Charts of the Week: https://t.co/4dgNGwG5Nx
APIsec|Con is back! This round we are focusing on the future of appsec in the age of AI.
Oct 21, 12 to 4 PM ET. Four hours, no vendor pitches.
Did your agent escape its sandbox and hack your neighbor?
Did your MCP server hand an attacker a valid token because a tool description told it to?
Did a model-written endpoint ship with BOLA and pass every test your other model wrote?
We want to hear from you!
The Call For Papers is open!
If you're looking for some more advanced reading, @garethheyes figured out how to use CSS in emails to steal passwords. This is what platinum tier security research looks like.
https://t.co/85qHdj5dR4
Cybersecurity depends on people whose work is rarely recognized. The innovators and builders of open source tools. The defenders and incident responders. The mentors.
As a Difference Makers Awards Advisory Board member, I invite you to submit your nomination and recognize the exceptional work across the security community.
Nominations are open now through September 14.
Nominate your Difference Maker here: https://t.co/DyvQfvhyQx
The new attack surface is AI.
- AI enabled web-app and APIs
- AI enabled infrastructure
- Employees using AI harnesses
- Organizations turning on AI productivity features
Attacking AI is a one of a kind course that teaches methodology to assess each one of these scenarios. Join us for the next cohort!
https://t.co/IYAgKSQiWV
A must read for anyone in Appsec! @HackWitHerr Bandana Kaur at @apisec_ai just released the most in-depth BOLA research, I've seen in years. The reality of BOLA findings does not match the reality of API testing.
BOLA shows no meaningful decline from 2023 to 2026, a time where the most awareness of the problem peaked. So, the gap isn't knowledge, it's testing techniques and remediation.
Check it out:
https://t.co/cmjePG5T2s
Learn OSINT with a free investigation platform, practical OSINT training, and real workflows for validating data, cross-referencing evidence, and building stronger investigative skills.
https://t.co/uX1hnF7kvP
Thank you to Maltego for sponsoring this video!
#osint#maltego #digitalinvestigations
A huge thank you to @cybersafehq for creating this opportunity.
A very big thank you to @apisecu for supporting and providing the voucher for this exam.
And to @danbarahona and @hAPI_hacker, thank you for your continuous support and contribution to the API Security community.
Heads up for anyone heading to São Paulo this September. I'm keynoting Mind The Sec 2026.
The talk: GOOD vs. REvil, Inside the Mind of the Kaseya Attacker. I know better than to talk ⚽ with a Brazilian crowd, so I'll stick to ransomware. Kaseya hit thousands in one afternoon, and I got intel straight from the person behind it, plus what really happened inside REvil from the human side.
Sept 15 to 17. Details: https://t.co/u0YIwU2TW2 @MindTheSec #mindthesec2026
Introducing Bot Mode for Hermes Desktop.
Your agent profiles become a series of named Bots. Each Bot has its own role, model, memory, skills and profile picture; Bots can use any model and even communicate with each other.
Build a specialist Bot once to use it forever.