The Hacking APIs Conference is back for 2026!
HAC NYC returns May 14th. CFP is open.
Got a live API hack? A breach case study? Research that made a security team sweat? Submit it.
Vulnerabilities that shipped. Exploits that worked. Defenses that held.
Who's going to be there?!?! Who's coming to the booth? See some cool shit that's never been done before and get free hugs (if you want a hug). Hugs must have two approvers in order for the merge request to succeed.
#BinaryDefense
Hacker Summer Camp is here, well it arrived yesterday but ignore the lateness, here is all the talks I'm going to be doing this year, should you be interested in checking them out!
Gotta catch ‘em all! Come find me or swing by the Semgrep Booth today to collect the first of the Semgrep Threat Dex stickers, 22 designs, each represents the last year in cyber security, from CISA and CVEs to Shai Hulud, new designs every day 🔥
If you want to learn:
1️⃣ XSS
↪️ SSRF
🤔 OWASP
🪟 DOM XSS
🔐 Auth bypass
💉 SQL injection
📁 File upload vulns
📦 GraphQL Hacking
🧰 Burp Suite Mastery
🧠 Business Logic Flaws
💔 Broken Access Control
🏴☠️ Real Exploit Techniques
💥 Much, much, much, more
I hope you found us!
I will be signing and giving away of my book Alice and Bob Learn Secure Coding at the ESET booth #4917 in the Black Hat Expo hall August 5, 3:00-4:00 pm and August 6, 2:00-3:00 pm! Come hang out with me and the ESET team!
PLUS Cybersecurity Trivia Showdown and The Great Escape: Cyber Challenge
The first official Hermes Desktop plugin is Kanban, now desktop native by popular request and significantly upgraded.
A plugin can add its own page, sidebar row, hotkeys, status bar actions, and backend endpoints. You can write your own plugin or import one using the SDK.
After 20 years chasing ransomware gangs for other people and organizations, I'm finally doing it doing it under my own company.
Launching Arkem Cyber today. Not another IOC feed, not another framework, original research on the adversary, built for the humans who have to make the call.
Also, I don't have a graphic designer, so forgive the logo. I made it myself, between getting this thing off the ground.
If you're a security leader who's tired of dashboards that can't answer "so what do we do about it?", let's talk: https://t.co/isJZYiCnBa
#ThreatIntelligence #Ransomware #CyberSecurity
Introducing Burp AT.
Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills.
Now live in public beta for Burp Suite Professional users.
https://t.co/VMWhsBRIDk
"One Request to bring the whole realm to ruin." @hAPI_hacker's API security talk has main-character energy and a single request that reads anything, acts as anyone, and claims admin powers. Come find the one API call that rules them all. 👑
This week's Unsupervised Learning (NO. 537) is out.
🤗 The Hugging Face breach, run by an AI agent swarm
🇨🇳 Kimi K3 as a threat to the US economy
🛠️ 6 AI attack harnesses
🛡️ My 3 ways to thrive after AI
https://t.co/82AYCB1ML0
Best watch out... @arcanuminfosec is coming ...
From now until after @defcon we will be announcing:
- CLASS GIVEAWAYS
- New products
- New open source resources
- SWAG drops for the CON
- and so. much. more.
Check out ai-surface, the latest free tool from @apisec_ai and @apisecu. It maps eight categories of AI attack surface straight from your source code.
Agent frameworks (LangChain, LangGraph, CrewAI, and 13 more), with tool inventories and flags on financial, destructive, and high-blast-radius authority. MCP servers, discovered and audited. Vector stores and RAG across 13 backends, flagging the ingestion paths that make up your poisoning surface. LLM call sites across 13 providers. API endpoints with the object-id segments that need BOLA review. Model gateways, AI infrastructure from Kubernetes to Terraform, and provider keys by name only, values never read.
Deepest today for Python and TypeScript/JavaScript. Runs offline. Nothing leaves your machine.
Seeing the surface is step one. Proving what an attacker can exploit at runtime is the harder problem, and that is our work at APIsec.
Repo and install below. If it is useful, give it a ⭐ on GitHub.
pip install apisec-ai-surface
https://t.co/uk6a3BSbA7
YC FOUNDERS i have an offer for you:
you get: free security testing
I get: to write about vulns (once they are patched)
WHY?
This is for a research paper on startup security
comment below and ill dm w more info :)
If you signed up for a career in cybersecurity you signed up for a career of continuous learning. Learning in this field doesn’t end with a cert, a degree, or a job offer, it never ends.
Woo, I can confirm "Can AI Do Novel Security Research? Meet the HTTP Terminator" is coming to @defcon! This research was a huge gamble and the result was glorious, can't wait to share!