Simply stated: Give us any kind of app and we'll hack it better than the rest.
Our clients include awesome tech companies in Silicon Valley, NYC, and beyond.
Do you use or exploit WebSockets? Check out our new blog post to see how modern browsers may (or may not) be protecting you from Cross-Site WebSocket Hijacking!
https://t.co/q32elxrwrE
Today our team at IncludeSec is releasing a site to help with key collision concerns. We've known for a while that private keys should not be shared, use this site to ensure they are not! https://t.co/FGQESjIbOR
New research🤩 on old tech👴! Our team's latest blog post demonstrates many ways memory vulnerabilities can occur in your legacy Delphi code despite being described as a "memory safe" language by the NSA.
https://t.co/NV53JVotPQ
It's winter, so hacking space heater IoT devices to completely control their firmware seems like the thing to do! In our latest blog post, you'll see some of the things we do for our IoT/HW clients!!
https://t.co/gul5NuUE9L
Hey folks, for those who like the HTB community we've done a collab contribution of a challenge box (free, no subscription needed), give it a spin if you like to hack the hackers! 🪓 👩💻
https://t.co/2ivQEybp5F
Hint: It's a tough box, check our github and our blog for info.
We're happy to sponsor great learning resources like @OpenSecTraining, the world is awash with a lot of bad training/certs, here's some courses that are solid and open/free!😀
As the year comes to a close, we want to once again thank all of the individual and corporate donors who generously contributed to #OST2's nonprofit mission this year! You help ensure that OST2 will be around for years to come!
https://t.co/tqm7V2lP1h
Platinum Partners:
@TrustedComputin
https://t.co/fsTvr8T4Ac
Gold Sponsors & Windows Security Track sponsor Winsider Seminars & Solutions (@yarden_shafir & @aionescu)
Gold Sponsors:
@3mdeb_com@binarly_io@crowdfense@DarkMentorLLC@NCCGroupplc
Bronze Sponsors:
@cyber5w@IncludeSecurity
And remember that the more Partners and Sponsors we get, the more instructors and classes we can support. So if your company sponsors conferences, you should ask them to sponsor OST2!
@hackaday Thanks for including some of our content @hackaday! Would you mind mentioning the Author/Company in your article? Keep that source credit going😀, thnx! We see you did it on last week's summary.
New blog! Join us as we explore seemingly safe but deceptively tricky ground in Elixir, Python, and the Golang standard library. Well-documented behavior is not always what it appears!
https://t.co/CZ41M6SfWy
Who hacks the hackers? We do!
Our new research on vulns in multiple common C2 frameworks used by netpen and red teams. If you use any of these take a look and patch up.
https://t.co/5lpJS6Mlbx
.@OpenTechFund’s Security Lab partner @IncludeSecurity’s security audit of VPN Generator (software that lets anyone provide a VPN to a small group) revealed that the tool only had 4 “low-risk” issues, 3 of which have already been fixed.
Learn more
https://t.co/lJDiI2UBu6
@kevinriggle this particular punk bar has been the host of many summerc0n after parties and we've spent many thousands there on "networking", the staff loves summercon every year!
Fresh blog post for ya;
We introduce coverage-guided fuzzing as a concept to hunt down bugs faster via modification of the Fuzzilli fuzzer from Google Project Zero.
https://t.co/u8Rzpvgkn8
Check out this @BSidesNYC 0x03 interview by @cybersnacker with Erik Cabetas where he discusses how BSidesNYC is different from the other New York conferences, how he started @IncludeSecurity, and what it's like to consult for #hacker movies.
https://t.co/9PkhwHv7uR
We released our new semgrep rules today. Given the recent news about executive orders from the Whitehouse, we thought it would be important to flag all of the code that doesn't meet federal standards.
Memory Safety is serious stuff today:
https://t.co/STqHYBDk4h
We're happy to support great open/free security training to get more folks into our industry. If you want to learn low-level RE/hacks/OS check out OST2! https://t.co/wRzpwapA3w
We're still seeing a lot of Ruby code out there in the tech world. If we see it we hack it! Latest blog post on advanced Ruby deserialization gadget chains for exploitation of application is up
https://t.co/aZazzSVm7i
It’s here folks, here’s an actually deeper dive into the topic of LLM prompt injection; Much more complete than all the fluff you see out there on the topic today. If you like under-the-hood AI context, this one is for you.
https://t.co/Z5zB6SF6MU