Our brilliant and talented Sam picked up a 4G industrial router from a second hand store, and as they say in the biz, what he found will shock you.
Check out the blow-by-blow as he wound up logged in to a "fake" root account. Full dets over on the blog: https://t.co/nENmrqb1C9
@justinsteven
hits the main stage today at Kawaiicon. If you can’t be in Wellington the live stream is here: https://t.co/TFD8Upmgol. It’s going to be a lot of fun 🤩
Congratulations to Noah and Jesse for their awesome talk yesterday!
Are you going to be in or around Wellington on the 7th-8th November? Are you a student or currently unwaged? TantoSec wants to get you to Kawaiicon❤️
We have tickets to give away. They cover entry to the con only. Travel & accom aren't included. Send us a DM if you can make it😎
Tanto Security ❤️ @DownUnderCTF - and when they asked us if we could do a pentest of their new brand new CTF scoreboard we knew we had to say yes.
With their permission we are proud to release the full pentest report today! 👇
🚆🚄🚅🚉🛤️🚃🚂
Training Alert!
We are partnering with @corelanc0d3r to bring his amazing exploit dev workshop to Melbourne for the first time. Want to take your exploit dev to the next level? Check out https://t.co/MUYhX0W98C Early Bird Discounts if you get in before October 1
A big thank you to Silver sponsor & long-time friend, @TantoSecurity.
They’re back for their third year supporting BSides Canberra and the community, and have also contributed accepted talks to this year’s conference.
More at: https://t.co/9Cetsvf4i1
Our Technical Director and co-founder @marcioalm will be at the Melbourne AppSec & DevSecOps Summit next week! He'll be pondering the changing nature of software assurance alongside @jksdua and friends of TantoSec @volvent and @pamoshea
It's blog post day! 🎉 Our email whisperer Ben Wilson has distilled his Outlook email spoofing journey from @BSidesCbr 2024 into a terrific post, walking you through the process of exploring niche email tricks that bypass anti-spoofing controls 👇
"Navigating Bug Bounties: From NAs to P1s"
Animesh Acharya shares the real story behind the stats, the quiet lessons between frustration and breakthrough. For anyone stuck, starting out, or seeking practical tips to level up their bug bounty game.
https://t.co/Ej8sUtStfl
🇦🇺 Corelan hits Melbourne for the FIRST time!
💥 Stack Exploit Dev: Feb 3–6, 2026
🧨 Heap Masterclass: Feb 9–12, 2026
🎯 w/ @TantoSecurity
🧠 Real skills. No fluff.
💣 Come prepared.
🕐 Early bird ends Sept 2025
👉 https://t.co/DckcMarpVW
#Corelan#ExploitDev
“What’s the worst that could happen?”
In 2020, @justinsteven registered a legacy S3 bucket once owned by the Linux Vendor Firmware Service.
He ended up between 100,000 Linux machines and their updates.
Catch the full story at BSidesCbr2025 https://t.co/EsMfLZ46M4
Talk Announcement: Sleepless Strings – Template Injection in Insomnia
At BSidesCbr 2025 @marcioalm & @justinsteven will share their discovery of CVE-2025-1087 – a critical template injection in the Insomnia API client leading to remote code execution
https://t.co/aEcmeeM34l
Today we're releasing Sleepless Strings. It's a blog post about a template injection bug in the Insomnia API client that leads to RCE in the latest version with just a few HTTP requests to a malicious server 💥
Some of our team will be up on the Gold Coast this week for the AUSCERT Security Conference. Come say hi and check out Lloyds talk on Friday at 1:45pm. 🏖️🥷