since the @discord block in brazil, i haven't been able to screenshare to my friends. i'm deploying @Mattermost with 10y enterprise license for 5k users.
* mattermost - @Cloudflare tunnel
* rtcd (webrtc) - $5 @OVHcloud
* storage on some s3
i hate the gov. dm me for free access.
Tomorrow, live from Croatia, Pedro will be attending BSides Zadar 2026 to share valuable insights on a crucial and often overlooked topic in web application security: the attack surface in PDF generators!
This talk presents 9 real, security-critical vulnerabilities discovered in these widely-used libraries, from Remote Code Execution via deserialization and template injection, to Local File Read, SSRF, and Denial of Service. More importantly, he'll present a practical 6-step methodology to identify and exploit vulnerabilities in any PDF export feature.
Key Takeaways:
- How to identify which PDF engine an application uses (and why it matters).
- Real exploitation techniques: HTML injection, SSRF bypasses, file oracles, and more.
- A systematic approach to testing PDF generators in your next security engagement.
- Defense strategies: what developers need to do right (and what they keep getting wrong).
Pedro Cruz is an Offensive Security Analyst at Hakai Security, specializing in penetration testing, vulnerability research, and bug hunting.
He holds a degree in Information Security from FATEC Ourinhos and maintains a solid technical background backed by industry-recognized certifications, including OSCP+, CRTO, DCPT, and CHWI.
See you at BSides Zadar!
Author: Pedro Cruz @gankd_
BSides Zadar: @BSidesZadar
Confira a agenda: https://t.co/XM9nrlns9f
Zadar , Croatia - September 11, 2026
I know a lot of people are looking at WESP (Windows Endpoint Security Platform
), I had my AI agent look at it, make it work, and do some fuzzing (no crashes). I don’t have anything exciting, but you might share this with your agent to have a jumpstart: https://t.co/A5xOAcDgJp
@PinkDraconian hey @PinkDraconian, do you think that this extension is safe for daily usage? i don't have the technical skills to test it by myself :,(
https://t.co/rsEXBm2NV6
thanks anyway =D
Hello London 🇬🇧
The Phrack team is here and we left our mark around the city.
If you can find any of these stickers, email us for a chance of getting a physical copy of Phrack 73 delivered to your doorstep.
Send proof to [email protected] and have fun!
If you're at @x33fcon#x33fcon be sure to grab a copy of Paged Out! magazine - we have 500 copies there (wayy more than are on the photo), and we DON'T want to send them back ;)
We are pleased to release tmp.0ut 5 Volume!
Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!!
https://t.co/tZLM50HOc0
@imnotcha0s released a little shellcode utility: assembly ↔ raw opcodes, disassembly, null-byte checking, and Python/C/escaped output in one interface. nothing bloated, just a convenient tool for people who are addicted to ctfs and/or have no social life
https://t.co/JoLU5U0pFu
If any of my past work on #OpenBSD, or my highlight posts here has been helpful to you at all, a small recurring monthly donation would help me pay for pizza, rent, & thinkpads (in that order). 🍕💻