Dev: “Can you reproduce this?”
Researcher: “It works on my machine 😅”
Yeah… that’s not a report.
If your vuln report needs a Zoom call to explain it,
you already lost.
How to write a good vuln report (save this):
1. Describe the issue like the reader has zero context
2. Translate technical risk into business risk - who is affected and how badly?
3. Write reproduction steps so precise that anyone on the team can follow them
4. Suggest a fix - reference OWASP, a CVE, or a config change
That’s exactly what Barracks enforces.
Every report is structured, verified, and built to be dev-ready - so it gets fixed, not ignored.
📌 Save this before your next submission.
#Barracks #CyberSecurity #Pentesting
I don't use net banking apps on my phone because the mandatory permissions they ask for make no sense.
Why does a banking app need access to my SMS, phone, contacts, etc., in the name of security, when not seeking invasive device permissions is, in fact, the global benchmark for cybersecurity. This is called the Principle of Least Privilege (PoLP).
“Don't do unto others what you don't want done unto you” has been at the heart of the Zerodha philosophy.
This is exactly why we've built Zerodha the way we have. Kite asks for ZERO permissions on mobile, for instance, and this is one of the big reasons why millions of people trust us. What has enabled us is SEBI's mandatory strong two-factor authentication framework strike the right balance between security and privacy.
We've decided to have a little fun on here and run a giveaway. We are giving away a Steamdeck OLED 1TB model to one lucky individual so that they are ready in time for the release of 'The Odarian Accounts: Blood and Banner'. For you to be entered into the giveaway you must:
1. Like this post.
2. Be following the account.
3. Repost this post.
You must have done all 3 criteria to be eligible for giveaway. It will end on the 9th April 15:00 GMT. The winner will be announced on here. Weare excited to begin this and good luck. 😆🤞
Bad News: Fake ORS Scam is BACK!
When ORSL got exposed they did not fix the product.
They just changed the name into something similar to confuse the public.
It’s shocking that even after so much public outrage & exposing they are continuing to deceive the public.
I request all Indians to unite and support by sharing this across all platforms to make Indians aware about this deception
If we don’t call this out loudly, these brands will keep coming with new names to fool the public again.
#ORS #FoodPharmer #LabelPadhegaIndia
🌍 𝗜𝗻𝘁𝗿𝗼𝗱𝘂𝗰𝗶𝗻𝗴 𝗖𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝘆 𝗗𝗮𝘆𝘀 𝗯𝘆 𝗧𝗵𝗲 𝗦𝗲𝗰𝗢𝗽𝘀 𝗚𝗿𝗼𝘂𝗽 🌍
✨ 𝘓𝘪𝘬𝘦 & 𝘙𝘦𝘴𝘩𝘢𝘳𝘦 𝘵𝘩𝘪𝘴 𝘱𝘰𝘴𝘵 🎁 5 𝘓𝘶𝘤𝘬𝘺 𝘞𝘪𝘯𝘯𝘦𝘳𝘴 𝘸𝘪𝘭𝘭 𝘨𝘦𝘵 𝘢 𝘍𝘙𝘌𝘌 𝘴𝘦𝘢𝘵!
At The SecOps Group, we’ve always believed that cybersecurity skills and opportunities should be within everyone’s reach. That’s why we’re launching 𝗖𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝘆 𝗗𝗮𝘆𝘀, 𝗼𝘂𝗿 𝗯𝗶𝗴𝗴𝗲𝘀𝘁 𝘀𝘁𝗲𝗽 𝘆𝗲𝘁 𝗶𝗻 𝗺𝗮𝗸𝗶𝗻𝗴 𝗼𝗽𝗽𝗼𝗿𝘁𝘂𝗻𝗶𝘁𝗶𝗲𝘀 𝗮𝗰𝗰𝗲𝘀𝘀𝗶𝗯𝗹𝗲 𝗳𝗼𝗿 𝗲𝘃𝗲𝗿𝘆𝗼𝗻𝗲. 🤝
💡 𝗪𝗵𝗮𝘁 𝗶𝘀 𝘁𝗵𝗲 𝗖𝗼𝗺𝗺𝘂𝗻𝗶𝘁𝘆 𝗗𝗮𝘆𝘀 𝗶𝗻𝗶𝘁𝗶𝗮𝘁𝗶𝘃𝗲?
Community Days is a dedicated exam day where the cost is significantly reduced, seats are limited, and participants get a one-time chance to prove their skills. The exams must be taken on the event day itself; they cannot be rescheduled, and no retakes are available. It’s designed to make exams more affordable while keeping the challenge real.
📅 𝗘𝘅𝗮𝗺 𝗗𝗮𝘁𝗲: 𝟮𝟲𝘁𝗵 𝗦𝗲𝗽𝘁𝗲𝗺𝗯𝗲𝗿
Mark your calendars! The FIRST edition of Community Days will take place on 26th September, giving you a one-day window to take your exam at a reduced price.
📝 𝗘𝘅𝗮𝗺𝘀: 𝗖𝗔𝗣𝗲𝗻 & 𝗖𝗔𝗣
Choose from two of our AppSec exams:
📙 Certified AppSec Pentester (CAPen)
Limited to 100 participants only.
Original price - £250
Community days price - £25 onwards
📗 Certified AppSec Practitioner (CAP)
Limited to 200 participants only.
Original price - £100
Community days price - £10 onwards
💰 𝗦𝗮𝗹𝗲 𝗦𝘁𝗮𝗿𝘁𝘀: 𝗠𝗼𝗻𝗱𝗮𝘆 𝟮𝟮𝗻𝗱 𝗦𝗲𝗽𝘁𝗲𝗺𝗯𝗲𝗿
The Community Days sale goes live on Monday, so you’ll have the chance to secure your exam seat early.
This is about creating equal opportunities for everyone to demonstrate their skills, grow, and thrive in cybersecurity. 🌍
🔗 Know more: https://t.co/jOaYjeSVRf
#CommunityDays #TheSecOpsGroup #CyberSecurity #AppSec #Pentesting #CyberSkills #EthicalHacking #SkillGrowth #CyberCommunity #SecurityExams #CyberTalent #InfoSec #AffordableLearning #PentestCertification #CyberOpportunities
Prompt Injection is one of the first attack vectors used to exploit weaknesses or bypass behavior in AI models.
Here is an illustrated thread with 5 different prompt injection techniques 👇
All media channels, digital platforms and individuals are advised to refrain from live coverage or real-time reporting of defence operations and movement of security forces. Disclosure of such sensitive or source-based information may jeopardize operational effectiveness and endanger lives. Past incidents like the #KargilWar, 26/11 attacks, and the #Kandahar hijacking underscore the risks of premature reporting. As per clause 6(1)(p) of the Cable Television Networks (Amendment) Rules, 2021, only periodic briefings by designated officials are permitted during anti-terror operations. All stakeholders are urged to exercise vigilance, sensitivity, and responsibility in coverage, upholding the highest standards in the service of the nation. 🇮🇳
Read more: https://t.co/bHscgUBMEV
#MediaAdvisory #NationalSecurity #MIBIndia #ResponsibleReporting
@rajnathsingh@DefenceMinIndia@SethSanjayMP@HQ_IDS_India@adgpi@indiannavy@IAF_MCC@PIB_India
Are you a Burp Repeater power user? The latest release introduces a new feature called 'Custom actions'. With these you can quickly build your own repeater features. Here's a few samples I made for you:
If you want to override something for a quick check, set an orange conditional breakpoint there and inject the code you want to check.
Here's a very basic demo on how to set them in dev tools.
@win3zz 100%, faced similar thing but because i overlooked the wordlist config, otherwise dirsearch works very well when wordlist and its options are marked appropriately
Hello everyone.
Inviting applications for the most coveted 11th edition of Gurugram police cyber security summer internship.
. 1st June 2024 onwards.
. Timings shall be 10 AM to 1 PM for Cyber Ambassadors program and 2 PM to 5 PM for Cyber Warriors program.
. 30 days course. No fees, No stipend.
. Location : "Cy-Lab", Police station Cyber East, Sector 43, Gurugram.
. Certificate for completion. Limited seats.
. Profiles shall be filtered based on merit and interview.
. Guide/Mentor: Dr. Rakshit Tandon
Apply fast!
Click the link https://t.co/QaLe2PbjQ6 or scan the QR code.
Best wishes
Gurugram police
#GPCSSI2024 @gurgaonpolice@cyberpoliceggm
🚀 Google Recaptcha Solver
A Python script to solve Google reCAPTCHA using the DrissionPage library.
https://t.co/AWfY54mMsW
#cybersecurity#infosec#bugbounty