We just made it to @BSidesTampa Unlucky13, and itโs already been great to be here ๐ด๐ดโโ ๏ธ
Even before getting to the venue at @USouthFlorida, you could tell the team put a lot of care into the details; clear parking directions, check-in info, and everything you need to get settled.
The energy is awesome. Around 2,000 people are here, plus what looks like a huge group of volunteers helping keep things moving.
There are also several villages and tracks running in parallel, covering everything from offense and defense to CISO topics, IoT hacking, AI, and more. Plenty to learn, plenty of people to meet, and a really strong community vibe.
Looking forward to catching up with friends and meeting new folks ๐ค
If youโre here and want to connect, shoot us a message.
Enjoy the conference!
The most common LLM security problems usually donโt start with advanced attacks.
They come from production systems that still have prototype assumptions: the model is trusted too much, the tools are scoped too loosely, and the guardrails live in prompts instead of code.
We put together a short post on 5 vulnerabilities that show up repeatedly in LLM deployments:
https://t.co/fEttNGJy0y
๐ @HackSpaceCon 2026 mission accomplished!
We had a great time attending Hack Space Con this year. It was especially interesting to see so many conversations centered around the intersection of cybersecurity and space, along with the latest developments in AI.
With the recent Artemis II launch still fresh in everyoneโs mind, the space and cybersecurity themes felt especially relevant.
We also really enjoyed connecting with security practitioners, researchers, engineers, and newcomers who are just as excited about this space/cyber crossover as we are. ๐งโ๐
And as Space Coast locals, the conference gave us the perfect excuse to revisit the @ExploreSpaceKSC!
Big thanks to the organizers, speakers, sponsors, volunteers and everyone we met along the way.
Already looking forward to the next mission,ย and to @BSidesTampa next Saturday! ๐ดโโ ๏ธ
We wrote a blog post about why it's a bad idea to use domains like https://t.co/8XT6Bvu4Ax and https://t.co/9ViFeudvD4 during testing and in security write-ups.
Even though itโs very common to use them in PoC examples and payloads, they may end up being executed by people validating findings, potentially leaking information to uncontrolled third parties.
To make things worse, these patterns have made their way into LLM training data, and agents are more than happy to reuse them during testing.
Read the full blog post:
https://t.co/KEbeSInILx
#pentesting #aiagents #appsec
AI agents are evolving, but manual pentesting isnโt going away anytime soon.
To cut out the repetitive friction in @Burp_Suite, we built 3 lightweight extensions to sharpen your workflow:
Tab Autonamer: Dynamic naming for Repeater/Intruder tabs.
Find in History: Instant jumps from Search to Proxy entries.
Forward OPTIONS: Auto-skip preflight noise.
Low on flash, high on efficiency. ๐ ๏ธ
Get them on GitHub:๐ https://t.co/ZpZ5nb0OE4
Full breakdown:๐ https://t.co/UbCV5vtCaK
#BugBountyTips #Pentesting #BurpSuite #AppSec #RedTeaming
Weโve just launched our new website: https://t.co/I152J6fMaN
Built to better reflect how we approach security: no checklists, no noiseโjust real-world testing and meaningful results.
Have you ever needed to share a log file, JSON, or configuration file with a colleague, a vendor, or an AI assistantโbut hesitated because of the sensitive data inside? ๐
You need to keep the data structure intact for debugging, but you can't risk exposing PII, API keys, or credentials.
Today, we are releasing https://t.co/6PP9gDCUQb ๐
Itโs an open-source tool designed to sanitize your data before you share it anywhere. It supports formats like HTTP, JSON, XML, and YAML, replacing sensitive information with realistic placeholders.
Most importantly? It runs 100% in your browser. There is no backend processing, so your sensitive data never leaves your device.
Give it a try: https://t.co/JiG9EpPfOv
Check out the repo: https://t.co/uR2fqjKYvF
#infosec #privacy #devtools #opensource
Excited to announce a new release of Security Notes, our tool designed for performing and documenting security source code reviews โ
This version includes numerous improvements, bug fixes, and a major new feature: Breadcrumbs ๐
We designed Breadcrumbs to solve a common challenge: getting lost in the "rabbit hole" of a complex review. This feature allows you to track the implementation of a single function or feature across multiple source files, leaving "crumbs" in code snippets to map your path ๐
We'd love for you to give it a try ๐ค
Your feedback is always welcome! ๐ก
Visual Studio Code Marketplace: https://t.co/CHHYuSLE1J
Github project: https://t.co/WO6AcppZR8
#appsec #bugbountytips #vscode #devsecops
What a week for cybersecurity in the Sunshine State!
We are at @BsidesORL at @FullSail, and the event is just getting started with an awesome crowd.
Looking forward to some great talks and meeting new people. Reach out if you want to connect today or at the upcoming events!
Next stops: @bsidessoflo and @BSidesStPete.
#BSides #InfoSec #Cybersecurity
Be extra careful when using the @defcon open Wi-Fi and submitting credentials over insecure protocols โ ๏ธ
You don't want to get roasted by the Packet Hacking Village on the @wallofsheep ๐
#defcon33
Amazing talk by @albinowax on why 'HTTP/1.1 must die', unveiling new desync attacks and sharing how his research earned over $350K in bug bounties!
#defcon33#AppSec#BugBounty
The @MaritimeVillage is absolutely crushing their debut at #defcon33! They didn't just show up, they brought unmanned vehicles and a full-on Coast Guard rescue boat. What an incredible setup!
In case you are into defense, make sure to visit the @BlueTeamVillage at #DEFCON33! Cool setup and some killer CTFs you donโt want to miss. ๐ก๏ธ
#BlueTeam
@defcon 33 is here! We are excited to reconnect with friends and meet new faces.
Rumor has it: view the billboard through this year's badge color lenses to kick off the challenge! #DEFCON33
Refactor Security turns 3 today!ย ๐
Three years ago, we started Refactor Security with the goal of making security more practical and effective for modern teams. It's been an incredible journey so far, and weโre proud of the progress weโve made together.
None of that happens without our incredible team, our trusted partners, and the friends who supported us from day one. We are grateful for everything we've accomplished together. Thank you ๐
As we step into year four, weโre more energized than ever to keep working hard and to help even more companies build and ship securely.
Letโs keep pushing security forward! ๐