Inspektor Gadget has completed its first security audit. Three vulnerabilities fixed, six hardening recommendations addressed — coordinated by @OSTIFofficial and led by @ShielderSec.
> https://t.co/zM4EN0cl0Y
Well that was a ride! Happy to share that I've been awarded with the OMSE certificate after successfully completing the "Offensive Mobile Security Expert" course and exam by @8kSec .
Thanks to @ShielderSec for this training opportunity and to @8kSec for their top-notch content!
Can a hostile container sneak past your eBPF tracing? Sometimes, yes.
With @OSTIFofficial & @CloudNativeFdn we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…).
Work by @ndaprela & @suidpit👏
🔗 https://t.co/LktKoqX7it
#KubeCon EU starts today and guess what? Our very own @suidpit will be on stage with a panel about the @kubernetesio Security Audit we performed during 2025 with the support of @OSTIFofficial!
🗓️ March 25 - 16:45 CET
📍 Hall 8 | Room F
Attending @1ns0mn1h4ck?
Meet @not4nhacker@Luk3ros and @Sev1rus from our AppSec and Red teams!
They are eager to discuss about breaking complex authentication implementations and relaying all the things to DA!
Love breaking things just to see how they work? 🐛🔨
A @ShielderSec delegation is on the ground at @fosdem, and we're looking for fellow hackers and security researchers.
If you are passionate about securing the Open Source world, we definitely need to talk!
Happy New Year, Hackers! 🎆
We’re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens.
Want to learn more about our approach into auditing complex libraries and writing cool exploits?
Attend @OSTIFofficial's meetup where our very own @Th3Zer0 and @suidpit will talk about the "Security Audit of OpenEXR"
🗓️: Dec 02
🕗: 20:00 CET
RSVP: https://t.co/j3slgeZ4Pq
So, Symantec/Broadcom PAM seems to contain code in PHP, Java, and Perl simultaneously. Guess how many issues are hiding there? @Paupu_95 keeps the tension high, and we still don’t know the answer. This #TheSAS2025 talk is quite thrilling.
Attending #theSAS25? Meet @Paupu_95 for his PAM pwnage talk!
It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss 👀
Attending #TheSAS2025? Don't miss our gangster @Paupu_95 pull off a credential heist, taking down a PAM and going from no info to full infra compromise!
You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo Cavaglià (@Paupu_95) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream"
🏰 His team spent two weeks reverse engineering Broadcom’s CA PAM and found 13 vulnerabilities that lead to complete infrastructure takeover. A malicious actor can decrypt all stored credentials, move laterally to every managed host, and own the company.
More SAS gold (aka agenda): https://t.co/41ZlbIcJa1
👋🏿 Hackers!
Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge? @ShielderSec is hiring a Red Teaming Lead to join our crew!
More info ⬇️ (share appreciated) #hiring#redteaming
https://t.co/l7yi7QpvlZ
🚨 New Open Source Audit Alert! 🚨
Shielder, with @OSTIFofficial & @AcademySwf, audited OpenEXR and MaterialX:
🔍 11 issues found (1 critical, 3 still to be published)
✔️ Most fixed, others planned
🗣️ to @ndaprela@smaury92@suidpit @Th3Zer0
Full details in the blog post ⬇️🧵