Six months ago we discovered an Authentication Bypass Vulnerabiity in the @auth0 platform. After working with them, today, we can disclose the full details. Read our blog post here: https://t.co/Kf0tV6bGXy
Nos fuimos unos días a vivir la primer edición de @ekoparty Miami junto a @BugBountyArg y documenté todo en un VLOG. Espero que les guste :)
https://t.co/xWQu2qONEJ
Just successfully exploited my first web race condition using the techniques described by @albino_wax in Smashing the State Machine. With a bit of AI, I identified a race in an authorization check where shared state between concurrent requests could be overwritten by a higher-privileged user. By triggering the race condition during authorization validation, I was able to bypass access controls and retrieve data belonging to users from other organizations.
A great reminder that sometimes the bug isn't in the authorization logic itself, but in when that logic executes. Thanks @albinowax for the excellent research and methodology.
I know it is really hard to understand how much better and improved the proxmark3 has become over the years.
Here is a graphic list of the following card technologies that is currently supported in #proxmark.
Meet the Burp Ambassadors: @soyelmago 🇦🇷
Alan Levy is a Buenos Aires-based security consultant, content creator, and founder of @BugBountyArg.
He’s also behind LATAM’s first online bug bounty conference: BountyMagicCon.
#BurpAmbassador#BurpSuite
Everything in the Proxmark3 Iceman firmware.
Every iCLASS, SEOS, Mifare, UL-AES, FeliCa update.
Every late night debugging session.
None of it is sponsored. All of it is open source.
If it has saved you time or taught you something, consider buying me a coffee.
Patreon this week: promo code 82409 for a discount.
https://t.co/jNaIDBOAHd
#Proxmark3 #RFID #OpenSource #InfoSec
The math on this collection should mass-humble every streaming service on the planet.
One guy. A Sony cassette recorder. 10,000 concerts over 40 years. 30,000 individual sets from 3,000+ artists. R.E.M., The Cure, Nirvana, Björk, Depeche Mode, Sonic Youth, Phish, Tracy Chapman, Boogie Down Productions.
His first recording of Nirvana was July 8, 1989 at a tiny club called Dreamerz. Kurt Cobain was 20 years old. The band introduced themselves by saying they were from Seattle. This was two full years before Nevermind existed. That tape is now cleaned up and streaming for free.
The digitization operation alone is wild. One volunteer drives to Jacobs' house monthly, picks up 10-20 boxes of 50-100 tapes each, runs them through 10 simultaneous cassette decks he repaired himself. 5,500 tapes digitized since late 2024. Dozens more volunteers across the US and Europe do mastering, metadata, and setlist verification. Sometimes they contact the actual artists to confirm what songs were played.
The collection went from 171 recordings in January 2025 to over 2,300 by April 2026. At this rate it'll take years to upload everything.
Spotify has 100 million tracks. Apple Music has 100 million. Neither has a recording of Nirvana's first Chicago show. A guy with a tape recorder in his pocket does.
When I started seriously getting into RFID security, the information landscape was a mess.
Forum threads from 2009 with broken links. Research papers behind paywalls. Knowledge sitting in private Slack channels and IRC rooms that you needed to already know someone to access. The people who knew things weren't being gatekeepers intentionally, the tooling just hadn't created a natural gathering point yet.
Then there was the Proxmark forum, the center of it all for a decade.
Not https, and overrun with spam. Haters flooded it with spam.
That's part of why the Discord server exists.
It's now the largest RFID hacking community online with members from 40+ countries, spanning everyone from published researchers presenting at DEF CON and Black Hat to people who received their first Proxmark3 last week and aren't sure which end to point at the card.
The mix is deliberate. Beginners ask the questions that experts stopped asking years ago. Those questions are often the most interesting ones. "Why does this card respond to `lf search` but not `hf search`?" leads to a surprisingly fun conversation about frequency, modulation, and why the protocol landscape is the way it is.
If you're into RFID, NFC, access control security, or hardware hacking in general, the door is open.
https://t.co/hFdVqHFHBC
#RFID #NFC #CyberSecurity #InfoSec #HardwareSecurity #Community #Proxmark3
https://t.co/WntjngoXW8
https://t.co/3ReVw9sAE4
"iClass is secure"
Sure. Until the firmware was extracted and master keys leaked.
Then: "use iClass SE"
Until the crypto was reversed, tear-off attacks published, and SAM support.
Then: "use SEOS"
Until the SAM got hacked and SAM support landed in Flipper
Every proprietary RFID system follows the same arc.
Obscurity. Breach. Patch. Repeat.
Open standards with real crypto exist.
Nobody wants to replace the hardware.
#iClass #HID #SEOS #RFID #Proxmark3 #PhysicalSecurity
https://t.co/3ReVw9sAE4
https://t.co/J8xCAPVRE1
You can now run a full Linux operating system inside a 6mb PDF.
Someone embedded a RISC-V emulator inside a standard document. You don't need a virtual machine, just a PDF reader.
→ Runs interactively inside the file.
→ Powered by a tiny RISC-V emulator.
→ The entire OS fits in just 6MB.
Cinematic platformers.
Key characteristics are realistic animations, interactions with the environment, harsh consequences and heavy focus on story and atmosphere.
Pioneered by Jordan Mechner with Prince of Persia (Amiga version shown in the video).
Another World and Flashback are also the Amiga versions, Blackthorn is the SNES one, OnEscapee is on Amiga and Oddworld is shown on the PlayStation. Background music is the Flashback main theme (Amiga version).
@PabloSabbatella Podrías, Pablito, compartir más info técnica sobre las “dos huevadas” a las que te referís? Más que nada porque mencionás “la mayoría” y no algún caso aislado. Y me preocupa. Gracias!
Merry Christmas! 🎄✨ All music at https://t.co/ofMIbfTKV7 is now FREE to download 🎁 It’s also DMCA-safe if you want to use it on your Twitch streams 👾🎶 Hope you have a great time! 🎄❤️