Found a Medium DoS in Base’s gossip layer by bypassing its flood limiter with invalid-signature blocks.
🏆 Chief Finding in the Base Azul audit competition.
Writeup: https://t.co/PlQb7PuC6M
#Base#Web3Security#BlockchainSecurity
Everyone says to add SSL pinning to your mobile apps. This blog argues on reasons to remove it: https://t.co/I5KceSHEjs
A revoked or renewed cert bricks your app until users force-update, and Frida drops the pin in minutes anyway. The real fix moves the decision server-side.
Follow @8kSec for more practical security content
🌍 Earth Day Giveaway - Learn Mobile or AI Security, On Us
One beautiful planet we all share. Let's patch it together. 🌱
To celebrate Earth Day, we're planting 3 free seats 🌱 in any 8kSec Academy course - winner's choice of the whole forest:
• Practical AI Security: Attacks, Defenses, and Applications
• Practical Mobile Application Exploitation
• Offensive Mobile Reversing and Exploitation
• Offensive iOS Internals
• Offensive Android Internals
Explore the catalog → https://t.co/B8Q31o3o8q
How to enter (zero carbon footprint 🍃):
🌿 Follow us
🌿 Like this post
🌎 Repost to spread the seeds
🌟 Bonus: double your chances!
💬 Comment your favorite place on Earth that you have visited or would like to visit 🌍, and we'll count your entry twice
3 winners sprout on April 27. We’ll DM each winner to select their course.
PimpMyKali is your go-to script for automating the installation, configuration, and optimization of tools in Kali Linux. Whether you're setting up a fresh VM or tuning your existing system, PMK v2.0 streamlines the process, saving you time and eliminating frustrating guesswork.
𝗪𝗵𝗮𝘁’𝘀 𝗡𝗲𝘄 𝗶𝗻 𝘃𝟮.𝟬?
🛠️ Enhanced speed and functionality for faster lookups and installations.
🛠️ New features like speedrun mode to bypass prompts and menus.
🛠️ Added support for modern tools like PlumHound and WaybackRust.
🛠️ Updated installation methods to ensure compatibility with evolving tooling.
🛠️ Improved menu structure with more intuitive options and updated command-line switches.
👉 In case you missed the original announcement, catch up and check out the blog: https://t.co/u4LQPV7zTl
📚 Cybersecurity-Books
Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity positions
📄 Checkout on Github
https://t.co/qYqEX5FHHe
#bugbounty#bugbountytips#bugbountytip#hackerone #bugcrowd #infused #cybersecurity #pentesting #redteam #informationsecurity #securitycipher #technology #coding #code #recon #ai #llm #owasp
New giveaway, this time thanks to @hacker0x01!
We will pick 10 winners to win a 1-month pentesterlab license!
To enter:
1️⃣ Follow us @BugBountyDefcon and @hacker0x01
2️⃣ Like this post ❤️
3️⃣ Retweet this post
The giveaway is open until next Friday (10/25)
Good luck Everyone!