I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇
gmsgadget.com
1/4
24.07.2025 15:31 — 👍 22 🔁 13 💬 1 📌 0
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. “I would say the whole process took about 15-20 minutes,” the hacker said micahflee.com/the-signal-c...
04.05.2025 22:03 — 👍 276 🔁 110 💬 8 📌 15
🚀 Another plugin in the Caido Store!
Introducing "Data Grep" by @bebiksior.
Extract data from requests and responses. Great for building wordlists, finding secrets, or powering your recon.
Check it out: github.com/caido-commun...
24.04.2025 19:37 — 👍 6 🔁 1 💬 0 📌 0
Got sniped into the challenge and ended up doing some cool XSS research :D
11 char XSS with mind-boggling race-conditions.
TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char)
It's shorter than location=name !!
terjanq.me/solutions/jo...
14.12.2024 12:17 — 👍 29 🔁 11 💬 1 📌 1
Environments are something I've wanted for a while now.
30.11.2024 20:08 — 👍 12 🔁 3 💬 0 📌 0
My latest blog post is live! nastystereo.com/security/cro...
Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
27.11.2024 09:10 — 👍 79 🔁 29 💬 3 📌 4
Flatt Security XSS Challenge
Execute alert(origin) on each challenge origins.
Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far
challenge-xss.quiz.flatt.training
21.11.2024 17:58 — 👍 6 🔁 2 💬 0 📌 0
TIL: Some surprising code execution sources in bash
add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsec
21.11.2024 17:16 — 👍 5 🔁 1 💬 0 📌 0
yeah wrote this yrs ago, would not use this as-is 😂
15.11.2024 22:46 — 👍 3 🔁 0 💬 0 📌 0
Author (The Fault in Our Stars, The Anthropocene Reviewed, etc.)
YouTuber (vlogbrothers, Crash Course, etc.)
Football Fan (co-owner of AFC Wimbledon, longtime Liverpool fan)
Opposed to Tuberculosis
Your Jeopardy! pal. Author of 100 PLACES TO SEE AFTER YOU DIE (bit.ly/3kLgJKO) and a bunch of other stuff. OMNIBUS co-founder (patreon.com/omnibusproject).
Fondée en 1974, l'École de technologie supérieure (ÉTS) est spécialisée en ingénierie appliquée. Les ingénieures, ingénieurs, chercheuses et chercheurs qu’elle forme sont reconnus pour leur approche pratique et novatrice inégalée.
Rowing and Sculling for all of us.
Rowing news, interesting articles and snippets that catch our eye from around the world of rowing.
We are British rowers and scullers and are in no way affiliated with USA rowing
Covering life in the future
https://www.theverge.com/subscribe
We are Microsoft's global network of security experts. Follow for security research and threat intelligence. https://aka.ms/threatintelblog
Bot highlighting changes to the New York Times "Top Stories" feed.
original by @j-e-d.bsky.social
Bluesky version by @unchi.org
Source: https://github.com/j-e-d/NYTdiff
Nobody knows politics and policy like we do.
www.politico.com
Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range
Cybersecurity blue team person. Love to discuss urbanism, housing crisis and most "bigger-than-you" modern challenges. YIMBY. Involved with @construisonsmtl.ca, Locomotion.app and @northsec.io
Independent journalist.
Send tips via Signal: 202-510-1268.
Join my newsletter 👇👇👇
kenklippenstein.substack.com
Mom of 2, Host of @briefingwithpsaki.bsky.social Tuesday-Friday at 9pm ET on MSNBC starting May 6.
Democratic Nominee for Mayor of NYC. Assemblymember. Running to make this city affordable. Democratic Socialist. Early Voting: 10/25 - 11/2. Election Day: 11/4. zohranfornyc.com
Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://xbow.com/traces
AI researcher at XBOW. Security, RE, ML. PGP http://keybase.io/moyix/
Bringing you propaganda since 1776.
Proud supporter of child labor and the military industrial complex.
IN OIL WE TRUST
Landscape architect and urban designer in the daytime
Advocate for better bike infrastructure and urban design in Montréal the rest of the time
If we don't agree on a subject let's have a conversation about it
My views are personal , not my employer's
Blog feed for https://dustri.org/b
Also available at https://infosec.exchange/@jvoisin
I run a kill shelter for small dogs 🧡🖤