Doyensec's Avatar

Doyensec

@doyensec.bsky.social

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

58 Followers  |  4 Following  |  63 Posts  |  Joined: 19.11.2024  |  1.9351

Latest posts by doyensec.bsky.social on Bluesky

Post image

Weโ€™re super excited to welcome Yassine Bengana to the Doyensec team! ๐ŸŽ‰

Heโ€™s bringing serious AppSec skills and great vibes โ€” canโ€™t wait to see the cool stuff weโ€™ll break (and build) together ๐Ÿ”ฅ

#AppSec #infosec #Doyensec

05.11.2025 19:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

The #Doyensec team is back from another great retreat! This time we toured Ireland ๐Ÿ‡ฎ๐Ÿ‡ช and even met a working ๐Ÿ‘ sheep dog ! What a great chance for our remote team to connect IRL! Also, a big thank you ๐Ÿ™ to our tour guide Antonio!
#security #appsec #remote

30.10.2025 18:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Going to be near Dublin this Wednesday (10/22)? come join #Doyensec for an evening of drinks ( ๐Ÿป/โ˜• ), networking, and great conversations about all things #appsec & #cybersecurity.

RSVP here: docs.google.com/forms/d/1fa4...

#Infosec #Pwn2Own #BSidesDublin #OWASPIreland #security

20.10.2025 14:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SQUID-2025:2 Information Disclosure in Error handling Due to a failure to redact HTTP Authentication credentials Squid is vulnerable to an Information Disclosure attack. __________________________________________________________________ ###...

๐Ÿšจ Just released - details on a serious vulnerability from our Leonardo Giovannini's research! An Information Disclosure allowing a remote attacker to identify security tokens/credentials when #squid is used for load balancing.๐Ÿšจ

#doyensec #appsec #security #vulnerability

github.com/squid-cache/...

17.10.2025 17:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you want, you can also RSVP via email at dublin@doyensec.com

14.10.2025 16:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
People chatting about appsec over drinks

People chatting about appsec over drinks

Live in or passing through #Dublin enroute to #pwn2own ? If you're in #appsec join #doyensec to talk #security over drinks (๐Ÿบ or โ˜•๏ธ) Oct. 22nd! Want to talk about our job openings or upcoming projects, that's great too!

RSVP here: docs.google.com/forms/d/1fa4...

cc: @bsidesdublin.bsky.social

14.10.2025 15:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Post image

In our final ksmbd research post @73696e65.bsky.social provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out!

blog.doyensec.com/2025/10/08/k...

#doyensec #appsec #security

08.10.2025 16:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Paged Out! Deeply technical zine. And it's free.

๐ŸงžYour wish has been granted - the latest @pagedout.bsky.social edition is out! In it, our Szymon Drosdzol takes a quick look at #vibecoding, walking through the creation of an AI agent ๐Ÿค–. Check it out today!

#doyensec #appsec #ai #Security

pagedout.institute

06.10.2025 14:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“ข Our latest blog post shows why VBScriptโ€™s Randomize + Rnd are terrible for cryptographic token generation. See how attackers can easily recover seeds and secrets.
๐Ÿ”— blog.doyensec.com/2025/09/25/y...

#doyensec #appsec #security #crypto

25.09.2025 16:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Incomplete fix for GHSA-p46v-f2x8-qp98 ยท Issue #937 ยท prest/prest This is a followup on GHSA-p46v-f2x8-qp98. I spent some time looking into the mitigations introduced. While some of them perform adequate validation of user-controlled input, there are instances wh...

๐ŸšจSecurity Advisory๐Ÿšจ

Systemic SQL Injection vulnerability in pREST.

Details from our Viktor Chuchurski's bypassing the initial fix were also published:
github.com/prest/prest/...

#Doyensec #AppSec #Security #PostgreSQL #SQLInjection

19.09.2025 14:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Systemic SQL Injection # Summary pREST provides a simple way for users to expose access their database via a REST-full API. The project is implemented using the Go programming language and is designed to expose access t...

๐ŸšจSecurity Advisory๐Ÿšจ

Systemic SQL Injection vulnerability in pREST!

Initial report details published: github.com/prest/prest/...

#Doyensec #AppSec #Security #PostgreSQL #SQLInjection

19.09.2025 14:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

We'd like to welcome our newest addition Marcelino "Marce" Siles Rubia! Another success story from our #internship program! The future of #appsec is looking bright ๐Ÿ˜Ž at #doyensec !

04.09.2025 18:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Person typing on the keyboard with sparks coming from the screen.

Person typing on the keyboard with sparks coming from the screen.

๐Ÿ“ข It's here! Part 2 of Norbert Szetei's (@73696e65.bsky.social) research into ksmbd. See how customized fuzzing & the appropriate sanitizers led to discovering 23 Linux kernel CVEs, including use-after-frees & out-of-bounds reads/writes.

blog.doyensec.com/2025/09/02/k...
#doyensec #appsec #security

02.09.2025 19:59 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“– Read about a real-world C# #cryptography vulnerability we've discovered in the wild, in our latest blog post! No math required (unless you're into that sort of thing)!

blog.doyensec.com/2025/08/19/t...

#doyensec #appsec #security #csharp

19.08.2025 13:05 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Are you located in the US/EU? passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
#doyensec #security #internship

07.08.2025 07:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐ŸšจSecurity Advisories๐Ÿšจ: multiple vulnerabilities in Retool, including host header injection and CSRF - discovered by Doyensec and the Robinhood Red Team!

docs.retool.com/disclosures/...

docs.retool.com/disclosures/...

#doyensec #appsec #security #retool #robinhood

17.07.2025 19:36 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Our latest ๐ŸšจSecurity Advisory๐Ÿšจ includes multiple vulnerabilities affecting the immersed platform. The findings include an RCE via Session Overwriting, an RCE via CSRF and a Privilege Escalation flaw. Read the details here:

www.doyensec.com/resources/Do...

#doyensec #appsec #security

10.07.2025 19:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hands typing at a keyboard with sparks coming out of the screen.

Hands typing at a keyboard with sparks coming out of the screen.

Just published - Our new white paper comparing Semgrep's Code and Community editions! We dove into both versions of this popular tool to see what the differences were and how they performed against each other. Check it out!
www.doyensec.com/resources/Co...

#doyensec #appsec #security #semgrep

26.06.2025 18:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
TumpiCon 2025

Several members of the @doyensec.bsky.social team are heading to @tumpicon.org ๐Ÿ‡ฎ๐Ÿ‡น for our Norbert Szetei's (@73696e65.bsky.social) presentation on his awesome ksmbd security research. If you're around, make sure to talk to Luca Carettoni & the team!
#doyensec #appsec #TumpiCon

tumpicon.org

25.06.2025 13:35 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿš€ We have just released a new Security Advisory for @NASA's CFITSIO library ๐Ÿ›ฐ๏ธ. Click the link for details on the Heap Overflow, Type Confusion, Out-of-Bound Writes & other vulnerabilities discovered by our Adrian Denkiewicz !

www.doyensec.com/resources/Do...

#doyensec #appsec #security

17.06.2025 13:04 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Thanks to inspiration and support from Teleport, Doyensec is proud to release the Security Policy Evaluation Framework, an open source tool for testing security policy engines!

github.com/gravitationa...

#doyensec #appsec #rigo #cedar #openfga #security

10.06.2025 13:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐ŸšจJust posted๐Ÿšจ: Learn about real-world API authorization vulnerabilities we frequently see with the slides from Szymon Drosdzol's recent presentation at the CONFidence conference in Krakow.

doyensec.com/resources/CO...

#doyensec #appsec #security

05.06.2025 13:49 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
A picture of Marcelino on a background showing "tech worker" items on a desktop.

A picture of Marcelino on a background showing "tech worker" items on a desktop.

We'd like to welcome ๐Ÿ‘‹ Marcelino Siles Rubia as our latest Application Security Intern. Welcome aboard! ๐ŸŽ‰

#doyensec #appsec #internship

02.06.2025 08:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
lecture 2025 - CONFidence lecture 2025

Attending CONFidence conference in Krakow ๐Ÿ‡ต๐Ÿ‡ฑ this weekend? Be sure to check out our Szymon
Drosdzol's presentation - API Authorization Antipatterns: confidence-conference.org/lecture-2025...

#doyensec #appsec #confidencecon

30.05.2025 13:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Several members of the #doyensec team are here in Berlin ๐Ÿ‡ฉ๐Ÿ‡ชattending ๐ŸŽฏOffensive Con ๐ŸŽฏ this weekend! Ping us or just say "hallo" in person, if you'd like to talk #appsec or grab a coffee. We're looking forward to some amazing talks!
#offensivecon #security

15.05.2025 17:52 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿšจ Advisory Alert!๐Ÿšจ We've just published our Aleandro Prudenzano's advisory (in cooperation with Edoardo Geraci) regarding a heap overflow in HAProxy. Read all the details here: www.doyensec.com/research.htm...

#doyensec #appsec #security #haproxy

13.05.2025 13:44 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

We'd like to welcome the latest member of our team - Diego Perez, our new Application Security Intern! Welcome aboard! ๐ŸŽ‰

#doyensec #appsec #security #internships

12.05.2025 18:39 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Going beyond SSO, our Francesco Lacerenza decided to take a deep dive into SCIM in our latest blog post. Read it today to learn how including this user identity standard in your next test's scope can reap big rewards!

blog.doyensec.com/2025/05/08/s...

#doyensec #appsec #security #scim

09.05.2025 09:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Our Norbert Szetei's latest research has resulted in at least 1โƒฃ5โƒฃ CVEs in ksmbd๐Ÿคฏ, including multiple use-after-frees, bounds checks, type confusion and overflowsโ€ผ๏ธ Check it out today!

www.doyensec.com/research.htm...

#doyensec #appsec #security #linux

06.05.2025 18:50 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Thanks to all the people who make @BSSidesSF happen every year. We're always happy to sponsor such a great conference! All of the #Doyensec team who attended had a great time! See you next year!
#bsides #bsidessf

01.05.2025 08:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@doyensec is following 4 prominent accounts