Doyensec's Avatar

Doyensec

@doyensec.bsky.social

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

63 Followers  |  4 Following  |  81 Posts  |  Joined: 19.11.2024
Posts Following

Posts by Doyensec (@doyensec.bsky.social)

Spacestation on a planet as the cover of Paged Out

Spacestation on a planet as the cover of Paged Out

Check out the latest edition of @pagedout.bsky.social featuring Doyensec's own Bartล‚omiej (Bartek) Gรณrkiewicz vibing on Reversing Python Bytecode, along with plenty of great articles!

pagedout.institute/download/Pag...
#appsec #doyensec #security #reversing #pagedout

24.02.2026 16:55 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

Testing APIs? Stop guessing what's running under the hood. Use InQL's Engine Fingerprinter in Burp to identify the #GraphQL stack in seconds and save yourself the trial and error.

blog.doyensec.com/2025/12/02/i...
github.com/doyensec/inql

#doyensec #appsec #inql #security #bugbountytips

19.02.2026 20:01 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Hands typing on keyboard with sparks coming out of the monitor

Hands typing on keyboard with sparks coming out of the monitor

Introducing SafeUpdater by Michael Pastor - A security-first update framework for Electron apps, built around explicit threat models, integrity and authenticity guarantees, and real attack mitigations. Check it out today!

blog.doyensec.com/2026/02/16/e...

#AppSec #Electron #doyensec #security

17.02.2026 15:50 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CONFidence 2025: Szymon Drosdzol - API Authorization Antipatterns
YouTube video by PROIDEA Events CONFidence 2025: Szymon Drosdzol - API Authorization Antipatterns

If you missed our Szymon Drosdzol's presentation on "API Authorization Antipatterns" at CONFidence (@confidenceconf), or just want to see it again, it's your lucky day! The video is now available here: www.youtube.com/watch?v=Jje2.... Hope you enjoy it!

#appsec #doyensec #security

05.02.2026 20:16 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms ยท Doyensec's Blog Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms

Humans vs. AI? We put them to the test in our new post! We went head-to-head with AI tools to see who would win? Check it out today to see the results!

blog.doyensec.com/2026/02/03/o...

#appsec #doyensec #outline #ai

03.02.2026 17:37 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Set your #xss hunting ๐ŸŽฏ on easy mode! In the latest edition of our Eval Villain video series, Dennis Goodlett demonstrates the time-saving power of the "needles" feature.

youtu.be/LI9QOuQDduE

#appsec #doyensec #bugbountytips #security

29.01.2026 16:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Sponsors

๐ŸฅณDoyensec is proud to announce our sponsorship of the UC Davis Cyber Security Club!๐Ÿ’ป๐Ÿ”

We're committed to supporting the next generation of #cybersecurity talent ๐Ÿ“š๐Ÿง—

daviscybersec.org/sponsors/

#appsec #doyensec #infosec #ucdavis

27.01.2026 17:48 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

In our latest blog post, Szymon Drosdzol provides an in-depth walkthrough of using the #frida toolkit to demonstrate the right way to intercept OkHTTP traffic. This is essential knowledge for #android security research!

Check it out: blog.doyensec.com/2026/01/22/f...

#appsec #doyensec #security

23.01.2026 02:09 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐ŸŽ‰ We'd like to welcome our newest intern (and second Luca), Luca Molteni! We're confident he'll be the next amazing engineer to emerge from our proven internship program. ๐Ÿš€

#appsec #doyensec #security #internship

19.01.2026 16:30 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿ“ขJust published - the third video in our series on Eval Villain. Our Dennis Goodlett walks through using it to find ๐Ÿ”Ž a DOM XSS to demonstrate its functionality. Check it out today!
youtu.be/Hp7TexA6vFg

#appsec #doyensec #security #evalvillain #xss

15.01.2026 16:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

In the second post on Eval Villain, @bemodtwz walks through the quick & easy setup and its configuration. Check it out & start finding those client-side vulnerabilities today!

youtu.be/-hIA5uLNFck

Download: github.com/swoops/eval_...

#appsec #doyensec #security

08.01.2026 19:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Video thumbnail

Happy New Year from the #Doyensec team!

30.12.2025 21:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿฅ‚๐Ÿค– A toast to 9 years of #Doyensec!

Nine years of pushing application security forward, breaking things so others donโ€™t, & helping teams build with security from day one. ๐Ÿธ

Cheers to the bugs weโ€™ve found, the apps weโ€™ve strengthened, & the many secure years still to come. ๐ŸŽ‰

19.12.2025 15:01 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Happy Holidays everyone!โ˜ƒ๏ธ Weโ€™re taking a break next week for our annual shutdown to celebrate another successful year and give our team time to recharge. ๐Ÿ™Œ
#doyensec #appsec #security

15.12.2025 15:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Introducing Eval Villain
YouTube video by Doyensec Introducing Eval Villain

Weโ€™re excited to share the first video in our Eval Villain series from our Dennis Goodlett.

This powerful security tool is designed to uncover client-side vulnerabilities and help defenders spot risky patterns.

youtu.be/2dUoOyYKkzU

#doyensec #appsec #security #evalvillain #xss

09.12.2025 23:54 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
InQL v6.1.0 Just Landed with New Features & Contribution Swag! ๐Ÿš€ ยท Doyensec's Blog InQL v6.1.0 Just Landed with New Features & Contribution Swag! ๐Ÿš€

If you're interested in contributing to this awesome #FOSS security project for #graphql, we're rewarding contributions!

You can learn about the latest release here: blog.doyensec.com/2025/12/02/i... and check out the project here: github.com/doyensec/inql

#doyensec #security #opensource

02.12.2025 18:36 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

๐Ÿš€ inQL v6.0.1 is out!
Our GraphQL security tool got big upgrades.โšก
โ€ข Schema Brute-Forcer
โ€ข Server Engine Fingerprinting
โ€ข Automatic Variable Generation
โ€ข Performance boosts & other improvements

Details: blog.doyensec.com/2025/12/02/i...

#doyensec #graphql #appsec #security

02.12.2025 18:36 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Weโ€™re proud that #Doyensec was selected to help secure the IETF โ€” and to share the first batch of vulnerabilities we uncovered. Read more in the newly published advisories ๐Ÿ‘‡

github.com/ietf-tools/x...
github.com/ietf-tools/x...

#appsec #security

13.11.2025 19:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Weโ€™re super excited to welcome Yassine Bengana to the Doyensec team! ๐ŸŽ‰

Heโ€™s bringing serious AppSec skills and great vibes โ€” canโ€™t wait to see the cool stuff weโ€™ll break (and build) together ๐Ÿ”ฅ

#AppSec #infosec #Doyensec

05.11.2025 19:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

The #Doyensec team is back from another great retreat! This time we toured Ireland ๐Ÿ‡ฎ๐Ÿ‡ช and even met a working ๐Ÿ‘ sheep dog ! What a great chance for our remote team to connect IRL! Also, a big thank you ๐Ÿ™ to our tour guide Antonio!
#security #appsec #remote

30.10.2025 18:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Going to be near Dublin this Wednesday (10/22)? come join #Doyensec for an evening of drinks ( ๐Ÿป/โ˜• ), networking, and great conversations about all things #appsec & #cybersecurity.

RSVP here: docs.google.com/forms/d/1fa4...

#Infosec #Pwn2Own #BSidesDublin #OWASPIreland #security

20.10.2025 14:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SQUID-2025:2 Information Disclosure in Error handling Due to a failure to redact HTTP Authentication credentials Squid is vulnerable to an Information Disclosure attack. __________________________________________________________________ ###...

๐Ÿšจ Just released - details on a serious vulnerability from our Leonardo Giovannini's research! An Information Disclosure allowing a remote attacker to identify security tokens/credentials when #squid is used for load balancing.๐Ÿšจ

#doyensec #appsec #security #vulnerability

github.com/squid-cache/...

17.10.2025 17:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you want, you can also RSVP via email at dublin@doyensec.com

14.10.2025 16:12 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
People chatting about appsec over drinks

People chatting about appsec over drinks

Live in or passing through #Dublin enroute to #pwn2own ? If you're in #appsec join #doyensec to talk #security over drinks (๐Ÿบ or โ˜•๏ธ) Oct. 22nd! Want to talk about our job openings or upcoming projects, that's great too!

RSVP here: docs.google.com/forms/d/1fa4...

cc: @bsidesdublin.bsky.social

14.10.2025 15:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1
Post image

In our final ksmbd research post @73696e65.bsky.social provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out!

blog.doyensec.com/2025/10/08/k...

#doyensec #appsec #security

08.10.2025 16:26 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Paged Out! Deeply technical zine. And it's free.

๐ŸงžYour wish has been granted - the latest @pagedout.bsky.social edition is out! In it, our Szymon Drosdzol takes a quick look at #vibecoding, walking through the creation of an AI agent ๐Ÿค–. Check it out today!

#doyensec #appsec #ai #Security

pagedout.institute

06.10.2025 14:59 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

๐Ÿ“ข Our latest blog post shows why VBScriptโ€™s Randomize + Rnd are terrible for cryptographic token generation. See how attackers can easily recover seeds and secrets.
๐Ÿ”— blog.doyensec.com/2025/09/25/y...

#doyensec #appsec #security #crypto

25.09.2025 16:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Incomplete fix for GHSA-p46v-f2x8-qp98 ยท Issue #937 ยท prest/prest This is a followup on GHSA-p46v-f2x8-qp98. I spent some time looking into the mitigations introduced. While some of them perform adequate validation of user-controlled input, there are instances wh...

๐ŸšจSecurity Advisory๐Ÿšจ

Systemic SQL Injection vulnerability in pREST.

Details from our Viktor Chuchurski's bypassing the initial fix were also published:
github.com/prest/prest/...

#Doyensec #AppSec #Security #PostgreSQL #SQLInjection

19.09.2025 14:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Systemic SQL Injection # Summary pREST provides a simple way for users to expose access their database via a REST-full API. The project is implemented using the Go programming language and is designed to expose access t...

๐ŸšจSecurity Advisory๐Ÿšจ

Systemic SQL Injection vulnerability in pREST!

Initial report details published: github.com/prest/prest/...

#Doyensec #AppSec #Security #PostgreSQL #SQLInjection

19.09.2025 14:52 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

We'd like to welcome our newest addition Marcelino "Marce" Siles Rubia! Another success story from our #internship program! The future of #appsec is looking bright ๐Ÿ˜Ž at #doyensec !

04.09.2025 18:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0