smaury's Avatar

smaury

@smaury.bsky.social

Co-Founder @shielder.com CTF Player jbz.team Cliff Jumping Lover (23mt max so far)

947 Followers  |  322 Following  |  49 Posts  |  Joined: 19.07.2023  |  1.8125

Latest posts by smaury.bsky.social on Bluesky


๐ŸคŸ๐Ÿฟ

01.02.2026 18:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Love breaking things just to see how they work? ๐Ÿ›๐Ÿ”จ

โ€‹A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers.

โ€‹If you are passionate about securing the Open Source world, we definitely need to talk!

31.01.2026 08:29 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

Happy New Year, Hackers! ๐ŸŽ†
Weโ€™re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens.

31.12.2025 12:49 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Nano Banana opinion on this is

09.12.2025 13:02 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

What's the Bobby Tables equivalent in #AI era?

09.12.2025 12:54 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Join us tomorrow to learn more about this cool audit!

01.12.2025 15:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Want to learn more about our approach into auditing complex libraries and writing cool exploits?

๐Ÿ—“๏ธ: Dec 02

๐Ÿ•—: 20:00 CET

RSVP: luma.com/ostif-meetup...

25.11.2025 09:15 โ€” ๐Ÿ‘ 2    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
RomHack - Job opportunities Check for RomHack sponsor's job opportunities

๐Ÿ‘‹๐Ÿฟ Hackers!

Are you a Red Teaming Wizard ๐Ÿง™๐Ÿฟ looking for a new challenge? @shielder.com is hiring a Red Teaming Lead to join our crew!

More info โฌ‡๏ธ (share appreciated) #hiring #redteaming
romhack.io/job-opportun...

07.08.2025 19:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Working with folks from @lucasfilm.bsky.social, @ilmvfx.bsky.social, and Apple to secure some of the OSS foundations the movie and entertainment industries rely on was so cool!

Big shout-out ๐Ÿ“ฃ to the @ostifofficial.bsky.social and ASWF for making this possible.

31.07.2025 15:23 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

The TumpiCon experience will start tomorrow!
Can't wait to meet y'all in Pinerolo ๐Ÿž๏ธ
Schedule is out: tumpicon.org

25.06.2025 20:23 โ€” ๐Ÿ‘ 7    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Woah - thanks Nestlรจ and @intigriti.com!

23.05.2025 09:34 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

It's so cool working with the GoogleVRP team - folks over there are amazing.
I love the concept of "you report something, then we work together with you to escalate it as much as possible".
High bounties are also a nice addendum :)
#BugBounty #bugbountytips

20.05.2025 18:53 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
RomHack Conference 2025 Schedule, talks and talk submissions for RomHack Conference 2025

Romhack is coming up and the CfP is still open!
Got novel research youโ€™d love to present in front of an eager audience, with the stunning Roman landscape as your backdrop, and on the same stage where @jameskettle.com will deliver the keynote?
Submit now!
cfp.romhack.io/romhack-2025/

27.04.2025 06:35 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF, @thephpf.bsky.social, and @quarkslab.bsky.social with funding provided by @sovereign.tech. For the report and further links, check out ostif.org/php-audit-co...

10.04.2025 19:12 โ€” ๐Ÿ‘ 5    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Is there a way I can wipe this from my brain?
Jim Carrey any recommendations?
mobapc.it/prodotto/sha...

10.04.2025 06:47 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Just published some talks on tumpicon.org
Wanna join us? Follow the trail ๐Ÿฅพ

09.04.2025 09:35 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox.
Update now and stay tuned for the technical details!
Ref: support.apple.com/en-us/122373

07.04.2025 08:58 โ€” ๐Ÿ‘ 9    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Woah -- more Google Chrome VRP swag in my mailbox today!

Wondering how to get some yourself? Find vulnerabilities in Chrome!

More info here: bughunters.google.com/about/rules/...

03.04.2025 12:20 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.

One of my old Google VRP reports just went public -- check it out if you want to see an example of CEF exploitation.

bughunters.google.com/reports/vrp/...

18.03.2025 13:02 โ€” ๐Ÿ‘ 8    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Security Code Audit of Mullvad VPN ยท Zoom ยท Luma Join us for a presentation and meetup with Markus Vervier and Eric Sesterhenn of X41 D-Sec GmbH around their company's audit of Mullvad VPN. Markus Vervier isโ€ฆ

Our next meetup is a presentation from our friends at X41 D-Sec GmbH. Join us next Wednesday, March 26th, at 14:00 CDT for a presentation and discussion with Markus Vervier and Eric Sesterhenn on their audit of @mullvad.bsky.social. We can't wait for this one! RSVP at lu.ma/wreregye

17.03.2025 19:50 โ€” ๐Ÿ‘ 3    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
A deep dive into Cellebrite: Android support as of February 2025 A deep dive into Cellebrite: Android support as of February 2025

We recently analyzed the latest Cellebrite device support matrix published in February 2025.
The reality is worrisome. It can be used to unlock most of the mobile devices we use every day.

Read our report:
(ENG) osservatorionessuno.org/blog/2025/03...
(ITA) osservatorionessuno.org/it/blog/2025...

17.03.2025 10:34 โ€” ๐Ÿ‘ 6    ๐Ÿ” 7    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

My pixel 7 almost melt down in my hands -- but yes!

14.03.2025 13:01 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Is this the year of cracking on smartphones?

14.03.2025 07:08 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Swag day -- thanks ChromeVRP and @amyre.bsky.social

13.03.2025 11:11 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

In Lausanne for @1ns0mn1h4ck.bsky.social? Donโ€™t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!

13.03.2025 09:43 โ€” ๐Ÿ‘ 7    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Hey hackers!
Weโ€™ve started sending out the first invites โ€” check your inbox! ๐Ÿ‘€
Didnโ€™t get one? Take the fast track and submit a talk!

06.02.2025 11:32 โ€” ๐Ÿ‘ 11    ๐Ÿ” 7    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

tmux and chill

07.03.2025 06:48 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

๐Ÿ—ฃ๏ธ

06.02.2025 11:36 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

On my way to @fosdem.bsky.social!
If you are into securing open source code then we should definitely have a chat -- looking forward to meeting y'all!

01.02.2025 03:08 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
GET /%0D%0ASet-Cookie: foo=bar
403 Forbidden

GET /%E4%BC%8D%E4%BC%8ASet-Cookie: foo=bar
200 OK
Set-Cookie: foo=bar

GET /%0D%0ASet-Cookie: foo=bar 403 Forbidden GET /%E4%BC%8D%E4%BC%8ASet-Cookie: foo=bar 200 OK Set-Cookie: foo=bar

Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique.

portswigger.net/research/byp...

28.01.2025 14:01 โ€” ๐Ÿ‘ 39    ๐Ÿ” 22    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@smaury is following 18 prominent accounts