๐ก Discovery of the week for me:
While reviewing code on a .Net project (CSharp language), I noticed that SemGrep, with its set of community rules, was not effective on this technology.
So I looked for a complement and found Microsoft's DevSkim tool...
06.08.2025 06:07 โ ๐ 4 ๐ 1 ๐ฌ 1 ๐ 0
GitHub Security
Bug Bounty Program
Here are our July bug bounty stats!
โ
174 bounty reports submitted
๐ฅ140 hackers participated in our program
๐ฐ Awarded $103,202 in bounties
Found a vulnerability? Submit it here: bounty.github.com.
06.08.2025 06:57 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
When are you going to drop links to GitHub repos that also contain 100+ links to random Medium articles???
06.08.2025 09:43 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
โWhy use Bash, Python, or Go when you can use JS from the console!โ
๐๐๐
04.08.2025 09:26 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Canโt wait until someone other than Meta makes a good pair of these. Deleted my FB account a while back and when I went back to sign up again I just got insta-banned :(
01.08.2025 10:03 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Freebies - Mastering Burp Suite Pro
Freebies - Mastering Burp Suite Pro
I just added the 15-minute talk I gave at Tumpicon to the "Freebies" section.
This talk covers the extensions Piper and Scalpel, and allows users to easily manipulate encrypted data by shuffling blocks around
hackademy.agarri.fr/freebies
25.07.2025 16:38 โ ๐ 7 ๐ 6 ๐ฌ 0 ๐ 0
Unsupported Browser | HackerOne
Just had my #bugbounty report disclosed on
#HackerOne ๐ช
TL;DR
RCE via path traversal in the Mozilla VPN Client through the local websocket server (developer mode).
hackerone.com/reports/2995...
29.07.2025 10:46 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 1
Thanks for adding support for Zed! Absolutely love it as an IDE.
29.07.2025 11:45 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Sick! ๐
What are you using to record your terminal? Super crisp, and the auto-zoom is pretty handy to show the specific commands.
28.07.2025 10:07 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
How to grab subs for a target using subfinder, validate them and extract the text body from each response using httpx and jq, extract a wordlist of keywords using NLP then resolve them using puredns to find valid subdomains ๐
28.07.2025 08:28 โ ๐ 5 ๐ 2 ๐ฌ 2 ๐ 0
Made the switch from an Apple Watch to Suunto, and Iโm loving it!
Still does everything I used:
- Tracking Training
- Notifications
- Alarms / Timers
Iโve had it on my wrist for 5 days, and itโs only at 47% battery. Absolutely amazing battery life, and for the price itโs a steal!
27.07.2025 13:09 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
I suspect the major negative fallout of vibe coding isnโt going to be taking jobs from software developers but instead an epidemic of insecure apps that get hacked with ease
25.07.2025 19:25 โ ๐ 615 ๐ 84 ๐ฌ 30 ๐ 20
Part of the job as a cybersecurity professional is in fact arguing to purge and not log information about your customers.
Data is not oil. It's risk.
26.07.2025 00:56 โ ๐ 300 ๐ 43 ๐ฌ 11 ๐ 3
The web reader to clear up distractions in Safari is one of the best things Iโve ever used in a browser.
Itโs up there with uBlock Origin.
26.07.2025 13:54 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
If you can afford it, could always try hacking on a VDP that leans towards disclosure in between other projects.
++ for grabbing a pentesting role, you might end up liking it a lot and staying ๐
22.07.2025 19:50 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
๐ฅ Want to think like a hacker and truly understand JavaScript?
๐ป JavaScript for Hackers is your guide to breaking, bending, and mastering the language like never before.
09.07.2025 17:11 โ ๐ 16 ๐ 6 ๐ฌ 1 ๐ 0
Intigriti July XSS Challenge (0725) | Jorian Woltjer
My author's writeup of the July 2025 challenge. Perform Mutation XSS to DOM Clobber an change the insertion point into an iframe, then bypass the CSP using a new useful Socket.IO gadget
I made a hard @intigriti.com XSS challenge this July ๐
But, it involves some very interesting Mutation XSS & DOM Clobbering fun combined with a CSP Bypass using the powerful SocketIO gadget.
Everything's explained in my writeup below!
jorianwoltjer.com/blog/p/ctf/i...
19.07.2025 16:18 โ ๐ 6 ๐ 1 ๐ฌ 0 ๐ 0
This is pretty cool. Things start getting really confusing when you look into the chunk extensions so... this is a huge help!
22.07.2025 14:00 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Yeah I use the Novablast 2s a lot and like them (good lock in & durability)! The way they pronate isnโt an exact match to me, but thatโs because I wear barefoot shoes when Iโm not running.
If you have a Fleet Feet or something similar nearby, theyโre great for trying on all the brands.
22.07.2025 15:51 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Congratulations! ๐พ๐
Looking forward to the future SemGrep and security content ๐๐
22.07.2025 12:13 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Have you tried Brooks or ASICS?
Not sure on the cost there, but I usually am able to find the generation or two behind the current release on sale for about $60-$80 USD.
22.07.2025 12:10 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
haha CVE-2025-53770 whats the big deal amirite
21.07.2025 12:43 โ ๐ 10 ๐ 1 ๐ฌ 3 ๐ 1
Join the Twitch stream, and follow along with the book by @zachdaniel.dev & @sevensea.cat :
pragprog.com/titles/ldash...
21.07.2025 03:40 โ ๐ 1 ๐ 2 ๐ฌ 0 ๐ 0
Is the entry-level price still essentially around $500-$600 for a camera or two + the hub?
Checked into it a while ago because I needed just a single camera + a way to locally control it, but didnโt think it was worth the cost in that instance.
20.07.2025 17:17 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
100%. Same goes for going to the ER as well.
If you have to ask yourself โDo I need to go to the ER?โ or have any doubt of your status over the next day or two, you probably do.
And ER =! urgent care.
16.07.2025 14:07 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
As someone who has been debugging Playwright tests primarily via page.pause() and PWDEBUG for the past five years, I am blown away by Trace Viewer and live debugging through their vscode extension.
It's just so. Much. Better.
Use those two, thank me later.
16.07.2025 11:51 โ ๐ 26 ๐ 3 ๐ฌ 0 ๐ 1
If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.)
Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google
15.07.2025 19:09 โ ๐ 11 ๐ 3 ๐ฌ 2 ๐ 0
Iโd bet itโs good for any vulns (in general). Thereโs new reports for Chrome everyday, and the add-ons these companies integrate can probably lead to some cool finds!
Saw this post right after I saw one about leaking the IPs of users using the Braveโs integrated TOR browser.
16.07.2025 12:40 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Your new favorite reading siteโsocial, gamified, kind (think if Goodreads and Reddit had a baby)
www.pagebound.co
Programmer by day, programmer by night.
Blog: https://push.cx Bootstrapping: https://recheck.dev
I run https://lobste.rs and stream office hours Mon+Thu: https://push.cx/stream
For people migrating, I was @pushcx on Twitter. I use he/him.
breaks rules, breaks systems, breaks code, but never, ever breaks hearts.
CTF player with The Flat Network Society - bug bounty & web security research
since 1985
https://phrack.org
Hi, I'm Jade!
Developing https://continuwuity.org
Programming in Rust and JavaScript and stuff
A lil bit of blog at https://jade.ellis.link/
ADHD and all that jazz
not enough attention span to finish filling this out
https://tech.lgbt/@JadedBlueEyes
Private account! Red teamer @codewhitesec. @frycos@infosec.exchange @frycos@X
security enthusiast | space | F1 | bikes
Helping developers search, understand, and write code in complex codebases with AI.
I make tv for developers at @codetv.dev
jason.energy/links
he/him
Open source durable execution system. Write code thatโs fault tolerant, durable, and simple. Used by @stripe @netflix @datadoghq @snapchat and many others.
Your Only Source For Professional Dog Ratings
nonprofit: @15outof10.org โค๏ธโ๐ฉน
links.weratedogs.com
A person (probably). Geek, all things #golang and #python. Brain teaser books @pragprog.com . Author at LinkedIn learning. Team member of GopherCon Israel, PyData Tel Aviv and Go Israel meetup.
Technical excellence from a trusted friend and author royalties up to 50%. We are Pragmatic, and we are developers, for developers.
https://pragprog.com
WHY2025 is an international non-profit outdoor hacker camp/conference taking place in The Netherlands in the summer of 2025.
WHY2025.org
zigzagging my way through cursed code and bugs
[bridged from https://infosec.exchange/@swapgs on the fediverse by https://fed.brid.gy/ ]
๐งโ๐ป finding flags @fluxfingers.net
๐ finding bugs @ Cure53
he/him
https://realansgar.dev
Strategic technologist and author focused on safety-by-design human experience, sustainability, and privacy-enhancing technology at @omnifi.foundation.
A durable execution specialist in #Golang.
โ ๏ธ Bot Account โ ๏ธ
Follow for my hand-curated application security feeds.
๐ฌ Run by @alp1n3.dev