Love breaking things just to see how they work? ππ¨
βA @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers.
βIf you are passionate about securing the Open Source world, we definitely need to talk!
31.01.2026 08:29 β
π 3
π 3
π¬ 0
π 1
Want to learn more about our approach into auditing complex libraries and writing cool exploits?
ποΈ: Dec 02
π: 20:00 CET
RSVP: luma.com/ostif-meetup...
25.11.2025 09:15 β
π 2
π 3
π¬ 0
π 1
Huge thanks to #theSAS25 organization and ppl who voted for this amazing prize! It's been a real pleasure!
27.10.2025 18:35 β
π 0
π 0
π¬ 0
π 0
Attending #theSAS25? Meet @paupu.bsky.social for his PAM pwnage talk!
It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss π
26.10.2025 15:56 β
π 1
π 3
π¬ 0
π 0
π¨ New Open Source Audit Alert! π¨
Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX:
π 11 issues found (1 critical, 3 still to be published)
βοΈ Most fixed, others planned
π£οΈ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org
Full details in the blog post β¬οΈπ§΅
31.07.2025 15:09 β
π 4
π 4
π¬ 1
π 1
Just published some talks on tumpicon.org
Wanna join us? Follow the trail π₯Ύ
09.04.2025 09:35 β
π 6
π 3
π¬ 0
π 1
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox.
Update now and stay tuned for the technical details!
Ref: support.apple.com/en-us/122373
07.04.2025 08:58 β
π 9
π 5
π¬ 0
π 0
In Lausanne for @1ns0mn1h4ck.bsky.social? Donβt miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
13.03.2025 09:43 β
π 7
π 5
π¬ 0
π 0
Hey hackers!
Weβve started sending out the first invites β check your inbox! π
Didnβt get one? Take the fast track and submit a talk!
06.02.2025 11:32 β
π 11
π 7
π¬ 1
π 1
Shielder - Karmada Security Audit
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
π¨ New Open Source Audit Alert! π¨
Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io:
π 6 issues found (1 high, 1 medium, 2 low, 2 info)
βοΈ Most fixed, others planned.
π£οΈ to @suidpit.bsky.social and @thezero.org
Full details in the blog post!
www.shielder.com/blog/2025/01...
16.01.2025 16:01 β
π 6
π 5
π¬ 0
π 2
Introducing SecureDrop Protocol
This blog post is a part of a series about our research toward the next generation of the SecureDrop whistleblowing β¦
In early 2023 we (@thezero.org & @smaury.bsky.social) collaborated with SecureDrop to start designing and prototyping the #E2EE messaging protocol for a future version of SecureDrop.
π blog post: securedrop.org/news/introdu...
π» poc code: github.com/freedomofpre...
07.05.2024 10:54 β
π 5
π 3
π¬ 0
π 0
Shielder - Bref Security Audit
Bref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
We recently partnered with the Open Source Technology Improvement Fund (OSTIF) to perform a security audit sponsored by AWS on Bref. The audit resulted in 5 findings promptly addresses by @mnapoli.bsky.social.
The report is now public, check the details here: www.shielder.com/blog/2024/03...
29.03.2024 12:09 β
π 2
π 2
π¬ 0
π 0
Shielder - Hunting for ~~Un~~authenticated n-days in Asus Routers
Notes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240.
Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @thezero.org and @suidpit.bsky.social combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 www.shielder.com/blog/2024/01...
30.01.2024 13:47 β
π 6
π 5
π¬ 1
π 0