Great views from the level up party last night. #blackhat2025 #blackhat.
07.08.2025 23:54 β π 0 π 0 π¬ 0 π 0@factionsecurity.com.bsky.social
Faction is an open-source tool for: - Automated Pentest Reporting - Track Vulnerability Remediation - Collaborate With Your Team - and more https://www.factionsecurity.com #appsec #redteam #securitytools #cybersecurity #infosec #hacking
Great views from the level up party last night. #blackhat2025 #blackhat.
07.08.2025 23:54 β π 0 π 0 π¬ 0 π 0Greetings from BlackHat 2025! If youβre attending this year come check out my talk on OWASP Faction, Thursday at noon - Arsenal station 3! #pentesting #owasp #hacking #blackhat2025 #redteam #appsec
06.08.2025 20:31 β π 3 π 2 π¬ 2 π 0#BlackHat Arsenal was awesome!!! ππππΊπΊπΊThanks to all that came to my talk. I forgot to bring stickers with me but will be giving them out at #Defcon. Look for them in the usual spots or DM me.
#owasp #appsec #redteam #pentesting
@factionsecurity.com
π I'm excited to be presenting Faction at BlackHat Arsenal 2025! π
Come by Thursday Aug 7th 12-12:55 am to see what Faction can do for you and get some STICKERS!!!
#hacking #pentesting #blackhat #BH2025 #appsec
www.blackhat.com/us-25/arsena...
π Faction 1.6 is Here β Powerful New Features for Open Source and Enterprise Users
Lots of updates that brings major improvements that make #pentest reporting more flexible and tailored to your needs.
docs.factionsecurity.com/blog/2025/07...
#appsec #redteam #opensource #cybersecurity #hacking
π OWASP Faction 1.5.2 is live!
This is a major update with improvements to help you deliver more streamlined and professional assessments.
Whatβs new?
β
Checklist Improvements
π SAML Authentication
π Better Markdown Handling
github.com/factionsecur...
#AppSec #Cybersecurity #OWASP #redteam
10 Burp extensions I actually use... BUT none of them are in the top 30 most popular in the BApp Store!
I get tired of seeing the same extensions come up in "top 10" lists. Here are some hidden gems you might not have tried... yet. In no particular order.
π§΅π
Happy to announce that Faction is now an #OWASP Project!!! π
#appsec #applicationsecurity #pentesting #vulnerability #cybersecurity #redteam #hacking
owasp.org/www-project-...
Itβs a new year and time to start the year off right by automating your manual #pentest with Faction. ππΎπ₯
We got a lot of cool stuff planned for this year! Weβll be releasing more info in the coming months. Stay tuned!
#appsec #redteam #hacking
www.factionsecurity.com
Happy holidays from us at Faction Security!!! ππ€Άπ
Hope you get some downtime so you hack all the things next year!
#cybersecurity
We just released Faction 1.4! π
If you're currently using Enterprise or Teams versions, then you have already been upgraded π
This release includes bug fixes in pentest report peer reviews and fixes several CVE's.
Find out more: www.factionsecurity.com
#appsec #redteam #hacking #cybersecurity
We published a blog post on how to automate boilerplate text in your #pentesting reports using the #opensouce security tool, Faction. Check out the link below!
we-are-faction.medium.com/automate-pen...
#appsec #infosec #redteam #pentest #hacking #hacking-tools #security-tools
I agree, Iβve seen a lot of reports where the severity did not match the complexity of the attack or address compensating controls. If you canβt prove that an outside attacker can gain access to the resource you exploited then it should be rated as a recommendation to improve security posture
08.12.2024 22:03 β π 0 π 0 π¬ 0 π 0I've developed a Python tool called Fback that generates wordlists for fuzzing backup files. It takes a JSON-based pattern file and a seed wordlist as input and produces a target-specific wordlist as output. Github: github.com/Spix0r/Fback
#bugbounty #bugbountytools #cybersecurity
Hey #cybersecurity, we are building opensource tools to help streamline #pentesting assessments. We realize every company is different.
We want to know where your pain points are and what would make your life as a #pentester easier. Reply or DM us your feedback.
#infosec #appsec #redteam
Slashdot is now on Bluesky!
03.12.2024 00:31 β π 182 π 41 π¬ 14 π 16This was one of our favorite talks from #defon32. This is a really clever approach to getting SQL injection at the protocol level.
#appsec #sqlinjection #hacking #applicationsecurity
www.youtube.com/watch?v=Tfg1...
Happy thanksgiving for all that celebrate! π¦
29.11.2024 01:28 β π 0 π 0 π¬ 0 π 0We're πliveπ in five, working on Open Source. π±
Join us with questions, comments & your important Syft & Grype bugs! π
www.youtube.com/watch?v=hCRt...
#sbom #opensource #security
Ready to level up your cybersecurity skills? π»π
Mireia Cano teaches us how to build an AppSec program at #WICCON2024!
Level up here: www.youtube.com/watc...
#CyberSecurity #WomenInTech
We got a story up on @medium.com! Learn out how to create your first #pentest report using Faction:
we-are-faction.medium.com/how-to-autom...
#appsec #redteam #informationsecurity #infosec #pentesting #ethicalhacking
Must read of the week: Ronan Farrow is looking at how governments (including the US) use spyware tech on individuals, activists, and journalists. www.newyorker.com/news/news-de...
21.11.2024 03:36 β π 83 π 32 π¬ 4 π 4When building your #pentest reports, Do you prefer CVSS scoring, critical/high/med/low, or something else to explain the severity of a finding?
#appsec #infosec #redteam #infosec
Cybercriminals have devised a novel method to cash out from stolen credit card details linked to mobile payment systems such as Apple Pay and Google Pay, dubbed 'Ghost Tap,' which relays NFC card data to money mules worldwide.
www.bleepingcomputer.com/news/securit...
Try this list. You can find many different starter packs. blueskydirectory.com/starter-pack...
20.11.2024 17:56 β π 0 π 0 π¬ 0 π 0Here is a searchable list of many different starter packs. A bunch in there for cybersecurity, infosec, and hacking. blueskydirectory.com/starter-packs
20.11.2024 17:51 β π 1 π 0 π¬ 1 π 0GitHub launches $1.25M open source fund with a focus on security
19.11.2024 17:34 β π 101 π 13 π¬ 2 π 1Checkout my vulnerable web application, allows security teams to verify tools, educate developers and hone their skills!
github.com/SirAppSec/vu...
Spotify playlists and podcasts are being abused to push pirated software, game cheat codes, spam links, and "warez" sites.
www.bleepingcomputer.com/news/securit...