The past few weeks have been quiet, but weโre back!
๐ ๏ธ deepwiki.com
๐ ๏ธ github.com/AsyncFuncAI/...
๐ชฒ blog.trailofbits.com/2025/04/23/h...
๐ ๏ธ github.com/quarkslab/pr...
๐ก๏ธ hdm.io/decks/Charti...
@pentesterlab.com.bsky.social
We make learning web hacking and security easier. Online systems, code review, videos & courses that can be used to understand, test and exploit bugs!
The past few weeks have been quiet, but weโre back!
๐ ๏ธ deepwiki.com
๐ ๏ธ github.com/AsyncFuncAI/...
๐ชฒ blog.trailofbits.com/2025/04/23/h...
๐ ๏ธ github.com/quarkslab/pr...
๐ก๏ธ hdm.io/decks/Charti...
Your face when you realize your next security code review is on a Clojure codebase...
20.04.2025 23:10 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0Articles worth reading discovered last week:
๐ชฒ labs.watchtowr.com/xss-to-rce-b...
๐งฉ gist.github.com/Panya/990b45...
#PentesterLabWeekly
Two great pieces of content for this week:
๐ชฒ www.wiz.io/blog/ingress...
๐ชฒ zhero-web-sec.github.io/research-and...
#PentesterLabWeekly
โผ๏ธ blog.doyensec.com/2025/03/18/e...
๐จ workos.com/blog/samlstorm
๐ค๏ธ projectdiscovery.io/blog/discour...
โ๏ธ labs.watchtowr.com/by-executive...
โค๏ธ tmpout.sh/4/
๐ผ labs.watchtowr.com/bypassing-au...โจโจ
Get our weekly news direct to your mailbox: pentesterlab.substack.com
If people spent as much time actually learning hacking as they do optimizing how to learn hacking, theyโd be a lot better at it. Just start. Break things. Learn. Repeat.
20.03.2025 09:18 โ ๐ 4 ๐ 0 ๐ฌ 0 ๐ 0We just released 3 new labs in our Golang Code Review Badge:
pentesterlab.com/badges/golan...
#golang
What a week! SAML&Ruby, PHP&XXE and so much more!
๐จ github.blog/security/sig...
๐ง๐ปโ๐ป seeinglogic.com/posts/visual...
๐คฏ swarm.ptsecurity.com/impossible-x...
๐ป scrapco.de/blog/analysi...
More details in our blog: pentesterlab.com/blog/researc...
#PentesterLabWeekly
Articles worth reading discovered last week:
๐ www.elttam.com/blog/rails-s...
๏น afine.com/understandin...
๐ชฒ slcyber.io/blog/sitecor...
For more details, check out our blog:
pentesterlab.com/blog/researc...
Want to prove your API hacking skills?
Earn the PentesterLab API badge!
Hands-on labs designed to test and improve your ability to find and exploit API vulnerabilities.
https://pentesterlab.com/badges/api
AI-generated code is reshaping secure code reviewโfewer trivial bugs, but more hidden threats.
Read more in our new blog post:
pentesterlab.com/blog/secure-...
What do you think?
Articles worth reading discovered last week:
๐ mizu.re/post/explori...
โ๏ธ devanshbatham.hashnode.dev/fragility-of...
๐ซ www.wiz.io/blog/nvidia-...
๐ www.reversinglabs.com/blog/rl-iden...
๐ฅ brutecat.com/articles/lea...
Think teaching devs to hack is risky?
In reality, a bit of hacking knowledge helps them spot vulnerabilities early and build stronger apps.
Discover why having devs with a 'hacker mindset' is a win for security:
pentesterlab.com/blog/why-dev...
๐จ Just launched: Two brand-new API Mass Assignment labs!
Ready to level up your #API hacking skills? Dive into realistic scenarios & learn how to exploit hidden parameters:
1๏ธโฃ API Mass Assignment 01
2๏ธโฃ API Mass Assignment 02
pentesterlab.com/badges/api/
Articles worth reading discovered last week:
๐ค blog.doyensec.com/2025/01/30/o...
โ ๏ธ www.feistyduck.com/newsletter/i...
๐ pathonproject.com/zb/?871f0933...
And as always, itโs in our blog: pentesterlab.com/blog/researc...
#PentesterLabWeekly
Iโm excited to share that in a few weeks Iโll be heading to the US for a series of talks and workshops focused on security code review and JWTโand Iโll be bringing some
@pentesterlab.com swag along too!
Invariants + Short Feedback Loops = your secret weapon ๐ก๏ธ in web hacking & exploit dev! โจโจ
Validate assumptions locally, iterate fast โก, and say goodbye to endless 10-minute test cycles โฑ๏ธ.โจ
Master these two techniques and watch your productivity skyrocket ๐ :
pentesterlab.com/blog/invaria...
Jumping straight into โfull exploitationโ can lead to confusion and missed bugs.
Instead, focus on minimal, incremental changes to isolate vulnerabilities. Itโs a simple shift that reduces false negatives and clarifies which step triggers the bug.
pentesterlab.com/blog/minimal...
Articles worth reading discovered last week:
๐ฎ ssno.cc/posts/revers...
๐พ github.blog/security/vul...
๐น psi3.ru/blog/swl01u/
๐ samcurry.net/hacking-subaru
๐ pathonproject.com/zb/?f4f3382a...
#PentesterLabWeekly
๐ Level up your #CyberSecurity skills FOR FREE! ๐ก๏ธ
Earn the Recon Badge with Pentesterlab and master: ๐ Virtual Hosts ๐ DNS Recon ๐ TLS Recon ...and so much more!
Start your journey today
๐ pentesterlab.com/badges/recon
๐จ 3 new MongoDB IDOR labs are live! ๐จ
Learn how to understand and predict MongoDB's ObjectId. Perfect for pentesters, appsec engineers, and devs looking to level up their security skills!
Start learning now: pentesterlab.com/badges/api/
Networking in InfoSec isnโt just about IP addresses and portsโitโs also about people!
Discover how meetups, conferences, and volunteering can open big career doors in InfoSec.
Read more: pentesterlab.com/blog/infosec...
Scoping a security code review? Donโt fall into these traps:
๐ซ Too little time = missed issues
๐ซ Too much time = wasted resources
Learn how to balance depth, coverage & cost while delivering tailored artefacts like SAST rules for long-term security.
๐ pentesterlab.com/blog/scoping...
Articles worth reading discovered last week:
๐คฏ www.wiz.io/blog/nuclei-...
๐ pathonproject.com/zb/?47a5c4d2...
#PentesterLabWeekly
Want to elevate your hacking skills? Master the 'Engineer Mind'??โจโจBuild mental models of code and architecture to predict vulnerabilities and navigate complex systems.
It's the perfect counterpart to the 'Criminal Mind.' ๐ ๏ธโก
Read more: pentesterlab.com/blog/enginee...
Want to find vulnerabilities like a pro? Develop the 'criminal mind'! ๐ง
Think like an attacker, question assumptions, and uncover flaws others miss. ๐๐ป
Learn how ๐ pentesterlab.com/blog/crimina...
The single best thing you can do to crush your goals in 2025:
Limit your phone usage to just 1 hour a day. ๐๐ต
WOOOOT ? poke @pentesterlab.com
01.01.2025 19:19 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0If your New Yearโs resolution is to get better at web security code review, donโt miss our upcoming live training. Learn how to find vulnerabilities and strengthen your skills:
pentesterlab.gumroad.com