home.social

#doyensec — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #doyensec, aggregated by home.social.

fetched live
  1. "You don't need pentesters anymore." - Every hype cycle, ever.

    While the AI debate continues in Vegas, we'll be busy finding the bugs it missed and proving which "findings" were never vulnerabilities in the first place.

    Happy Black Hat & DEF CON!

    #BlackHat #DEFCON #AppSec #AI #CyberSecurity #HackerSummerCamp #doyensec #security

  2. "You don't need pentesters anymore." - Every hype cycle, ever.

    While the AI debate continues in Vegas, we'll be busy finding the bugs it missed and proving which "findings" were never vulnerabilities in the first place.

    Happy Black Hat & DEF CON!

    #BlackHat #DEFCON #AppSec #AI #CyberSecurity #HackerSummerCamp #doyensec #security

  3. 🇫🇷 Un petit bug with a big impact.

    A vulnerability reported by Doyensec's French team members in Electron's `shell.openPath()` has now been patched. Apps relying on string-only path validation could be tricked into opening a different file via an embedded null byte.

    Merci to the Electron maintainers for the quick fix.

    github.com/electron/electron/s

    #doyensec #appsec #security #electron #electronjs

  4. Hey pentesters📢, make your lives easier by using maSSO - a weaponized SSO Identity Provider for security testing of OIDC & SAML 2.0 Service Providers.

    The IdP your target trusts - that you fully control. Intercept, edit, re-sign. 👇 github.com/doyensec/maSSO

    #doyensec #appsec #security

  5. Hey pentesters📢, make your lives easier by using maSSO - a weaponized SSO Identity Provider for security testing of OIDC & SAML 2.0 Service Providers.

    The IdP your target trusts - that you fully control. Intercept, edit, re-sign. 👇 github.com/doyensec/maSSO

    #doyensec #appsec #security

  6. After publishing our whitepaper (blog.doyensec.com/2026/05/27/a) comparing Aikido and XBOW, we evaluated our own AI-assisted testing workflow against one of the same targets to see whether it would identify the same High and Critical findings.

    Built by and for our security engineers, our tooling accelerates codebase understanding, builds a knowledge base of application behavior and architecture, and uses that context to uncover vulnerabilities.

    Beyond rediscovering the previously reported and fixed issues, the workflow identified two additional vulnerabilities:

    * A cross-tenant invitation token validation flaw ([PR#1561](github.com/getfider/fider/pull))
    * A read-only SSRF in the OAuth implementation ([PR#1567](github.com/getfider/fider/pull))

    Both issues were responsibly disclosed and promptly remediated.

    Our conclusion: AI-powered security tooling can significantly enhance testing, but the best results still come from combining it with experienced human expertise.

    #doyensec #appsec #security #ai

  7. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  8. Proud to share that @doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing!

    Contact us today to see how our research-driven approach shapes the future of #appsec!

    anthropic.com/research/glasswi

    #doyensec #security #ai #claude #claudecode #claudemythos #anthropic

  9. After uncovering memory bugs in NASA’s CFITSIO, we looked at turning its *documented* features into attack primitives.

    Check out the blog post for details & a newly released Docker playground to reproduce the demos locally.

    #AppSec #doyensec #security

    blog.doyensec.com/2026/05/19/c

  10. After uncovering memory bugs in NASA’s CFITSIO, we looked at turning its *documented* features into attack primitives.

    Check out the blog post for details & a newly released Docker playground to reproduce the demos locally.

    #AppSec #doyensec #security

    blog.doyensec.com/2026/05/19/c

  11. While we're happy for our prize and that our exploit targeting OpenAI's Codex in the Coding Agent category was successful at #PWN2OWN, this was a collision💥 as the bug was previously known to the vendor. Back to the research! #P2OBerlin

    #doyensec #appsec #security #ai #openai

  12. While we're happy for our prize and that our exploit targeting OpenAI's Codex in the Coding Agent category was successful at #PWN2OWN, this was a collision💥 as the bug was previously known to the vendor. Back to the research! #P2OBerlin

    #doyensec #appsec #security #ai #openai

  13. If you're attending #PWN2OWN, be sure to watch Doyensec's Leonardo Giovannini demonstrate his #OpenAI Codex 0day exploit live Thursday, May 14 at 15:30.

    If you can't make it in person, keep an eye on blog.doyensec.com/ for more great #ai security research like this - coming very soon!

    See the PWN2OWN schedule here: zerodayinitiative.com/blog/202

    #appsec #doyensec #ai #0day #exploit

  14. If you're attending #PWN2OWN, be sure to watch Doyensec's Leonardo Giovannini demonstrate his #OpenAI Codex 0day exploit live Thursday, May 14 at 15:30.

    If you can't make it in person, keep an eye on blog.doyensec.com/ for more great #ai security research like this - coming very soon!

    See the PWN2OWN schedule here: zerodayinitiative.com/blog/202

    #appsec #doyensec #ai #0day #exploit

  15. Proud to share that #Doyensec has 3 unpatched 0day submissions for this year's #PWN2OWN - one for each #AI Coding Agent category target & our OpenAI Codex exploit was selected for the competition! The other vulnerabilities have been reported to the other vendors.

    #security

  16. Proud to share that #Doyensec has 3 unpatched 0day submissions for this year's #PWN2OWN - one for each #AI Coding Agent category target & our OpenAI Codex exploit was selected for the competition! The other vulnerabilities have been reported to the other vendors.

    #security

  17. Read how #Doyensec went beyond the basic #AI & web testing to reshape how our client thinks about risks and how we enabled them to evaluate a previously unknown attack surface. It’s amazing when our passion for #appsec has such a big impact!

    #security

    unit21.ai/blog/risk-decisions-

  18. Read how #Doyensec went beyond the basic #AI & web testing to reshape how our client thinks about risks and how we enabled them to evaluate a previously unknown attack surface. It’s amazing when our passion for #appsec has such a big impact!

    #security

    unit21.ai/blog/risk-decisions-

  19. Our CloudSecTidbits series is back with a bang! In the latest edition, we're releasing maSSO - A weaponized Identity Provider (IdP) for security testing! Read all about it and the dangers of Multi-SSO AWS Cognito User Pools.

    #doyensec #appsec #security

    blog.doyensec.com/2026/05/05/c

  20. Our CloudSecTidbits series is back with a bang! In the latest edition, we're releasing maSSO - A weaponized Identity Provider (IdP) for security testing! Read all about it and the dangers of Multi-SSO AWS Cognito User Pools.

    #doyensec #appsec #security

    blog.doyensec.com/2026/05/05/c

  21. Introducing SafeUpdater by Michael Pastor - A security-first update framework for Electron apps, built around explicit threat models, integrity and authenticity guarantees, and real attack mitigations. Check it out today!

    blog.doyensec.com/2026/02/16/e

    #AppSec #Electron #doyensec #security

  22. 🎯 Make XSS hunting easier and faster

    In the latest video in our Eval Villain series, @bemodtwz demonstrates how the “needles” feature can dramatically speed up your search for DOM-based XSS and other injection points.

    If you’re doing client-side security testing, this is a great example of how the right tooling can remove friction and help you focus on what matters: finding real vulnerabilities.

    👉 Watch here: youtu.be/LI9QOuQDduE

    #AppSec #Doyensec #BugBounty #security #XSS

  23. In our latest blog post, Szymon Drosdzol provides an in-depth walkthrough of using the #frida toolkit to demonstrate the right way to intercept OkHTTP traffic. This is essential knowledge for #android security research!

    Check it out today: blog.doyensec.com/2026/01/22/f

    #appsec #doyensec #security

  24. In our latest blog post, Szymon Drosdzol provides an in-depth walkthrough of using the #frida toolkit to demonstrate the right way to intercept OkHTTP traffic. This is essential knowledge for #android security research!

    Check it out today: blog.doyensec.com/2026/01/22/f

    #appsec #doyensec #security

  25. In the second post on Eval Villain, [email protected] walks through the quick & easy setup and its configuration. Check it out & start finding those client-side vulnerabilities today!

    youtu.be/-hIA5uLNFck

    Download it today: github.com/swoops/eval_villain

    #appsec #doyensec #security

  26. In the second post on Eval Villain, [email protected] walks through the quick & easy setup and its configuration. Check it out & start finding those client-side vulnerabilities today!

    youtu.be/-hIA5uLNFck

    Download it today: github.com/swoops/eval_villain

    #appsec #doyensec #security

  27. 🥂🤖 A toast to 9 years of #Doyensec!

    Nine years of pushing application security forward, breaking things so others don’t, & helping teams build with security from day one. 🍸

    Cheers to the bugs we’ve found, the apps we’ve strengthened, & the many secure years still to come. 🎉

  28. 🥂🤖 A toast to 9 years of #Doyensec!

    Nine years of pushing application security forward, breaking things so others don’t, & helping teams build with security from day one. 🍸

    Cheers to the bugs we’ve found, the apps we’ve strengthened, & the many secure years still to come. 🎉

  29. We’re excited to share the first video in our Eval Villain series from @bemodtwz

    This powerful security tool is designed to uncover client-side vulnerabilities and help defenders spot risky patterns.

    youtu.be/2dUoOyYKkzU

    #doyensec #appsec #security #evalvillain #xss

  30. 🚨 Just released - details on a serious vulnerability from our Leonardo Giovannini's research. An information disclosure within error messages allowing a remote attacker to identify security tokens/credentials when #squid is used. Perfect for SSRF!🚨

    #doyensec #appsec #security #vulnerability

    github.com/squid-cache/squid/s

  31. In our final ksmbd research post, @sine provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out!

    blog.doyensec.com/2025/10/08/k

    #doyensec #appsec #security

  32. In our final ksmbd research post, @sine provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out!

    blog.doyensec.com/2025/10/08/k

    #doyensec #appsec #security

  33. 🧞Your wish has been granted - the latest @PagedOut edition is out! In it, our Szymon Drosdzol takes a quick look at #vibecoding, walking through the creation of an AI agent🤖. Check it out today!

    #doyensec #appsec #ai #Security

    pagedout.institute/

  34. 📢 It's here! Part two of Norbert Szetei's (@sine) research into ksmbd. See how customized fuzzing & selecting the right sanitizers led to discovering 23 Linux kernel CVEs, including use-after-frees & out-of-bounds reads/writes.

    blog.doyensec.com/2025/09/02/k
    #doyensec #appsec #security #fuzzing

  35. Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
    #doyensec #security #internship #bugbounty

  36. Several members of the @doyensec team are heading to @TumpiConIT 🇮🇹 for our Norbert Szetei's presentation on his awesome ksmbd security research. If you're around, make sure to talk to Luca Carettoni & the team!
    #doyensec #appsec #TumpiCon

    tumpicon.org/

  37. Several members of the @doyensec team are heading to @TumpiConIT 🇮🇹 for our Norbert Szetei's presentation on his awesome ksmbd security research. If you're around, make sure to talk to Luca Carettoni & the team!
    #doyensec #appsec #TumpiCon

    tumpicon.org/

  38. 🚀 We have just released a new Security Advisory for NASA's CFITSIO library 🛰️. Click the link for details on the Heap Overflow, Type Confusion, Out-of-Bound Writes & other vulnerabilities discovered by our Adrian Denkiewicz !

    doyensec.com/resources/Doyense

    #doyensec #appsec #security

  39. 🚀#InQL v6.0 is here! Full Kotlin rewrite w/ improved performance & responsiveness!
    🆕 Built-in GraphiQL & #GraphQL Voyager visualization regardless of the target
    🆕Circular references detector
    🆕Improved batch queries screen
    🚀 SPEED!
    #doyensec #appsec

    github.com/doyensec/inql/relea

  40. 🥳The latest !exploitable is here! We're sharing all the joy that comes with exploiting an arbitrary file write in GitLab, while cruising the Mediterranean. 🚢 Everything from onerous configurations to spotty internet! Enjoy!
    #doyensec #appsec #security

    blog.doyensec.com/2025/03/18/e

  41. Knock, knock, everyone. 🐇 Want to see how far the rabbit hole goes? Check out our latest blog post where we walk you through exploiting one of the most famous vulnerabilities ever - while on a cruise! 🛥️

    blog.doyensec.com/2025/03/04/e

    #doyensec #appsec #security

  42. Ahoy! 🦜 Our first "!exploitable" post provides a technical dive 🤿 into the sea 🌊 of IoT exploitation. Read it today to learn how our team 🏴‍☠️ developed an exploit while floating in the Mediterranean!

    blog.doyensec.com/2025/02/11/e

    #doyensec #appsec #security #iot #exploits

  43. Despite being central to their security, many orgs struggle to securely implement #OAuth. Our new post walks through common issues & how to prevent them, along with a useful checklist! Read it today & ensure your org is secure: blog.doyensec.com/2025/01/30/o

    #doyensec #security #appsec

  44. Following our attempts to contact the casdoor maintainers, we're releasing an advisory regarding their software. This vulnerability allows attackers to exfiltrate data from the identity provider (IdP) or obtain access over SCIM. Details here:
    doyensec.com/resources/Doyense

    #doyensec #appsec #security

  45. Nice to see Maxence Schmitt's CSPT research (a nominee for #Portswigger's top 10 web hacking techniques for 2024) getting a shout out on the Critical Thinking Bug Bounty podcast !

    Check out the review and comments here: youtu.be/3rkg1CUDpjA?si=yu4AtH

    #doyensec #appsec #security #CSPT2CSRF

  46. 3️⃣ Rolo Miján's second nomination turned theory into reality by creating the #BurpSuite Prototype Pollution Gadgets Finder. It automated poisoning JSON objects in requests and cleaned them up afterwards to keep testing running smoothly. This research led to finding vulns in Axios and Nodemailer plus more!

    blog.doyensec.com/2024/02/17/s

    #doyensec #appsec #security

  47. This year, Doyensec is excited to have 4⃣ great nominations in Portswigger's Top 10 Web Hacking Techniques! 🥳

    Check them all out and vote for your favorites (hopefully ours🤞) today!

    portswigger.net/research/top-1

    #appsec #security #portswigger #doyensec