home.social

#securityresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityresearch, aggregated by home.social.

  1. New #CloudSecTidbits explores how misconfigured AWS ELBs can silently break security boundaries through rule shadowing, CloudFront/WAF bypasses, and alternate routing paths.

    We’re also releasing ELBaph — a new read-only tool to map ELB routing graphs, detect exposed paths, and surface real-world attack chains across ALBs/NLBs.

    blog.doyensec.com/2026/05/25/c

    #AppSec #Doyensec #AWS #CloudSecurity #AppSec #SecurityResearch

  2. New #CloudSecTidbits explores how misconfigured AWS ELBs can silently break security boundaries through rule shadowing, CloudFront/WAF bypasses, and alternate routing paths.

    We’re also releasing ELBaph — a new read-only tool to map ELB routing graphs, detect exposed paths, and surface real-world attack chains across ALBs/NLBs.

    blog.doyensec.com/2026/05/25/c

    #AppSec #Doyensec #AWS #CloudSecurity #AppSec #SecurityResearch

  3. Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

    At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

    🔗 oxidizeconf.com/sessions/await

    #Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust

  4. Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

    At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

    🔗 oxidizeconf.com/sessions/await

    #Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust

  5. Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

    At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

    🔗 oxidizeconf.com/sessions/await

    #Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust

  6. Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

    At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

    🔗 oxidizeconf.com/sessions/await

    #Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust

  7. Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.

    At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.

    🔗 oxidizeconf.com/sessions/await

    #Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust

  8. Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.

    After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.

    Today I’m sharing it with you 👇

    This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.

    Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?

    write-ups.security-chu.com/p/m

    #ResponsibleDisclosure #Cybersecurity #SecurityResearch

  9. Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.

    After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.

    Today I’m sharing it with you 👇

    This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.

    Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?

    write-ups.security-chu.com/p/m

    #ResponsibleDisclosure #Cybersecurity #SecurityResearch

  10. Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.

    After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.

    Today I’m sharing it with you 👇

    This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.

    Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?

    write-ups.security-chu.com/p/m

    #ResponsibleDisclosure #Cybersecurity #SecurityResearch

  11. Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.

    After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.

    Today I’m sharing it with you 👇

    This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.

    Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?

    write-ups.security-chu.com/p/m

    #ResponsibleDisclosure #Cybersecurity #SecurityResearch

  12. Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.

    After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.

    Today I’m sharing it with you 👇

    This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.

    Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?

    write-ups.security-chu.com/p/m

    #ResponsibleDisclosure #Cybersecurity #SecurityResearch

  13. I’ve published a new case study on BASE System, a multi-tenant ticketing platform from Poland used - according to the operator’s own claims - by more than 50 venues in Poland.

    The article documents customer email exposed in a redirect URL, nginx/1.10.3 on Ubuntu 16.04, broken CORS, cookies without the Secure flag, and a sales layer running under homelinux.net... DynDNS from Oracle.

    dadalo.pl/en/tech/anatomy-risk

    #privacy #cybersecurity #infosec #gdpr #appsec #securityresearch #privacy #phishing