๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ญ๐ฌ, ๐ฎ๐ฌ๐ฎ๐ฒ
A great mix of content this week!
๐ ๐๐ฟ๐ผ๐ป๐๐๐ฟ๐๐ฎ๐ถ๐ป: ๐ ๐ฃ๐ฒ๐ฟ๐๐ผ๐ป๐ฎ๐น ๐๐ ๐๐๐๐ถ๐๐๐ฎ๐ป๐ ๐๐๐ถ๐น๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ณ๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐๐ฟ๐ผ๐๐ป๐ฑ ๐จ๐ฝ
Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....
08.03.2026 21:01
๐ 4
๐ 1
๐ฌ 1
๐ 0
CVE-2026-1731 Metasploit module demo
My first @metasploit-r7.bsky.social module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version ๐
04.03.2026 09:36
๐ 3
๐ 2
๐ฌ 1
๐ 0
Browser-Based Port Scanning in the Age of LNA
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ต, ๐ฎ๐ฌ๐ฎ๐ฒ
Mostly AI...
๐ป ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ-๐๐ฎ๐๐ฒ๐ฑ ๐ฃ๐ผ๐ฟ๐ ๐ฆ๐ฐ๐ฎ๐ป๐ป๐ถ๐ป๐ด ๐ถ๐ป ๐๐ต๐ฒ ๐๐ด๐ฒ ๐ผ๐ณ ๐๐ก๐
Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
01.03.2026 23:58
๐ 2
๐ 3
๐ฌ 1
๐ 0
What you don't see - PentesterLab's Blog
More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars.
vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days.
pentesterlab.com/blog/what-yo...
02.03.2026 00:04
๐ 4
๐ 5
๐ฌ 0
๐ 1
vue de zensical
Zensical : un gรฉnรฉrateur de sites statiques qui permet de transformer rapidement une documentation Markdown en un site professionnel, personnalisable et multilingue. (Dรฉcouvert via Mat V. )
๐ Le projet : github.com/zensical/...
๐ En savoir plus : https://zensical.org/
28.02.2026 18:30
๐ 36
๐ 12
๐ฌ 2
๐ 1
Overview of one repo
๐งโ๐ As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested.
๐ Cheat sheet, methodology and tools: github.com/righettod/to...
๐ฌ R&D: github.com/righettod/po...
#appsec #appsecurity #ai
26.02.2026 07:50
๐ 1
๐ 1
๐ฌ 0
๐ 0
๐ฅ OWASP CRS is evolving! Introducing #CRSLang โ a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out ๐ coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity
18.02.2026 01:43
๐ 4
๐ 2
๐ฌ 0
๐ 1
Erratum, it's opened tonight February the 15th ๐
--------------
Erratum, c'est ouvert ce soir le 15 fรฉvrier ๐
15.02.2026 12:15
๐ 3
๐ 2
๐ฌ 0
๐ 0
Voxxed Days Luxembourg's CFP will be opened from tonight February the 17th at 11:30 PM to March the 29th at midnight.Luxembourg
----------------
L'appel aux orateurs de Voxxed Days sera ouvert ร partir de ce soir, le 17 fรฉvrier ร 23h30 jusqu'au 29 mars ร minuit.
---
voxxedlu2026.cfp.dev
15.02.2026 12:04
๐ 6
๐ 10
๐ฌ 2
๐ 0
Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically donโt need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.
07.02.2026 18:50
๐ 8
๐ 5
๐ฌ 0
๐ 0
Sqldef : un outil CLI qui permet le "diffing" de deux schรฉmas SQL et de gรฉnรฉrer automatiquement les instructions de migration nรฉcessaires.
๐ sqldef.github.io/
06.02.2026 16:30
๐ 17
๐ 2
๐ฌ 1
๐ 0
MORE LABS IN OUR JAVASCRIPT CODE REVIEW BADGE:
pentesterlab.com/badges/javas...
06.02.2026 00:53
๐ 2
๐ 1
๐ฌ 0
๐ 0
Thank you very much for this amazing free software ๐
05.02.2026 11:28
๐ 0
๐ 0
๐ฌ 0
๐ 0
Important Clarification: Notepad++ Security Incident | Notepad++
Important Clarification: Notepad++ Security Incident (Indicators of Compromise provided by our former hosting provider is included):
notepad-plus-plus.org/news/clarifi...
05.02.2026 03:28
๐ 9
๐ 3
๐ฌ 1
๐ 0
Execution of the POC performed.
๐งโ๐ Learning of the day for me thanks to @pentesterlab.com and Claude.
๐ฌ For the regular expression "[A-z]":
In a character class [X-Y], it matches all characters with ASCII codes from X to Y inclusive. So [A-z] means all ASCII characters from 65 (A) to 122 (z).
#appsec #appsecurity
02.02.2026 10:28
๐ 4
๐ 1
๐ฌ 1
๐ 0
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
Notepad++ Hijacked by State-Sponsored Hackers
Security Update - Resolution of Notepad++ Update Server Compromise
notepad-plus-plus.org/news/hijacke...
02.02.2026 00:44
๐ 53
๐ 29
๐ฌ 11
๐ 4
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!
apply.workable.com/portswigger/...
23.01.2026 10:36
๐ 8
๐ 8
๐ฌ 0
๐ 0
CVE-2026-23993: JWT authentication bypass in HarbourJwt via โunknown algโ
I didn't know Harbour even existed as a language when I found this bug. The fun part is that I also ...
๐ฅ CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg.
Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes.
Write-up + fix: pentesterlab.com/blog/cve-202...
21.01.2026 22:12
๐ 6
๐ 6
๐ฌ 0
๐ 1
๐ References used:
- developer.mozilla.org/en-US/docs/W...
- pentesterlab.com/exercises/sv...
- portswigger.net/web-security...
- www.fortinet.com/blog/threat-...
21.01.2026 07:25
๐ 1
๐ 0
๐ฌ 0
๐ 0
POC performed.
๐งโ๐ Learning of the day for me: I discovered that browsers (at least Chromium) display an SVG image even if the specified content type is set to XML. The contained JS script is also executed.
#appsec #appsecurity
21.01.2026 07:25
๐ 6
๐ 2
๐ฌ 3
๐ 0
Overview of the page.
๐ก OWASP Secure Headers Project: We have added information and examples regarding the Trusted Types feature of the Content-Security-Policy header.
๐ owasp.org/www-project-...
#appsec #appsecurity #owasp_shp
12.01.2026 05:59
๐ 0
๐ 1
๐ฌ 0
๐ 0
GitHub - C4illin/ConvertX: ๐พ Self-hosted online file converter. Supports 1000+ formats โ๏ธ
๐พ Self-hosted online file converter. Supports 1000+ formats โ๏ธ - C4illin/ConvertX
๐ฅ Hot Repo๏ผ ๐ฅ (100+ new stars)
๐ฆ C4illin / ConvertX
โญ 13,699 (+159)
๐ TypeScript
๐พ Self-hosted online file converter. Supports 1000+ formats โ๏ธ
09.01.2026 12:02
๐ 2
๐ 1
๐ฌ 0
๐ 0
logo
docker-android : une image Docker minimaliste permettant de faire tourner un รฉmulateur Android avec KVM.
๐ github.com/HQarroum/...
03.01.2026 18:30
๐ 26
๐ 4
๐ฌ 0
๐ 0
GitHub - BurntSushi/ripgrep: ripgrep recursively searches directories for a regex pattern while respecting your gitignore
ripgrep recursively searches directories for a regex pattern while respecting your gitignore - BurntSushi/ripgrep
Best news I've discovered today is that ripgrep is also available for Windows and you can install it with winget (winget install ripgrep). ripgrep is like the grep utility in Linux, but a bit faster, it also accepts grep's params github.com/burntsushi/r...
18.12.2025 18:27
๐ 1
๐ 1
๐ฌ 0
๐ 0
๐ Les guides de lโANSSI sont sur #MesServicesCyber !
๐ฅ๏ธ Alors que le site de lโANSSI รฉvolue, MesServicesCyber se transforme pour vous simplifier lโaccรจs aux conseils et recommandations de lโANSSI, et de ses partenaires.
Rendez-vous sur :
๐ messervices.cyber.gouv.fr/catalogue/?m...
17.12.2025 14:11
๐ 7
๐ 5
๐ฌ 1
๐ 0