Closing keynote for Day 1 announced for BSides Prague 2026 ๐
Louis Nyffenegger (@snyff.pentesterlab.com), application security expert and founder of PentesterLabs, is joining us!
๐ท April 23, 2026 Donโt miss it. ๐ท๐ฅ
#bsides #bsidesprg #keynote
04.03.2026 08:23
๐ 0
๐ 1
๐ฌ 0
๐ 0
Browser-Based Port Scanning in the Age of LNA
๐ฅ๐ฒ๐๐ฒ๐ฎ๐ฟ๐ฐ๐ต ๐ช๐ผ๐ฟ๐๐ต ๐ฅ๐ฒ๐ฎ๐ฑ๐ถ๐ป๐ด - ๐ช๐ฒ๐ฒ๐ธ ๐ต, ๐ฎ๐ฌ๐ฎ๐ฒ
Mostly AI...
๐ป ๐๐ฟ๐ผ๐๐๐ฒ๐ฟ-๐๐ฎ๐๐ฒ๐ฑ ๐ฃ๐ผ๐ฟ๐ ๐ฆ๐ฐ๐ฎ๐ป๐ป๐ถ๐ป๐ด ๐ถ๐ป ๐๐ต๐ฒ ๐๐ด๐ฒ ๐ผ๐ณ ๐๐ก๐
Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
01.03.2026 23:58
๐ 2
๐ 3
๐ฌ 1
๐ 0
What you don't see - PentesterLab's Blog
More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars.
vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days.
pentesterlab.com/blog/what-yo...
02.03.2026 00:04
๐ 4
๐ 5
๐ฌ 0
๐ 1
SEE MUM, "I" CAN STILL FIND BUGS!
21.01.2026 22:15
๐ 2
๐ 0
๐ฌ 0
๐ 0
Today (2025-12-29) is 2026-W01-1 in ISO week-date ๐คฏ\
So itโs the first day of ISO week-year 2026, even though the date is still 2025.
(Week 1 = week with the first Thursday)
29.12.2025 00:15
๐ 3
๐ 0
๐ฌ 1
๐ 0
Black Friday at @pentesterlab.com ๐งจ
For a limited time:
๐ 1 year of PRO for $146.52
๐ Student special: 3 months PRO for $25.99
Hands-on labs. Real CVEs. Security code review training used by real AppSec & pentest teams.
โฐ Offer ends 2 Dec 2025, 23:59:59 UTC
๐ pentesterlab.com/pro
27.11.2025 22:06
๐ 2
๐ 3
๐ฌ 0
๐ 0
I have been using docker for 10 years...
Today I learned that you don't need to provide the full container id when you run docker exec...
21.11.2025 06:25
๐ 5
๐ 0
๐ฌ 0
๐ 0
Thanks :) It was great to catch up! See you at Kawai!
20.10.2025 21:33
๐ 3
๐ 0
๐ฌ 0
๐ 0
Really awesome preso from @snyff.pentesterlab.com @pentesterlab.com over at BSides Perth. Jam packed with patterns, approaches, tips and tricks to level up finding bugs in code. #bsides #bsidesperth
19.10.2025 02:33
๐ 3
๐ 2
๐ฌ 1
๐ 0
Iโve spent 2 solid hours doing bug bounty and I still havenโt made $200k.
Can someone tell me what Iโm doing wrong?
#bugbountytips
20.04.2025 23:09
๐ 6
๐ 1
๐ฌ 1
๐ 0
I Donโt Want My Devs to Become Hackers! - PentesterLab's Blog
Discover why encouraging developers to learn ethical hacking boosts security, reduces bugs, and fosters a proactive security culture in your organization.
Think teaching devs to hack is risky?
In reality, a bit of hacking knowledge helps them spot vulnerabilities early and build stronger apps.
Discover why having devs with a 'hacker mindset' is a win for security:
pentesterlab.com/blog/why-dev...
13.02.2025 18:21
๐ 2
๐ 1
๐ฌ 0
๐ 0
From now on, I'll call any snippet of vulnerable code shared on Social Media as
"Security Code Review Porn"
It gives the wrong expectations about what real code review actually involves.
07.02.2025 02:44
๐ 5
๐ 0
๐ฌ 0
๐ 0
Common OAuth Vulnerabilities ยท Doyensec's Blog
Common OAuth Vulnerabilities
Articles worth reading discovered last week:
๐ค blog.doyensec.com/2025/01/30/o...
โ ๏ธ www.feistyduck.com/newsletter/i...
๐ pathonproject.com/zb/?871f0933...
And as always, itโs in our blog: pentesterlab.com/blog/researc...
#PentesterLabWeekly
02.02.2025 21:50
๐ 6
๐ 3
๐ฌ 0
๐ 0
If youโre in the area, hereโs my schedule:
* OWASP Bay Area (Feb 11)
* CactusCon in Mesa/Phoenix (Feb 14 & 15)
* OWASP Los Angeles (Feb 18)
* OWASP Orange County (Feb 20)
Iโd love to connectโif youโre nearby, please stop by and say hello (and maybe grab some swag)!
29.01.2025 23:33
๐ 0
๐ 0
๐ฌ 0
๐ 0
Iโm excited to share that in a few weeks Iโll be heading to the US for a series of talks and workshops focused on security code review and JWTโand Iโll be bringing some
@pentesterlab.com swag along too!
29.01.2025 23:33
๐ 5
๐ 2
๐ฌ 1
๐ 0
28.01.2025 03:12
๐ 9
๐ 1
๐ฌ 0
๐ 0
...
22.01.2025 09:35
๐ 2
๐ 0
๐ฌ 1
๐ 0
A Signature Verification Bypass in Nuclei (CVE-2024-43405) | Wiz Blog
Wiz's engineering team discovered a high-severity signature verification bypass in Nuclei which could potentially lead to arbitrary code execution.
Someone shared this write-up in the @pentesterlab.com 's discord:
www.wiz.io/blog/nuclei-...
I love this article so much! The content and the analysis are A+
I really like the ๐ฉ (very similar to pentesterlab.com/blog/another...)
05.01.2025 03:02
๐ 8
๐ 0
๐ฌ 0
๐ 0
joernchen - Friday 13th @ 1ยฐC
YouTube video by Tiny Club Berlin
Have a great weekend and enjoy some tunes:
youtu.be/j_Md8_7mhOU
04.01.2025 13:46
๐ 6
๐ 3
๐ฌ 2
๐ 0
Golang: because hackers havenโt given up on SQL injection in 2024...
30.12.2024 00:48
๐ 11
๐ 1
๐ฌ 0
๐ 0
Thank you! โบ๏ธโบ๏ธโบ๏ธ
23.12.2024 06:09
๐ 1
๐ 0
๐ฌ 0
๐ 0
Someone replied that I had the wrong handle for James, I fixed it but I cannot find the original message.
Thanks to whoever raised it.
18.12.2024 21:56
๐ 1
๐ 0
๐ฌ 1
๐ 0
I put together a VERY limited (for now) list of web hackers in a Starter pack:
go.bsky.app/9uay4Ad
A lot of people are missing (I will try to add more as I find them) but make sure you follow people already in the list!
18.12.2024 00:54
๐ 31
๐ 14
๐ฌ 3
๐ 0
Cross-Site POST Requests Without a Content-Type Header by @lukejahnke
https://nastystereo.com/security/cross-site-post-without-content-type.html
#BBRENewsletter85
16.12.2024 15:05
๐ 2
๐ 1
๐ฌ 0
๐ 0