This wonderful wallpaper and the Issue #9 cover were created by Vasyl/Joker^NAH^TRSI. Both this and other wallpapers, as well as Issue #9 which just came out, can be downloaded from Paged Out!'s website!
Gynvael Coldwind
@gynvael.bsky.social
Security researcher/programmer ⁂ Managing director @ HexArcana ⁂ @DragonSectorCTF founder ⁂ he/him
hackarcana.com/py-summer ← Tomorrow is the first day of my advanced Python workshop - you should consider signing up if you like Python, but never found the time to dig beneath the surface :)
hackArcana
hackarcana.com
Issue #9 of the free @pagedout.bsky.social zine is here! 90 pages of pure technical awesomeness! Please help spread the news ❤️ Web: pagedout.institute/webview.php?... PDF: pagedout.institute/download/Pag... Wallpaper: pagedout.institute/download/Pag... Patreon: www.patreon.com/cw/PagedOut Enjoy!
Paged Out!
Deeply technical zine. And it's free.
pagedout.institute
My advanced-and-fun-parts-of-Python workshop starts next week! If you like Python, don't miss out :) Also, I really like this ad which will go into the next Paged Out! issue, so I'm sharing it as well ;)
Whatever .get()'s you the flag (video): www.youtube.com/watch?v=CtgF...
Whatever .get()'s you the flag
YouTube video by GynvaelEN
youtube.com
hackarcana.com/py-summer Last day of my summer workshop's pre-sale (afterwards the price goes up a bit). If you enjoy Python, this is one you don't want to miss!
I've posted a new Python/CTF story! Whatever .get()'s you the flag hackarcana.com/article/what... Enjoy!
I was invited to give an interview at the Woman In Red podcast! Join us at www.twitch.tv/womaninredpr... in ~52 minutes (or watch it later at www.youtube.com/@womaninredp...). Should be fun!
womaninredpresents - Twitch
Welcome to my channel! I'm Dorota Kozlowska, aka Woman in Red, and I'm passionate about sharing the art of penetration testing with kindness. You will feel as if Bob Ross was alive and a hacker. | Int...
twitch.tv
After finalizing some other workshops I finally will have some time to add the missing details to my Python Cyber Summer Camp. Meaning: If you want to get a ticket in a lower pre-sale price, there isn't too much time left. You can find it on hackArcana's website btw (see also: this image)
AREA41 just published the recording from my pretty unusual talk: "Hacker Goes Speedrunning: Beating A 25 Hour Game In Under 2 Minutes" www.youtube.com/watch?v=OkL6... Enjoy!
Hacker Goes Speedrunning: Beating A 25 Hour Game In Under 2 Minutes - Gynvael Coldwind
YouTube video by DEFCON Switzerland
youtube.com
If you're at AREA41 in Zurich this week, be sure to say Hi! I will be around both days of the conference :)
New video about TOP 5 of my favorite things in UNICODE: youtu.be/OqonHO_Hsdo
TOP 5 Unicode Tricks
YouTube video by GynvaelEN
youtu.be
My 88th blog post, a number considered lucky in many parts of Asia, was featured in the latest #BSDNow episode. The twist? It was covered in episode 666. 😈 Coincidence? 🤔 www.bsdnow.tv/666
Everyone gets an LPE
fatgid, why zfs is ideal for media production, the CTF scene is dead, private repo behind TLS, and more...
bsdnow.tv
A quick note to folks who are considering attending our Kubernetes security workshop - we might end sales early, so please don't wait until the last minute. If you know it might take you a bit longer to secure funding, let me know and we'll figure something out :)
I've posted a new video about a specific variant of Open Redirect, that I think is the most problematic one, up to the point of actually being a vulnerability: www.youtube.com/watch?v=eTde...
The only Open Redirect that scares me
YouTube video by GynvaelEN
youtube.com
I'm thinking of doing an in-depth Python summer camp? (online live workshop, in English). If you're potentially interested, please add your email to the list: hackarcana.com/summer-pytho... (it's just so I can measure interest and have a way to let you know once more info is up).
hackarcana.com
There was this gem of a challenge on Google Beginners Quest 2025 - it's just 50 lines of code, but one can learn a lot from it: www.youtube.com/watch?v=V2HS...
The Perfect Beginner CTF Challenge
YouTube video by GynvaelEN
youtube.com
I haven't uploaded stuff to my YT for some time, but I've recorded a couple of videos yesterday. Here's the first one, which is on how to start with the time-limited K8s CTF challenges we have on hA: youtu.be/XFncTjtAtVA (second one will be about a different CTF task form BQ)
Time Limited K8s CTF (and How To Start)
YouTube video by GynvaelEN
youtu.be
Super happy to announce we've listed the first workshop done by external experts at my educational site! hackarcana.com/workshop-list If you need to secure Kubernetes or want to learn how to assess its security - hands on! - you got to check this out.
Interested in getting to know some cybersecurity arcana? We're doing a livestream today with a misconfigured Kubernetes getting hacked :) Access is granted, but you have to register... or get the link another way ;) hackarcana.com/challenge/20...
hackArcana
hackarcana.com
[Good read for a lazy Friday] 0.1 + 0.2 is not 0.3. Yes, yes, everyone in programming knows this - it's these damn floats again! But what are the exact reasons? Since I love floats, I've reworked an answer I've recently given into an article that dives deep into this: hackarcana.com/article/floa...
Quite a lot of folks already finished our mini-CTF - congratz :)
We're running a small challenge next week on my edu site. We actually got 2 amazing k8s sec experts who made mini-quest-CTF (3 challs chained). The setup for this is an engineering marvel - probably it's more complex than we've done on any other CTFs. Anyway, Apr 29th, 6pm CEST.
We set up a Kubernetes cluster. It looks fine at first glance. But one small detail changes everything. Will you be able to spot it? If you haven't joined yet, sign up for our "Cloud Security Challenge for Kubernetes"! 👉 link in the comment.
Hey folks! We're running a 2-3 challenge K8s-themed mini-CTF. It's both for fun, but also to test our infra before the upcoming workshops on security of K8s. Anyway, it starts April 29, so sign up if you want to hack some Kubernetes :)
📣 Registration for the "Cloud Security Challenge for Kubernetes" is now open! Break into a vulnerable cluster, escalate privileges, and extract secrets – just like in real-world attacks. Free / Intermediate / ~2h / Hands-on / Starts April 29 Think you can break it? 👉 hackarcana.com/k8s-challenge
A 25-hour RPG finished in under 2 minutes. Not speedrunning - hacking. @gynvael.bsky.social breaks the game using reverse engineering, bugs, and his uncanny skills. #CONFidenceConf 2026 👉 bit.ly/joinCONFI2026
When working with computers we frequently find these cool little tidbits/tricks/tips we could share. They are too small to make a full article, but they are likely the right size for Paged Out! magazine, where each article is just 1 page 😎 CFP deadline for Issue #9: 30th April'26
This article reminded me of a GOATed FPGA bistream RE task from GoogleCTF - GPURTL by Robin - where the key to solving it for me was observing the pattern of changing bits in FPGA's registers. LiveOverflow made a video about it - link in the reply in case you want to check it out.
Learning reverse engineering and hungry for some real-world tips and tricks? Check out this article by Amnesia ("Reverse Engineering Cryptography Code"). This is a solid overview with multiple approaches to the topic.
www.youtube.com/watch?v=gJM9... ← my new old talk was released as a standalone; it's a fun story of how you go from being able to write '2' (0x32, 1 byte) anywhere on the FS to full RCE with admin/root privs
CTF In A Box ? The Weirdest NETGEAR Network Switch 2021 Exploit Chain - Gynvael Coldwind
YouTube video by GreHack
youtube.com
A perfect 1-page Friday reading → here's a fun article by Jacob Strieb about (ab)using <canvas> element in HTML and PNGs to get DEFLATE compression into older browsers (without reimplementing the whole thing in JS).