With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬
smaury
@smaury.bsky.social
Co-Founder @shielder.com CTF Player jbz.team Cliff Jumping Lover (23mt max so far)
⚽ I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, accessed RTMP stream keys for every live World Cup 2026 camera feed. An attacker could've replaced live TV worldwide. bobdahacker.com/blog/fifa-hack #InfoSec #FIFA #WorldCup
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live ...
bobdahacker.com
Slides for my WarCon talk ✅ See y'all in Warsaw 👀 Spoiler ⏬ youtu.be/LWGJA9i18Co?...
OK Go - Upside Down & Inside Out
YouTube video by OKGoVEVO
youtu.be
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
shielder.com
The guys on IRC told me I needed special hardware for a smurf attack. Am I doing this right?
Can't wait to see the final report going public!
#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F
Love breaking things just to see how they work? 🐛🔨 A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers. If you are passionate about securing the Open Source world, we definitely need to talk!
Happy New Year, Hackers! 🎆 We’re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens.
Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...
OSTIF Meetups · Events Calendar
View and subscribe to events from OSTIF Meetups on Luma.
luma.com
@shielder.com security researchers Davide and Pietro will be presenting on their audit of OpenEXR next Tuesday, 13:00 CST. Join to hear about how a team at the top of their game is auditing high-value targets used in a billion dollar industry. RSVP here: luma.com/ir16fuig
👋🏿 Hackers! Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge? @shielder.com is hiring a Red Teaming Lead to join our crew! More info ⬇️ (share appreciated) #hiring #redteaming romhack.io/job-opportun...
RomHack - Job opportunities
Check for RomHack sponsor's job opportunities
romhack.io
Working with folks from @lucasfilm.bsky.social, @ilmvfx.bsky.social, and Apple to secure some of the OSS foundations the movie and entertainment industries rely on was so cool! Big shout-out 📣 to the @ostifofficial.bsky.social and ASWF for making this possible.
🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX: 🔍 11 issues found (1 critical, 3 still to be published) ✔️ Most fixed, others planned 🗣️ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org Full details in the blog post ⬇️🧵
The TumpiCon experience will start tomorrow! Can't wait to meet y'all in Pinerolo 🏞️ Schedule is out: tumpicon.org
It's so cool working with the GoogleVRP team - folks over there are amazing. I love the concept of "you report something, then we work together with you to escalate it as much as possible". High bounties are also a nice addendum :) #BugBounty #bugbountytips
Romhack is coming up and the CfP is still open! Got novel research you’d love to present in front of an eager audience, with the stunning Roman landscape as your backdrop, and on the same stage where @jameskettle.com will deliver the keynote? Submit now! cfp.romhack.io/romhack-2025/
RomHack Conference 2025
Schedule, talks and talk submissions for RomHack Conference 2025
cfp.romhack.io
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF, @thephpf.bsky.social, and @quarkslab.bsky.social with funding provided by @sovereign.tech. For the report and further links, check out ostif.org/php-audit-co...
Is there a way I can wipe this from my brain? Jim Carrey any recommendations? mobapc.it/prodotto/sha...
Just published some talks on tumpicon.org Wanna join us? Follow the trail 🥾
The second edition of TumpiCon is here! 📅 June 27-28, 2025 📍 Somewhere near Turin, Italy 🔒 Invite-only No flashy stages. No fluff. Just raw, technical, and unfiltered hacking. More details? If you know, you know. Follow the trail: tumpicon.org
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373
Woah -- more Google Chrome VRP swag in my mailbox today! Wondering how to get some yourself? Find vulnerabilities in Chrome! More info here: bughunters.google.com/about/rules/...
One of my old Google VRP reports just went public -- check it out if you want to see an example of CEF exploitation. bughunters.google.com/reports/vrp/...
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
bughunters.google.com
Our next meetup is a presentation from our friends at X41 D-Sec GmbH. Join us next Wednesday, March 26th, at 14:00 CDT for a presentation and discussion with Markus Vervier and Eric Sesterhenn on their audit of @mullvad.bsky.social. We can't wait for this one! RSVP at lu.ma/wreregye
Security Code Audit of Mullvad VPN · Zoom · Luma
Join us for a presentation and meetup with Markus Vervier and Eric Sesterhenn of X41 D-Sec GmbH around their company's audit of Mullvad VPN. Markus Vervier is…
lu.ma
We recently analyzed the latest Cellebrite device support matrix published in February 2025. The reality is worrisome. It can be used to unlock most of the mobile devices we use every day. Read our report: (ENG) osservatorionessuno.org/blog/2025/03... (ITA) osservatorionessuno.org/it/blog/2025...
A deep dive into Cellebrite: Android support as of February 2025
A deep dive into Cellebrite: Android support as of February 2025
osservatorionessuno.org
In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!