Pit
@suidpit.sh
Technomancer, bard, user of "books". I pay to dive in the sand in my shorts when it's freezing outside. I have no strong opinion on the joypad vs M+K beef.
With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬
NEW: Google is rolling out a new feature for Android called Intrusion Logging, designed specifically to help researchers investigate attacks done with spyware and forensic tools. Amnesty says this is “a fundamental shift in the amount and quality of forensic data available on Android devices.”
Google launches new Android security feature to help uncover spyware attacks | TechCrunch
Intrusion Logging is a new part of Android’s Advanced Protection Mode, which aims to help protect human rights activists, journalists, and dissidents from government spyware attack and law enforcement...
techcrunch.com
eBPF is great, Linux is great, auditing is fun
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
Changing a bit a famous quote by Winston Smith: IF there is hope, it lies in the self-hosted models. #AI
#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F
I want to shake hands very much with Andy Weir for _Project Hail Mary_. Such a great book. If Andy Weir had written my physics book for exercises in high school, I'd probably be a big head in CERN or sometimes now. #projecthailmary #andyweir #scifi
oh my, @zed.dev has finally implemented support for chat history on external agents pure gold 🏆
So I'm watching this Anime called Gachiakuta. It's basically about heroes bashing each other using glorified trash. And it's absolutely great. #gachiakuta
I have absolutely no reason to be so excited and satisfied about doing this. #vulkan #graphicsprogramming
I put Godot, Python and frida in the same room to write an ugly clone of CheatEngine, that happens to work cross-platform (thanks to frida, not me). If you run it on Linux, it can attach to games running via Proton. blogpost @ suidpit.sh/posts/freat-... code @ github.com/suidpit/freat #gamehacking
Freat - writing a game hacking birdfeeder for fun and...fun
Can we mash together frida, Python and Godot to write an ugly CheatEngine clone and learn more about game hacking?
suidpit.sh
Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...
OSTIF Meetups · Events Calendar
View and subscribe to events from OSTIF Meetups on Luma.
luma.com
@shielder.com security researchers Davide and Pietro will be presenting on their audit of OpenEXR next Tuesday, 13:00 CST. Join to hear about how a team at the top of their game is auditing high-value targets used in a billion dollar industry. RSVP here: luma.com/ir16fuig
After watching three episodes of the Foundation TV show, I was...unconvinced to continue. Bright side: I am now re-reading the books, and there really isn't the need for a movie adaptation. This writing is so compelling that I find it unfolding it before my eyes as "cinematically" as it could.
Attending #theSAS25? Meet @paupu.bsky.social for his PAM pwnage talk! It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss 👀
Ready for #theSAScon25 in Khao Lak 🇹🇭 🌴 Ping me if u wanna say hi!