g3n3r4l16
-
HackerTracker Disobey 2025 (hackertracker.app)
schedule and events of the Disobey 2025 conference.
-
Beej's Guide to Git (beej.us)
A beginner-friendly guide to mastering Git.
-
Search CTF Writeups (ctfsearch.hackmap.win)
Find writeups for Capture The Flag challenges.
-
Why I'm Joining Wiz (ramimac.me)
Rami shares insights into his decision to join Wiz.
-
Avoid ISP Routers (routersecurity.org)
Understand why you should avoid ISP-provided routers.
-
An in-depth analysis of potential vulnerabilities.
-
POST to XSS: Leveraging Pseudo Protocols in SSO Flows (security.lauritz-holtmann.de)
techniques for exploiting SSO flows.
-
Everyone Knows Your Location (timsh.org)
Tracking yourself through in-app ads.
-
Browser Syncjacking (labs.sqrx.com)
browser extensions can be exploited.
-
Collabfiltrator 4.0.1 Released (adamlogue.com)
New SQLi exfiltration support for the Burp plugin.
-
CSP Bypass Tactics (nzt-48.org)
Bypassing form-action CSP and other techniques.
-
CVE-2024-46507 (rhinosecuritylabs.com)
Yeti platform server-side template injection (SSTI).
-
Serving a (g)zip bomb with Caddy (dustri.org)
Learn about serving compressed payloads.
-
DeepSeek Security Insights (franklyspeaking.substack.com)
Thoughts on DeepSeek's implications for security.
-
DeepSeek Janus Security&Safety Concerns (evren.ninja)
Safety concerns and challenges of DeepSeek.
-
Rejecting CVSS as Broken (socket.dev)
cURL and Go teams' take on CVSS.
X1
-
HackerOne x AnthropicAI Bug Bounty (@michielprins)
Test the resilience of Constitutional Classifiers with rewards up to $30K.
g1thub4
-
Fuzzilli (github.com)
A JavaScript engine fuzzer by Google Project Zero. Explore on GitHub
-
Cloudflare-jsd (github.com)
Bypass Cloudflare's challenges using Python. Explore on GitHub
-
Bettercap v2.41.0 (github.com)
The latest release of the versatile MITM framework. Explore on GitHub
-
Awesome Secure Defaults (github.com)
Libraries for eliminating common bug classes. Explore on GitHub