
πα΅β₯πβ Η€ΕαΊΈΡΕπ’ π§
@DasMeDevon
Followers
500
Following
10K
Media
172
Statuses
5K
Just trying to reach that upper level β where your mind body and soul become one π€π€π€
πΊπ² ATX
Joined May 2011
Major cheat code for life: Commiting to something. The world is filled with the half-finished dreams of people who were too afraid to truly commit. Half in is actually all out. Even 90% gets you nowhere. Thereβs a magic in that last 10%. And it does not take talent, just courage.
159
441
3K
For those missing the talk, Blog: https://t.co/XBvFMbsfi0 Slides:
github.com
Mickey's Blogs. Contribute to jhftss/jhftss.github.io development by creating an account on GitHub.
6
41
165
βWhen a man canβt find a deep sense of meaning, they distract themselves with pleasure.β β Viktor Frankl
99
375
3K
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die:
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
20
249
749
Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment. Your own hands-on Entra lab for identity attack simulation. Built for red teams, blue teams and identity nerds. Check it out hereπ https://t.co/5qlXQiSYHS
9
232
694
I just learned that OSC8 (hyperlinks) in Windows Terminal uses ShellExecute(). Excellent trolling potential for README files π
14
87
481
Annual Defcon Bikeride is officially a go! I encourage you to try it this year if youβve never been. π #defcon33 #wehackhealth
https://t.co/eFafs4hik3
cycleoverride.org
2025-07-17: Fixed google form signup link This yearβs defcon bike ride will be a 7am, Friday Aug 8, starting and ending at Las Vegas Cyclery. TLDR: Ride a bβ¦
0
1
1
We recently identified a number of privilege escalation vulnerabilities in Lenovo Vantage on Windows; check out our latest blog for a technical deep dive
1
16
40
First ever (i think?) cli coding agents battle royale! 6 contestants: claude-code anon-kode codex opencode ampcode gemini They all get the same instructions: Find and kill the other processes, last one standing wins! 3... 2... 1...
169
697
6K
We are looking for a junior security researcher π€ No university degree or previous work experience required, but MUST be able to demonstrate interest in the field and some basic skills by either: 1. Have published blog post detailing 0-day vulnerability (found by yourself)
32
92
577
Man if I ever write a database hacking tool β Iβm just gonna call it paul_gerste. Heβs always pointing out neat database pwnage opportunities that have been overlooked for years. Would recommend his recent Defcon talk and blogs. π₯π₯π₯
SQL Injection despite using prepared statements? π§ Turns out that SQL syntax can be ambiguous! Learn how this has led to vulnerabilities in several popular PostgreSQL client libraries: https://t.co/d9pPFTwbvv
#appsec #security #vulnerability
0
0
2
Anyone else feel boxed out from watching the #NBAFinals ? π
0
0
0
Our new @GoogleDeepMind paper, "Lessons from Defending Gemini Against Indirect Prompt Injections," details our framework for evaluating and improving robustness to prompt injection attacks.
4
36
174
Great read with solid takeaways for instructing LLMs to assist in bug hunting. An interesting highlight besides the bug itself were the stats: o3 found it in 8/100 tries, Sonnet 3.7 in 3/100 runs, Sonnet 3.5 goes 0/100. I wonder how the new Sonnet 4 would perform? π€
I wrote-up how I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernelβs SMBΒ implementation. Link to the blog post below π
0
0
0
The first edition of the Arizona CTF (this one open just to undergrads in the state's various colleges) is running right now! Just over 100 undergrads pwning at the moment across AZ, 13 challenges solved, 10 challenges and 5 hours to go. First prize is $1337. Hype!
1
2
32
We're excited to announce our exclusive Zero Day Quest flash challenges, offering awards up to $100K for researchers who have qualified for the Zero Day Quest Onsite Hacking Event. These time-sensitive challenges will task our qualified researchers with uncovering hidden flags in
0
5
18
Iβm puzzled why Wisconsin didnβt go straight to the rim on that last possession. GGs none the less.
1
0
1