Doyensec Profile Banner
Doyensec Profile
Doyensec

@Doyensec

Followers
4K
Following
534
Media
283
Statuses
611

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

San Francisco / Warsaw
Joined May 2016
Don't wanna be here? Send us removal request.
@Doyensec
Doyensec
1 year
Has reliance on SSO left orgs with a single point of exploitation? Our latest research by @lacerenza_fra explores various IdP compromise scenarios as well as how to harden and detect attacks in @goteleport installations. #doyensec #teleport #security https://t.co/e7KmVUDIIN
0
14
44
@Doyensec
Doyensec
2 days
We’re super excited to welcome Yassine Bengana (@cousky_) to the Doyensec team! 🎉 He’s bringing serious AppSec skills and great vibes — can’t wait to see the cool stuff we’ll break (and build) together 🔥 #AppSec #infosec #Doyensec
0
1
16
@Doyensec
Doyensec
8 days
The #Doyensec team is back from another great retreat! This time we toured Ireland 🇮🇪 and even met a working 🐑sheep dog ! A great chance for our remote team to connect IRL. Also, a big thank you 🙏 to our tour guide Antonio! #security #appsec #remote
0
0
12
@Doyensec
Doyensec
18 days
Going to be near Dublin this Wednesday (10/22)? come join #Doyensec for an evening of drinks ( 🍻/☕ ), networking, and great conversations about all things #appsec & #cybersecurity. RSVP here: https://t.co/A2xzoh1KSQ #Infosec #Pwn2Own #BSidesDublin #OWASPIreland #security
Tweet card summary image
docs.google.com
Event Address: The Boar's Head - 149 Capel St, North City, Dublin, D01 T927, Ireland Date/Time: Wednesday October 22 @ 5:30 PM Contact us: [email protected]
@Doyensec
Doyensec
24 days
Live in or passing through #Dublin enroute to #pwn2own ? If you're in #appsec join #doyensec to talk #security over drinks (🍺/☕️) Oct. 22nd! Want to talk about our job openings or your projects? That's great too! RSVP here: https://t.co/UFqVIRwGwd @BSidesDublin @owaspireland
0
0
3
@Doyensec
Doyensec
21 days
🚨 Details on a serious #vulnerability from our @MaitaiThe's research. An information disclosure in error messages allows a remote attacker to identify security tokens/credentials when #squid is used. Perfect for SSRF!🚨 #doyensec #appsec #security https://t.co/Bm0JTqv9rS
Tweet card summary image
github.com
Due to a failure to redact HTTP Authentication credentials Squid is vulnerable to an Information Disclosure attack. __________________________________________________________________ ###...
0
5
21
@Doyensec
Doyensec
24 days
If you want, you can also RSVP via email at dublin@doyensec.com
0
0
1
@Doyensec
Doyensec
24 days
Live in or passing through #Dublin enroute to #pwn2own ? If you're in #appsec join #doyensec to talk #security over drinks (🍺/☕️) Oct. 22nd! Want to talk about our job openings or your projects? That's great too! RSVP here: https://t.co/UFqVIRwGwd @BSidesDublin @owaspireland
1
3
9
@Doyensec
Doyensec
1 month
In our final ksmbd research post, @73696e65 provides a detailed walkthrough for exploiting a local privilege escalation vulnerability. If you're interested in learning more about exploitation on modern systems - check it out! https://t.co/RPMvj0grOS #doyensec #appsec #security
0
31
94
@Doyensec
Doyensec
1 month
🧞Your wish has been granted - the latest @pagedout_zine edition is out! In it, our @tell1c0 takes a quick look at #vibecoding, walking through the creation of an AI agent🤖. Check it out today! #doyensec #appsec #ai #Security https://t.co/s6279LYJzI
Tweet card summary image
pagedout.institute
Deeply technical zine. And it's free.
0
8
26
@Doyensec
Doyensec
1 month
📢 Our latest blog post shows why VBScript’s Randomize + Rnd are terrible for cryptographic token generation. See how attackers can easily recover seeds and secrets. 🔗 https://t.co/YzWkvuudGN #doyensec #appsec #security #crypto
0
10
27
@Doyensec
Doyensec
2 months
We'd like to welcome our newest addition Marcelino Siles Rubia (@imarcex_)! Another success story from our #internship program! The future of #appsec is looking bright 😎 at #doyensec!
0
6
28
@Doyensec
Doyensec
2 months
📢It's here! Part 2 of Norbert Szetei's (@73696e65) research into ksmbd. See how customized fuzzing & the appropriate sanitizers led to discovering 23 Linux kernel CVEs, including use-after-frees & out-of-bounds reads/writes. https://t.co/LmigwJtB2c #doyensec #appsec #security
0
32
80
@Doyensec
Doyensec
3 months
📖Read about a real-world C# #cryptography vulnerability we've discovered in the wild in our latest blog post! No math required (unless you're into that sort of thing)! https://t.co/tV3LZ2oPRz #doyensec #appsec #security #csharp
0
9
41
@Doyensec
Doyensec
3 months
Are you located in the US/EU? passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - https://t.co/PGpjmTKxtA. #doyensec #security #internship
1
5
28
@Doyensec
Doyensec
4 months
🚨Security Advisories🚨: multiple vulnerabilities in Retool (@retool), including host header injection and CSRF - discovered by Doyensec and the Robinhood (@RobinhoodApp) Red team! https://t.co/pGVzkxIlu3 https://t.co/r8YXQQj9Im #doyensec #appsec #security #retool #robinhood
0
4
18
@Doyensec
Doyensec
4 months
Our latest 🚨Security Advisory🚨 includes multiple vulnerabilities affecting the immersed platform (@immersedXR). The findings include an RCE via Session Overwriting, an RCE via CSRF and a Privilege Escalation flaw. https://t.co/bnFgjIb9OF #doyensec #appsec #security
0
10
25
@Doyensec
Doyensec
4 months
📢Just published - Our new white paper comparing @semgrep's Code and Community editions! We dove into both versions of this popular tool to see what the differences were and how they performed against each other. https://t.co/RLvHuupK06 #doyensec #appsec #security #semgrep
0
9
36
@Doyensec
Doyensec
5 months
Several members of the @doyensec team are heading to @TumpiConIT 🇮🇹 for our Norbert Szetei's (@73696e65) presentation on his awesome ksmbd security research. If you're around, make sure to talk to @lucacarettoni & the team! #doyensec #appsec #TumpiCon https://t.co/DjJ5rB91Xm
0
2
9
@Doyensec
Doyensec
5 months
🚀We have just released a new Security Advisory for @NASA's CFITSIO library 🛰️. Click the link for details on the Heap Overflow, Type Confusion, Out-of-Bound Writes and other vulnerabilities discovered by our @a_denkiewicz ! https://t.co/7X6YVBzhdo #doyensec #appsec #security
0
10
44