ShielderSec Profile Banner
Shielder Profile
Shielder

@ShielderSec

Followers
2K
Following
281
Media
151
Statuses
466

InfoSec boutique. Owning things since 2014. We love to go for the extra mile, where we usually find the best 🦟🐞πŸͺ²πŸͺ³πŸ›πŸœπŸ•· the others miss.

Italy
Joined July 2014
Don't wanna be here? Send us removal request.
@ShielderSec
Shielder
27 days
Want to learn more about our approach into auditing complex libraries and writing cool exploits? Attend @OSTIFofficial's meetup where our very own @Th3Zer0 and @suidpit will talk about the "Security Audit of OpenEXR" πŸ—“οΈ: Dec 02 πŸ•—: 20:00 CET RSVP:
Tweet card summary image
luma.com
View and subscribe to events from OSTIF Meetups on Luma.
0
6
8
@ShielderSec
Shielder
2 months
Great achievement of our very own @Paupu_95 πŸŽ‰
@Paupu_95
Paolo CavagliΓ 
2 months
Huge thanks to #theSAS25 organization and ppl who voted for this amazing prize! It's been a real pleasure!
0
1
3
@ShielderSec
Shielder
2 months
πŸ”₯πŸ”₯πŸ”₯
@TheSAScon
TheSAS2025
2 months
So, Symantec/Broadcom PAM seems to contain code in PHP, Java, and Perl simultaneously. Guess how many issues are hiding there? @Paupu_95 keeps the tension high, and we still don’t know the answer. This #TheSAS2025 talk is quite thrilling.
0
1
1
@ShielderSec
Shielder
2 months
Attending #theSAS25? Meet @Paupu_95 for his PAM pwnage talk! It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss πŸ‘€
@Paupu_95
Paolo CavagliΓ 
2 months
Ready for #theSAScon25 in Khao Lak πŸ‡ΉπŸ‡­ 🌴 Ping me if u wanna say hi!
0
3
7
@ShielderSec
Shielder
3 months
Attending #TheSAS2025? Don't miss our gangster @Paupu_95 pull off a credential heist, taking down a PAM and going from no info to full infra compromise!
@TheSAScon
TheSAS2025
3 months
You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo CavagliΓ  (@Paupu_95) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream" 🏰 His team spent
1
3
3
@ShielderSec
Shielder
3 months
πŸ‘€ @cybersaiyanIT
0
1
2
@smaury92
smaury
5 months
πŸ‘‹πŸΏ Hackers! Are you a Red Teaming Wizard πŸ§™πŸΏ looking for a new challenge? @ShielderSec is hiring a Red Teaming Lead to join our crew! More info ⬇️ (share appreciated) #hiring #redteaming https://t.co/l7yi7QpvlZ
Tweet card summary image
romhack.io
Check for RomHack sponsor's job opportunities
0
6
12
@ShielderSec
Shielder
5 months
🚨 New Open Source Audit Alert! 🚨 Shielder, with @OSTIFofficial & @AcademySwf, audited OpenEXR and MaterialX: πŸ” 11 issues found (1 critical, 3 still to be published) βœ”οΈ Most fixed, others planned πŸ—£οΈ to @ndaprela @smaury92 @suidpit @Th3Zer0 Full details in the blog post β¬‡οΈπŸ§΅
1
5
9
@TheZDIBugs
TheZDIBugs
5 months
[ZDI-25-655|CVE-2025-54438] Samsung MagicINFO 9 Server downloadChangedFiles Directory Traversal Authentication Bypass Vulnerability (CVSS 9.8; Credit: Paolo Cavagli, Abdel Adim Oisfi, and Nicola Davico of Shielder)
Tweet card summary image
zerodayinitiative.com
Samsung MagicINFO 9 Server downloadChangedFiles Directory Traversal Authentication Bypass Vulnerability
0
2
13
@TheZDIBugs
TheZDIBugs
5 months
[ZDI-25-657|CVE-2025-54440] Samsung MagicINFO 9 Server MagicInfoWebAuthorClient Unrestricted File Upload Remote Code Execution Vulnerability (CVSS 9.8; Credit: Paolo Cavagli, Abdel Adim Oisfi, and Nicola Davico of Shielder)
Tweet card summary image
zerodayinitiative.com
Samsung MagicINFO 9 Server MagicInfoWebAuthorClient Unrestricted File Upload Remote Code Execution Vulnerability
0
1
4
@ShielderSec
Shielder
9 months
Last week @Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: https://t.co/fSRCbM8WbQ
0
8
18
@ShielderSec
Shielder
9 months
In Lausanne for @1ns0mn1h4ck? Don’t miss the chance to meet our very own @not4nhacker! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
5
3
5
@OSTIFofficial
OSTIF Official
11 months
#Karmada showed camaraderie with their security audit! Navigated with support from the @CloudNativeFdn and auditing by @ShielderSec, the work is now available publicly- read on below! πŸ‘‡
1
1
5
@OSTIFofficial
OSTIF Official
11 months
It was smooth sailing with the Karmada maintainer team, @ShielderSec, and the CNCF for this audit!
@CloudNativeFdn
CNCF
11 months
Read all about the results of the recent security audit of #CNCF project Karmada, a #Kubernetes orchestration system for running #cloudnative applications across different clouds and clusters πŸ“° Read more from @OSTIFofficial, who completed the audit ➑️ https://t.co/ESIySnO0o1
0
3
4
@ShielderSec
Shielder
11 months
🚨 New Open Source Audit Alert! 🚨 Shielder, with @OSTIFofficial & @CloudNativeFdn, audited @karmada_io: πŸ” 6 issues found (1 high, 1 medium, 2 low, 2 info) βœ”οΈ Most fixed, others planned. πŸ—£οΈ to @suidpit and @Th3Zer0 Full details in the blog post! https://t.co/mkRiqw7joX
shielder.com
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
0
8
20
@gbergel
☠ Ragnar ☠
1 year
Muy buena la charla β€œRiding the DYLD Rocket: Escaping from macOS Sandbox at Mach 1337” de @suidpit en #theSAS2024
0
1
3
@assolini
Fabio Assolini
1 year
@suidpit rocking at #TheSAS2024 stage, talking about macOS sandboxing escape
0
1
4
@ShielderSec
Shielder
1 year
Attending @TheSAScon in the beautiful Bali🏝️? Make sure not to miss @suidpit's talk about his novel research on the macOS 🍎 sandbox and how to bypass it. πŸ—“οΈ Wednesday, October 23 - 15:10
0
5
15