
shubs
@infosec_au
Followers
56K
Following
10K
Media
254
Statuses
5K
Co-founder, security researcher. Building an attack surface management platform, @assetnote
halcyon
Joined August 2013
RT @joernchen: Today I have a more serious topic than usual, please consider reposting for reach:. My wife and I are urgently looking for a….
0
111
0
RT @spaceraccoonsec: At @defcon, I presented my research on client-side deanonymization attacks in @Google's Privacy Sandbox! Privacy resea….
spaceraccoon.dev
I recently presented at the DEF CON 33 Mainstage and the 12th Crypto & Privacy Village on weaknesses in implementations of Google’s Privacy Sandbox that subverted privacy protections and enabled...
0
59
0
Today, we're releasing the new Searchlight Cyber (@SLCyberSec) tools website, which allows you to use several of our open-source tools for free via a web interface. You can self-register at (+ all our wordlists will be released there from now on!).
10
78
366
RT @BSidesCbr: KEYNOTE: Not All Vulnerabilities Are The Same.10 years ago, @infosec_au spoke at the first BSidesCbr. Now Australia’s top b….
cfp.bsidescbr.com.au
Over the past seven years, I've had the privilege of building and leading a security research team in Australia, with a focus on web security research, particularly in the context of enterprise...
0
13
0
The @SLCyberSec research team is releasing our final research post for our Christmas in July efforts, two RCEs and one XXE (all pre-auth) in Adobe Experience Manager Forms. One of the RCEs and the XXE still do not have official patches:
slcyber.io
Vulnerabilities in AEM Forms The Searchlight Cyber Research Team discovered and disclosed three critical vulnerabilities in Adobe Experience Manager Forms to Adobe in late April 2025. As of writing...
6
60
224
RT @kevin_mizu: I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Ha….
0
166
0
RT @_l0gg: Blog for ToolShell.Disclaimer: The content of this blog is provided for educational and informational purposes only. https://t.c….
0
82
0
For our third installment of Christmas in July, the @SLCyberSec Research Team is disclosing a critical authentication bypass vulnerability in ETQ Reliance that leads to RCE (CVE-2025-34143). Surprisingly, all you needed was a space to bypass auth.
slcyber.io
Note: In correspondence with Hexagon while disclosing the bugs below, they informed us that any sharing of source code would be considered a violation of their terms and license. The Java code has...
0
26
93
I hope everyone got some rest after @DownUnderCTF this weekend. My colleague @hash_kitten wrote up a blog post on a novel technique for SQL Injection in PDO's prepared statements, required to exploit the “legendary” challenge, which only got one solve:
slcyber.io
Searchlight Cyber's Security Research team details a Novel Technique for SQL Injection in PDO's Prepared Statements.
0
48
237
@Rhynorater @rez0__ Also, the %09 trick used for the AEM XSS was also a really noteworthy thing to highlight, again, really respect that they took the time to understand the broader impact of @hash_kitten's research. I think many people wouldn't have realised how broad it is before their podcast.
0
0
13
@Rhynorater @rez0__ I really appreciated that @Rhynorater identified the DotNetNuke bug as an order-of-operations issue. That's one of my favourite bug classes, and since it's very logical, it can be missed easily for an extended amount of time.
2
0
14
Enjoyed @Rhynorater's and @rez0__ 's takes on our Christmas in July research on the CTBB podcast. Give it a listen for a good summary! We have two more blogs scheduled to publish this month, wrapping up our research push for Christmas in July.
criticalthinkingpodcast.io
Episode 131: In this episode of Critical Thinking - Bug Bounty Podcast we're covering Christmas in July with several banger articles from Searchlight Cyber, as well…
2
6
77
This month's Christmas in July release from @SLCyberSec's Security Research team is a pre-authentication RCE vulnerability in Sawtooth Lighthouse Studio (CVE-2025-34300). This software is prevalent and hidden in plain sight. Read more on our blog:
1
28
131
RT @samwcyo: When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We (@iangcarroll and I) dis….
ian.sh
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We discovered a vulnerability that could allow an attacker to access more than 64 million job...
0
123
0
RT @BSidesCbr: Pre-auth bugs in enterprise software? Yes please. @hash_kitten takes us inside their research on Adobe Experience Manager—un….
cfp.bsidescbr.com.au
Adobe Experience Manager (AEM) is one of the most popular content and digital asset management systems used by enterprises. It’s likely that the home pages of some of the biggest brands you know and...
0
28
0