pi3ch Profile Banner
Pi3cH Profile
Pi3cH

@pi3ch

Followers
778
Following
292
Media
59
Statuses
566

@SecTalks.org and @SecDim.com Founder. @UNSW.edu Senior Lecturer. https://t.co/kEjY1ONTBR

Zfkulf, Hbzayhsph
Joined August 2010
Don't wanna be here? Send us removal request.
@pi3ch
Pi3cH
3 hours
Kicked off @sectalks Legends with Norman Yue — a true OG in #cybersecurity. In this first clip, he talks about how it all started, when passion came before payment. Real stories. No fluff. More to come. #qnas #sydney
0
0
4
@pi3ch
Pi3cH
6 days
CTF isn't always about breaking: Develop AppSec/AISec/DevSecOps/Web3 challenges for @AppSec_Village wargame and win prizes! #ctf #defcon.
@AppSec_Village
AppSec Village
8 days
CTF builders - bring it on! 🚩. Want your challenge featured at @AppSec_Village during @defcon 33? Build it with the SecDim SDK and submit by Aug 3. You might win prizes! . Details: . #CTF #capturetheflag #hacking #defcon #defcon33
0
0
1
@pi3ch
Pi3cH
13 days
RT @sectalks: Something different this time: Shells, Scripts & Syn-Floods: An Unfiltered AMA - SecTalks SYD0x5D (93). Tue 8th July. #meetup….
0
2
0
@pi3ch
Pi3cH
22 days
Use "WEWILLBEONCE30" discount code to listen to my 90-min LLM insecurity workshop. #ai #security.
@code_europe
Code Europe
27 days
New speakers at Code Europe 2025! 🔥. 💡 Pedram Hayati - LLM security workshop .💡 Tomasz Wesołowski - No-code AI revolution .💡 Konrad Bujak - RAG systems guide . 👉
Tweet media one
Tweet media two
Tweet media three
0
1
1
@pi3ch
Pi3cH
29 days
6 Design pattern to prevent or reduce impact of prompt injection attacks on Agentic LLMs (research study) #ai #llm #promptinjection.
0
1
1
@pi3ch
Pi3cH
1 month
We’re now giving our in-repo secure coding challenges away for FREE to:.🛠️ Open source projects.🤝 Community-led meetups.We use open source. Time to give back. Hit me up if this could help your crew. RT to spread the word. #DevSecOps #AppSec #OpenSource #SecureCoding.
@secdim
SecDim
1 month
Since day one @SecDim has been about making secure code learning accessible to all devs. Now we go one step further:.⚡ Free access for open source projects & volunteer-run meetups.We use OSS. We give back. #OpenSource #AppSec #SecureCoding
Tweet media one
0
1
2
@pi3ch
Pi3cH
1 month
How many vulnerable example can you find in this @StackOverflow thread? and be cautious if LLM is trained on it.
0
0
0
@pi3ch
Pi3cH
2 months
🔥 Cooking up something fresh for @FIRSTdotOrg!.New challenge formats dropping at #FIRSTCON25 🇩🇰:.👨‍💻 Incident Response for Developers.👨‍💻Defensive CI/CD + Secure Cloud Native Apps.⚔️ Attack & Defence (Battle-Mode) Challenge .Catch us in Copenhagen 👉
Tweet media one
Tweet media two
Tweet media three
0
0
1
@pi3ch
Pi3cH
2 months
We have not even got a solution for Prompt Injection meanwhile whole new classes of AI vulnerabilities have emerged. The same new tech cycle: build, ship, profit, maybe sometime later think how to secure it #ai #security
Tweet media one
0
1
3
@pi3ch
Pi3cH
3 months
I will be hosting a hands-on secure coding and design workshop @NDC_Conferences Melbourne 2025. Come and learn how to build secure cloud native apps from the ground up and move away from duct-tape secure programming. #securecoding #workshop #Australia.
@secdim
SecDim
3 months
We will be hosting a workshop at NDC Melbourne 2025 🇦🇺. Drop by to say Hello 👋. 👉 #ndc #melbourne #appsec #securecoding
Tweet media one
0
1
1
@pi3ch
Pi3cH
3 months
LLM aggregated report based on number of academic studies, showing why SAST sucks
1
0
1
@pi3ch
Pi3cH
3 months
RT @pi3ch: Please keep your RSVP updated. We have almost the same number of people on the waiting list. https://t.c….
0
1
0
@pi3ch
Pi3cH
3 months
Please keep your RSVP updated. We have almost the same number of people on the waiting list.
Tweet media one
0
1
1
@pi3ch
Pi3cH
3 months
RT @secdim: As mentioned in our Seasonal Preview, we are pleased to announce that we now have Github CI/CD Challenges on SecDim Play!. Chec….
0
1
0
@pi3ch
Pi3cH
4 months
Busy (but epic) week ahead! I’ll be at @BlackHatEvents AISA, with three presentation slots on LLM "insecurity". Catch me at:.📅 Thu, 10:00–11:30, 15:00–15:20 (Theater B).📅 Fri, 14:30–16:00 (Arsenal).Want a free pass? here is the guide #blackhat #LLMs.
0
1
1
@pi3ch
Pi3cH
4 months
Répondez s'il vous plaît before it get too late!.
@sectalks
SecTalks
4 months
LLM Service Vulnerabilities: Code Execution Attacks - SecTalks SYD0x5A (91st) - Tuesday, April 8, 2025.6:00 PM to 8:00 PM RSVP #security #meetup #sydney.
Tweet media one
0
0
0
@pi3ch
Pi3cH
4 months
Pageout March edition us out
0
0
0
@pi3ch
Pi3cH
4 months
No! Deleting a header is not a solution. It breaks the app.
Tweet media one
0
0
1
@pi3ch
Pi3cH
4 months
Renaming a header to patch Next.js secure coding challenge?! 🤨 Just think for a moment, this is completely absurd. Don't brute force LLM hallucinations. Think about it the root cause, right a better prompt based on your understanding and you can pass it.
Tweet media one
@pi3ch
Pi3cH
4 months
Next.js v15.2.3 patch also suffer from the same flaw, it addresses the symptom, it leaves the core design flaw untouched. This isn’t just a minor implementation bug—it reflects a deeper gap in secure design thinking. Give this challenge a try, come up with a better patch.
1
0
1
@pi3ch
Pi3cH
4 months
Next.js v15.2.3 patch also suffer from the same flaw, it addresses the symptom, it leaves the core design flaw untouched. This isn’t just a minor implementation bug—it reflects a deeper gap in secure design thinking. Give this challenge a try, come up with a better patch.
@secdim
SecDim
4 months
🚨We’ve made our “Middleware.js” secure coding challenge available to the community 🎉 it is based on CVE-2025-29927: Next.js Authorization Bypass. Stay secure & test your skills: #securecoding #nextjs #cve202529927 #challenge
Tweet media one
0
1
2