rezaduty retweeted
rezaduty
401 posts

rezaduty
@rezaduty
Offensively Defensive Continuous Developer #TryHarder
Joined Haziran 2018
495 Following1K Followers
rezaduty retweeted

Continuous Delivery Security Labs 2026
open.substack.com/pub/devsecopsgโฆ
๐ฅ Start engineering your career โ career.hadess.io
#githubactions #argocd #devsecops #devops #cd #github

English
rezaduty retweeted

Cybersecurity Career Coach that Turns Rookies into Pros.
After 7+ years creating content and collaborating with top security engineers & researchers, we've seen the same gaps over and over:
How to actually start and How to keep growing
we built: career.hadess.io
#job

English
rezaduty retweeted

CVE-2025-9959: smolagents Python Sandbox Escape
hazardlab.substack.com/publish/post/1โฆ
Python sandbox implementations often focus on blocking dangerous attribute access patterns like `obj.__class__` but forget that the same introspection is achievable through method invocation.
#python #cve

English
rezaduty retweeted

Last Friday at @BlackAlpsConf 2025, @noraj_rawsec explored the hidden security challenges of #Unicode ๐ค
With 1,000+ pages of specs, even small mistakes can become attack vectors.
Dive into the details ๐ synacktiv.com/ressources%253โฆ

English
rezaduty retweeted

Iโve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. Iโve earned around $500k in bounties and was on the road to $1M. Yet I donโt even have HSM, and I feel I havenโt been recognized as I should 1/4

Youssef Sammouda (sam0)@samm0uda
@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.
English
rezaduty retweeted

๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฏ๐ ๐๐ฒ๐๐ถ๐ด๐ป ๐ฅ๐ฒ๐ฎ๐นโ๐ง๐ถ๐บ๐ฒ ๐๐ผ๐บ๐บ๐๐ป๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป โ ๐๐๐๐ฎ๐ฐ๐ธ & ๐๐ฒ๐ณ๐ฒ๐ป๐๐ฒ ๐ฃ๐น๐ฎ๐๐ฏ๐ผ๐ผ๐ธ
open.substack.com/pub/devsecopsgโฆ
Donald ๐ฑโโ๏ธ, a developer and chaos wrangler, watched PacketPete, our mischievous red-teamer, go wild on his real-time stack ๐

English
rezaduty retweeted

NEED YOUR HELP!
My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,...
but companies keep saying:
"we aren't hiring right now!"
if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team
you're retweet is Extremely appreciated โค๏ธโ๐ฅ
soroush, if you see this, don't hate me, had to do it without telling you
English
rezaduty retweeted

๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฏ๐ ๐๐ฒ๐๐ถ๐ด๐ป - ๐๐
๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐๐ถ๐น๐ฒ ๐ ๐ฎ๐ป๐ฎ๐ด๐ฒ๐บ๐ฒ๐ป๐
open.substack.com/pub/devsecopsgโฆ
Syd, a senior Spring developer, trusted her file upload service with basic extension validation. "Only .pdf and .jpg files allowed," she thought.
#appsec #devsecops

English
rezaduty retweeted

Say hello to Eternal Tux๐ง, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130)
willsroot.io/2025/09/ksmbd-โฆ
Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration!
English
rezaduty retweeted

Secure by Design Frontend Security
open.substack.com/pub/devsecopsgโฆ
Imagine Frontend used dangerouslySetInnerHTML to render user comments without sanitization. An attacker crafted malicious JavaScript that stole authentication tokens from other users' browsers.
Learn more ๐

English
rezaduty retweeted

๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ๐ป๐๐ฟ๐ผ๐น ๐ ๐ถ๐ฑ๐ฑ๐น๐ฒ๐๐ฎ๐ฟ๐ฒ ๐ฃ๐น๐ฎ๐๐ฏ๐ผ๐ผ๐ธ
open.substack.com/pub/devsecopsgโฆ
Imagine zero trust applied only to north-south traffic. East-west service calls trusted cluster networks implicitly.
Learn more ๐

English
rezaduty retweeted

๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฏ๐ ๐๐ฒ๐๐ถ๐ด๐ป - ๐ช๐ฒ๐ฏ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ & ๐๐ฃ๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ย
open.substack.com/pub/devsecopsgโฆ
The panic began. It wasn't the new API. Learn more ๐

English
rezaduty retweeted

๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฏ๐ ๐๐ฒ๐๐ถ๐ด๐ปย - ๐๐๐๐ต๐ฒ๐ป๐๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป
open.substack.com/pub/devsecopsgโฆ
#appsec #authentication #identity #security #devsecops #bugbountytips #oauth #oidc

English
rezaduty retweeted

Behavioral Intelligence - BEHINT
Ever heard of stealing conversations from a lightbulb? turning desk lamp vibrations into crystal-clear audio. Pure side-channel magic from Ben-Gurion's mad scientists.
full analysis: open.substack.com/pub/redteamguiโฆ
#osint #redteam #ai #behint

English
rezaduty retweeted

Java Spring Bug Hunter's Secure Coding Playbook
open.substack.com/pub/devsecopsgโฆ
#appsec #java #productsecurity #spring #springsecurity #devops #devsecops #bugbountytips

English
rezaduty retweeted

๐๐ช๐ฆ ๐ฃ๐ฟ๐ผ๐ฎ๐ฐ๐๐ถ๐๐ฒ ๐๐ฒ๐ณ๐ฒ๐ป๐ฐ๐ฒ: ๐ง๐ต๐ฒ ๐๐ฟ๐ ๐ผ๐ณ ๐ช๐ฎ๐ฟ ๐ถ๐ป ๐๐น๐ผ๐๐ฑ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐
open.substack.com/pub/devsecopsgโฆ
#aws #cloud #redteam #devops #devsecops

English
rezaduty retweeted

AI For OSINT - Texture Intelligence
Read the full analysis: lnkd.in/dYakXZSf
The Pentagon leaks weren't solved by cyber forensicsโthey were cracked by GRANITE PATTERNS.
#ai #osint #redteam #pytorch #generativeai

English
rezaduty retweeted

๐๐ผ๐ป๐๐ฎ๐ถ๐ป๐ฒ๐ฟ ๐ข๐ฆ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฃ๐น๐ฎ๐๐ฏ๐ผ๐ผ๐ธ
open.substack.com/pub/devsecopsgโฆ
Maya ๐ฉโ๐ป was about to docker pull redis:latest when her security scanner screamed - the image contained 47 critical vulnerabilities and suspicious network activity!
#devops #devsecops #containers

English
rezaduty retweeted

Container Attack & Defend
open.substack.com/pub/devsecopsgโฆ
#container #devops #devsecops #redteam #eks #kubernetes #docker

English