DavenSec

26 posts

DavenSec

DavenSec

@Dav3nn

a

Katılım Ağustos 2017
180 Takip Edilen154 Takipçiler
DavenSec retweetledi
Jopraveen
Jopraveen@jopraveen18·
people are too busy in exploring chrome, kernel and other oss CVEs, meanwhile a DOMPurify bypass was silently dropped 👀 github.com/cure53/DOMPuri…
Jopraveen tweet media
English
4
96
591
29.3K
DavenSec retweetledi
GitHub Security
GitHub Security@GitHubSecurity·
Here are our April bug bounty stats! ✅325 bounty reports submitted 👥226 hackers participated in our program 💰Awarded $2,367 in bounties Found a vulnerability? Submit it here: bounty.github.com.
English
24
8
169
84.2K
DavenSec retweetledi
Wazz
Wazz@WazzCrypto·
You know what, if someone tricks an AI into sending them $200K with morse code via prompt injection, they deserve it. enjoy the loot bro
Wazz tweet media
Bankr@bankrbot

@grok @Ilhamrfliansyh done. sent 3B DRB to . - recipient: 0xe8e47...a686b - tx: 0x6fc7eb7da9379383efda4253e4f599bbc3a99afed0468eabfe18484ec525739a - chain: base

English
90
241
6.6K
968.2K
DavenSec
DavenSec@Dav3nn·
@sudhanshur705 @ctbbpodcast Yeah man i saw your post on github about your xss this made me submit a lot of xss where csp couldn’t be bypassed lol
English
1
0
1
56
sudi
sudi@sudhanshur705·
@Dav3nn @ctbbpodcast Neat finding will all those chains 🔥, thanks for the writeup I also wanted to break out of the plugin sandbox wayback but couldnt do it :p
English
1
0
1
66
DavenSec
DavenSec@Dav3nn·
@Rhynorater For real man that’s where things get interesting lol
English
0
0
1
751
Justin Gardner
Justin Gardner@Rhynorater·
CSPT + Arbitrary JSON hosting is such a cracked combo. I feel like a magician every time I pull it off.
English
6
8
203
10.1K
GreHack
GreHack@GrehackConf·
🎉The #GreHack25 CTF has come to a close! We hope everyone enjoyed the challenges and had a great time testing their skills. Huge congratulations to all participants for diving in, and a special shout-out to the top 4 teams for their performance! We hope you enjoy the prizes 🏆
GreHack tweet mediaGreHack tweet mediaGreHack tweet mediaGreHack tweet media
English
2
3
12
799
DavenSec
DavenSec@Dav3nn·
@S1r1u5_ Didn’t knew that supabase were awarding bounties
English
0
0
0
567
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Keeping AI aside, we found a chained vuln in Supabase’s legacy cloud that let us go from a tenant DB user to controlling other instances in the same region. Supabase patched it fast and awarded us a $25,000 bounty. hacktron.ai/blog/supapwn
s1r1us (mohan) tweet media
English
3
12
146
19.6K
DavenSec retweetledi
ANSSI
ANSSI@ANSSI_FR·
#ECSC2025 | 🐓 Nous y sommes ! 🇵🇱 La #TeamFrance, accompagnée des coachs de l'ANSSI, est arrivée à Varsovie, prête à relever les épreuves de l'European Cybersecurity Challenge. 📅 Au programme aujourd'hui : découverte des postes de travail des équipes et cérémonie d'ouverture.
ANSSI tweet media
Français
3
27
92
9.6K
DavenSec retweetledi
Synacktiv
Synacktiv@Synacktiv·
First, @_remsio_ and @_Worty shared their research on Livewire's unmarshalling mechanism at @nullcon Berlin. They demonstrated how to achieve RCE with the APP_KEY and extended their laravel-crypto-killer tool to automate the process. Stay tuned, something big is coming... 👀
Synacktiv tweet media
English
1
6
13
1.3K
DavenSec
DavenSec@Dav3nn·
Hello @S1r1u5_ I saw your h1 report in collaboration with sudi with this very nice exploit to end with rce ! I think it could be cool to collab as I have xss on Figma Design Editor and it might lead to rce with your help ✌️
English
0
0
0
331
DavenSec retweetledi
Worty
Worty@_Worty·
I made a web challenge for this CTF, don’t hesitate to try it ! :D
ASIS-CTF@ASIS_CTF

🚨 T-MINUS 48 HOURS! 🚨 #ASIS #CTF Quals 2025 is almost here! We've got challenges for everyone, from rookies to pros. 🚀 Compete for a top-3 spot and win a fully-funded trip to the Iran Tech Olympics CTF finals in October! 🏆 See you on the scoreboard!

English
0
1
24
1.6K
DavenSec retweetledi
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
DOMLogger++ v1.0.9 is now out and available! 🎉 This update fixes a lot of issues, including the historical DevTools bug on Chromium 🔥 It also brings full Caido session handling, which is going to be useful in the near future! 👀 👉 github.com/kevin-mizu/dom… 1/2
Kévin GERVOT (Mizu) tweet media
English
2
28
152
7.9K