ShiRake
10.5K posts


The best conversations at @defcon never happen at DEF CON. They happen in a hallway with people who found each other by accident. So we're skipping to that part. On August 7, @HacktronAI and @osec_io are putting one private dinner together in Vegas. No pitches or slides. Just good food, a strong technical crowd and conversations a conference floor makes impossible. At the table: top bug bounty hunters, CTF players, and security leaders worth knowing. Friday, August 7 · 6:30 PM @ Las Vegas. Seats are limited and by request. If you're in town, tell us a bit about yourself. Link in comments.

Today, we’re releasing rCTF v2, an open-source platform for hosting cybersecurity capture-the-flag competitions.








🚀 We open-sourced Sighthound today. Sighthound is a Rust-based static vulnerability scanner for source code. It runs locally or in CI, uses Tree-sitter parsers, and supports pattern-based detection plus taint flow analysis. It also comes with all it's rulesets with no paid account or signup needed. github.com/Corgea/Sightho… Why build another static scanner in 2026? Semgrep and OpenGrep are useful, but we kept running into a few constraints: the OCaml core raises the contribution bar for many developers, adding language support is not as simple as we wanted, and some higher-signal rule content in the ecosystem sits behind accounts or paid offerings. We wanted something fast, inspectable, easy to extend, and fully open. A few implementation details: - Rust binary for local and CI use - Tree-sitter parsing - Pattern matching and taint analysis by default - Cross-file taint propagation and dependency tracking - Parallel file discovery and scanning - Text, JSON, and CSV output - Rules written in RON and deserialized into typed Rust structs/enums - MIT licensed Current support includes Python, JS/TS, Java, Go, C#, HTML, PHP and Ruby. It focuses on source-code vulnerability classes like command injection, SQL injection, XSS, path traversal, code injection, unsafe deserialization, and crypto issues. It is not a secrets scanner. We're still have a lot of work to getting to where we want it to be so, we would love the community to test it, break it, report issues, and tell us where it falls short. PRs for rules, language support, fixtures, and false-positive tuning are very welcome.

We're launching a $100,000 fund to save CTFs.


RAM prices so bad I might pivot into gardening









