Offensively Defensive Continuous Developer #TryHarder

Joined June 2018
1 Photos and videos
rezaduty retweeted
Stop Googling cybersecurity skills. 499 infosec skills, structured paths, career mapping; all in one place. This is how you actually learn. career.hadess.io #infosec #job #career
1
1
16
2,395
rezaduty retweeted
Continuous Delivery Security Labs 2026 open.substack.com/pub/devsecโ€ฆ ๐Ÿ”ฅ Start engineering your career โ†’ career.hadess.io #githubactions #argocd #devsecops #devops #cd #github
3
24
379
rezaduty retweeted
Cybersecurity Career Coach that Turns Rookies into Pros. After 7 years creating content and collaborating with top security engineers & researchers, we've seen the same gaps over and over: How to actually start and How to keep growing we built: career.hadess.io #job
2
1
3
185
rezaduty retweeted
CVE-2025-9959: smolagents Python Sandbox Escape hazardlab.substack.com/publiโ€ฆ Python sandbox implementations often focus on blocking dangerous attribute access patterns like `obj.__class__` but forget that the same introspection is achievable through method invocation. #python #cve
3
7
1,105
rezaduty retweeted
25 Nov 2025
Last Friday at @BlackAlpsConf 2025, @noraj_rawsec explored the hidden security challenges of #Unicode ๐ŸŽค With 1,000 pages of specs, even small mistakes can become attack vectors. Dive into the details ๐Ÿ‘‰ synacktiv.com/ressources%3โ€ฆ
4
16
2,372
rezaduty retweeted
27 Sep 2025
Iโ€™ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. Iโ€™ve earned around $500k in bounties and was on the road to $1M. Yet I donโ€™t even have HSM, and I feel I havenโ€™t been recognized as I should 1/4
Replying to @Hacker0x01
@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.
40
126
796
257,980
rezaduty retweeted
๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐˜† ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ป ๐—ฅ๐—ฒ๐—ฎ๐—นโ€๐—ง๐—ถ๐—บ๐—ฒ ๐—–๐—ผ๐—บ๐—บ๐˜‚๐—ป๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป โ€” ๐—”๐˜๐˜๐—ฎ๐—ฐ๐—ธ & ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐˜€๐—ฒ ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ open.substack.com/pub/devsecโ€ฆ Donald ๐Ÿ‘ฑโ€โ™‚๏ธ, a developer and chaos wrangler, watched PacketPete, our mischievous red-teamer, go wild on his real-time stack ๐Ÿ‘‡
1
3
6
344
rezaduty retweeted
NEED YOUR HELP! My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,... but companies keep saying: "we aren't hiring right now!" if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team you're retweet is Extremely appreciated โค๏ธโ€๐Ÿ”ฅ soroush, if you see this, don't hate me, had to do it without telling you
12
120
247
82,888
rezaduty retweeted
๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐˜† ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ป - ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—™๐—ถ๐—น๐—ฒ ๐— ๐—ฎ๐—ป๐—ฎ๐—ด๐—ฒ๐—บ๐—ฒ๐—ป๐˜ open.substack.com/pub/devsecโ€ฆ Syd, a senior Spring developer, trusted her file upload service with basic extension validation. "Only .pdf and .jpg files allowed," she thought. #appsec #devsecops
3
10
417
rezaduty retweeted
Say hello to Eternal Tux๐Ÿง, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130) willsroot.io/2025/09/ksmbd-0โ€ฆ Cheers to @u1f383 for finding these CVEs the OffensiveCon talk from gteissier & @laomaiweng for inspiration!
11
199
754
81,685
rezaduty retweeted
Secure by Design Frontend Security open.substack.com/pub/devsecโ€ฆ Imagine Frontend used dangerouslySetInnerHTML to render user comments without sanitization. An attacker crafted malicious JavaScript that stole authentication tokens from other users' browsers. Learn more ๐Ÿ‘‡
1
3
6
427
rezaduty retweeted
๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น ๐— ๐—ถ๐—ฑ๐—ฑ๐—น๐—ฒ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ open.substack.com/pub/devsecโ€ฆ Imagine zero trust applied only to north-south traffic. East-west service calls trusted cluster networks implicitly. Learn more ๐Ÿ‘‡
1
6
10
478
rezaduty retweeted
๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐˜† ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ป - ๐—ช๐—ฒ๐—ฏ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ถ๐—ฐ๐—ฒ & ๐—”๐—ฃ๐—œ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜†ย  open.substack.com/pub/devsecโ€ฆ The panic began. It wasn't the new API. Learn more ๐Ÿ‘‡
2
4
19
1,169
rezaduty retweeted
๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ฏ๐˜† ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ปย - ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป open.substack.com/pub/devsecโ€ฆ #appsec #authentication #identity #security #devsecops #bugbountytips #oauth #oidc
1
5
13
467
rezaduty retweeted
Behavioral Intelligence - BEHINT Ever heard of stealing conversations from a lightbulb? turning desk lamp vibrations into crystal-clear audio. Pure side-channel magic from Ben-Gurion's mad scientists. full analysis: open.substack.com/pub/redteaโ€ฆ #osint #redteam #ai #behint
1
5
17
1,819
rezaduty retweeted
5
14
1,397
rezaduty retweeted
๐—”๐—ช๐—ฆ ๐—ฃ๐—ฟ๐—ผ๐—ฎ๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฐ๐—ฒ: ๐—ง๐—ต๐—ฒ ๐—”๐—ฟ๐˜ ๐—ผ๐—ณ ๐—ช๐—ฎ๐—ฟ ๐—ถ๐—ป ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† open.substack.com/pub/devsecโ€ฆ #aws #cloud #redteam #devops #devsecops
2
5
305
rezaduty retweeted
AI For OSINT - Texture Intelligence Read the full analysis: lnkd.in/dYakXZSf The Pentagon leaks weren't solved by cyber forensicsโ€”they were cracked by GRANITE PATTERNS. #ai #osint #redteam #pytorch #generativeai
9
15
1,419
rezaduty retweeted
๐—–๐—ผ๐—ป๐˜๐—ฎ๐—ถ๐—ป๐—ฒ๐—ฟ ๐—ข๐—ฆ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ open.substack.com/pub/devsecโ€ฆ Maya ๐Ÿ‘ฉโ€๐Ÿ’ป was about to docker pull redis:latest when her security scanner screamed - the image contained 47 critical vulnerabilities and suspicious network activity! #devops #devsecops #containers
1
5
17
1,239