smaury
@smaury.bsky.social
930 followers 320 following 45 posts
Co-Founder @shielder.com CTF Player jbz.team Cliff Jumping Lover (23mt max so far)
Posts Media Videos Starter Packs
smaury.bsky.social
👋🏿 Hackers!

Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge? @shielder.com is hiring a Red Teaming Lead to join our crew!

More info ⬇️ (share appreciated) #hiring #redteaming
romhack.io/job-opportun...
RomHack - Job opportunities
Check for RomHack sponsor's job opportunities
romhack.io
smaury.bsky.social
Working with folks from @lucasfilm.bsky.social, @ilmvfx.bsky.social, and Apple to secure some of the OSS foundations the movie and entertainment industries rely on was so cool!

Big shout-out 📣 to the @ostifofficial.bsky.social and ASWF for making this possible.
shielder.com
🚨 New Open Source Audit Alert! 🚨

Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX:
🔍 11 issues found (1 critical, 3 still to be published)
✔️ Most fixed, others planned
🗣️ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org

Full details in the blog post ⬇️🧵
Reposted by smaury
tumpicon.org
The TumpiCon experience will start tomorrow!
Can't wait to meet y'all in Pinerolo 🏞️
Schedule is out: tumpicon.org
smaury.bsky.social
Woah - thanks Nestlè and @intigriti.com!
smaury.bsky.social
It's so cool working with the GoogleVRP team - folks over there are amazing.
I love the concept of "you report something, then we work together with you to escalate it as much as possible".
High bounties are also a nice addendum :)
#BugBounty #bugbountytips
smaury.bsky.social
Romhack is coming up and the CfP is still open!
Got novel research you’d love to present in front of an eager audience, with the stunning Roman landscape as your backdrop, and on the same stage where @jameskettle.com will deliver the keynote?
Submit now!
cfp.romhack.io/romhack-2025/
RomHack Conference 2025
Schedule, talks and talk submissions for RomHack Conference 2025
cfp.romhack.io
Reposted by smaury
ostifofficial.bsky.social
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF, @thephpf.bsky.social, and @quarkslab.bsky.social with funding provided by @sovereign.tech. For the report and further links, check out ostif.org/php-audit-co...
smaury.bsky.social
Is there a way I can wipe this from my brain?
Jim Carrey any recommendations?
mobapc.it/prodotto/sha...
Reposted by smaury
tumpicon.org
Just published some talks on tumpicon.org
Wanna join us? Follow the trail 🥾
tumpicon.org
The second edition of TumpiCon is here!
📅 June 27-28, 2025
📍 Somewhere near Turin, Italy
🔒 Invite-only

No flashy stages. No fluff. Just raw, technical, and unfiltered hacking.
More details? If you know, you know.
Follow the trail: tumpicon.org
Reposted by smaury
shielder.com
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox.
Update now and stay tuned for the technical details!
Ref: support.apple.com/en-us/122373
smaury.bsky.social
Woah -- more Google Chrome VRP swag in my mailbox today!

Wondering how to get some yourself? Find vulnerabilities in Chrome!

More info here: bughunters.google.com/about/rules/...
Reposted by smaury
ostifofficial.bsky.social
Our next meetup is a presentation from our friends at X41 D-Sec GmbH. Join us next Wednesday, March 26th, at 14:00 CDT for a presentation and discussion with Markus Vervier and Eric Sesterhenn on their audit of @mullvad.bsky.social. We can't wait for this one! RSVP at lu.ma/wreregye
Security Code Audit of Mullvad VPN · Zoom · Luma
Join us for a presentation and meetup with Markus Vervier and Eric Sesterhenn of X41 D-Sec GmbH around their company's audit of Mullvad VPN. Markus Vervier is…
lu.ma
Reposted by smaury
osservatorionessuno.org
We recently analyzed the latest Cellebrite device support matrix published in February 2025.
The reality is worrisome. It can be used to unlock most of the mobile devices we use every day.

Read our report:
(ENG) osservatorionessuno.org/blog/2025/03...
(ITA) osservatorionessuno.org/it/blog/2025...
A deep dive into Cellebrite: Android support as of February 2025
A deep dive into Cellebrite: Android support as of February 2025
osservatorionessuno.org
smaury.bsky.social
My pixel 7 almost melt down in my hands -- but yes!
smaury.bsky.social
Is this the year of cracking on smartphones?
smaury.bsky.social
Swag day -- thanks ChromeVRP and @amyre.bsky.social
Reposted by smaury
shielder.com
In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
Reposted by smaury
tumpicon.org
Hey hackers!
We’ve started sending out the first invites — check your inbox! 👀
Didn’t get one? Take the fast track and submit a talk!
smaury.bsky.social
🗣️
tumpicon.org
Hey hackers!
We’ve started sending out the first invites — check your inbox! 👀
Didn’t get one? Take the fast track and submit a talk!
smaury.bsky.social
On my way to @fosdem.bsky.social!
If you are into securing open source code then we should definitely have a chat -- looking forward to meeting y'all!
Reposted by smaury
garethheyes.co.uk
Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique.

portswigger.net/research/byp...
GET /%0D%0ASet-Cookie: foo=bar
403 Forbidden

GET /%E4%BC%8D%E4%BC%8ASet-Cookie: foo=bar
200 OK
Set-Cookie: foo=bar
Reposted by smaury
smaury.bsky.social
Love when we can publish the results of our effort!