Doyensec @doyensec.bsky.social · 24/09/2026One tap was enough to bypass a Chrome for iOS security check. We found a way to use shortcuts to reach tel: or facetime: w/o Chrome applying its normal user-interaction checks. The issue, CVE-2026-13795, has been fixed. Details 👇 blog.doyensec.com/2026/09/24/c... #appsec #doyensec #security #ios 010
Doyensec @doyensec.bsky.social · 23/09/2026Come join our co-founder Luca Carettoni at #BEX Thursday 9/24 at the Rimini Expo Center 🇮🇹! He'll be available to chat about the cool projects we've done for helping to secure the space industry and the final frontier 🖖! www.bex-expo.space/en #appsec #doyensec #security 000
Doyensec @doyensec.bsky.social · 18/09/2026The skb that wasn’t freed - the Fragnesia primitive via Open vSwitch. #Doyensec found a local priv. esc. affecting default Arch, Fedora, Debian, Amazon #Linux & RHEL. Read how a missing flag allows an unprivileged user to gain root access. blog.doyensec.com/2026/09/17/o... #appsec #security 000
Doyensec @doyensec.bsky.social · 11/09/2026We originally published details of a OnePlus Android vuln after the vendor became unresponsive & 9+ months had passed w/o resolution of what appeared to be a straightforward bug. Only after publication did the vendor contact us again & request that we remove the post. #appsec #doyensec #security 111
Doyensec @doyensec.bsky.social · 18/08/2026“We were expecting the engagement to be a lot more time-consuming for us. … impressed with how independent you work and yet how deep you still go.” On the report: “Looks great and super comprehensive.” - Nuno Ferreira/Mintt Studio 👏 Exactly what we 🎯: low overhead, deep tech work & great results. 000
Doyensec @doyensec.bsky.social · 30/07/2026"You don't need pentesters anymore." - Every hype cycle, ever. While the AI debate continues in Vegas, we'll be finding the bugs it missed and proving which were never real in the first place. Happy Black Hat & DEFCON! #BlackHat #DEFCON #AppSec #CyberSecurity #HackerSummerCamp #doyensec #security 020
Doyensec @doyensec.bsky.social · 28/07/2026🇫🇷 Un petit bug with a big impact! A vuln reported by Doyensec's French team members in #Electron 's shell.openPath() is now patched. String-only path validation could be tricked into opening a different file via a null byte. github.com/electron/ele... #doyensec #appsec #security #electronjs 000
Doyensec @doyensec.bsky.social · 23/07/2026Hey pentesters 📢, maSSO just leveled up with Duo Mode & Signer Tab. Duo Mode: spin up two independent IdPs w/ one dashboard. Does your target's SP actually keep "Org A" and "Org B" separate? Now you can bring up the malicious IdPs in one command. github.com/doyensec/maSSO youtu.be/cHwUKgk2LQ8 100
Doyensec @doyensec.bsky.social · 09/07/2026Pentesters 📣 make your lives easier with maSSO - a weaponized SSO Identity Provider for security testing of OIDC & SAML 2.0 Service Providers. The IdP your target trusts - that you fully control. Intercept, edit, re-sign 👇 github.com/doyensec/maSSO #doyensec #appsec #security youtu.be/FGK2iKetesgyoutu.bemaSSO DemoYouTube video by Doyensec 000
Doyensec @doyensec.bsky.social · 08/07/2026Celebrating a big milestone for Matei Buzdea & Luca Molteni, as they've transitioned from #interns to full-time #security consultants! 🎉 From day one, they've shown curiosity, skill, & a passion for #appsec. Helping people develop is something we're proud of. On to the next chapter. 🚀 #doyensec 000
Doyensec @doyensec.bsky.social · 02/07/2026The @doyensec.bsky.social team had an amazing time at our retreat in Porto Portugal 🇵🇹! Festa de São João was a blast, along w/ kayaking, a vineyard tour & wine tasting, a vibe coding hackathon & getting to spend time with great people! We can't wait for the next one!! #doyensec #appsec #security 000
Doyensec @doyensec.bsky.social · 29/06/2026After our whitepaper (blog.doyensec.com/2026/05/27/a...) comparing Aikido & XBOW, we evaluated our own AI-assisted testing workflow against one of the targets. Beyond rediscovering the previously reported & fixed issues, the workflow identified 2 more vulnerabilities: #doyensec #appsec #security 100
Doyensec @doyensec.bsky.social · 17/06/2026New from #Doyensec's Savio Sisco - 🚀 Session Switcher for #burpsuite makes manual auth testing faster - now easily save & swap cookies/headers Quickly test IDORs & authZ issues, plus session auto-update rules that track live browser sessions blog.doyensec.com/2026/06/17/s... #security #appsec 000
Doyensec @doyensec.bsky.social · 09/06/2026Who needs a podcast? 🎧 🤯 Now you can watch 10+ hours of curated Doyensec presentations in our YouTube playlist: www.youtube.com/playlist?lis... Get free access to great security content, and if you enjoy it, give us a like! 👍 #doyensec #appsec #securityyoutube.comDoyensec Team Presentations - YouTube 000
Doyensec @doyensec.bsky.social · 05/06/2026🥳 If you missed it live, you can now watch our Szymon Drosdzol's presentation, API Productivity by Design: How Architecture Antipatterns Break Security and Your Sprint, from DevWorld on line. youtu.be/T5YlO5_u2U0?... #doyensec #appsec #Security #devworldyoutu.beSzymon Drosdzol - API Productivity by DesignYouTube video by Devworld Conference 000
Doyensec @doyensec.bsky.social · 04/06/2026🚨Released a #security update for #safeurl addressing an #SSRF bypass in non-default configs, affecting those with IPv6 support enabled. A fix was released within ~12 hours of report. Upgrade to version 0.2.4: github.com/doyensec/saf... Thanks to tonghuaroot for the report! #doyensec #appsecgithub.comMissing IPv6 CIDR Ranges in BlocklistThe `privateNetworks` blocklist was found to be missing newly added CIDR ranges. More specifically, the following CIDR ranges were not being blocked: - `64:ff9b:1::/48`: NAT64 local-use prefix (RF... 010
Doyensec @doyensec.bsky.social · 28/05/2026Proud to share that Doyensec was trusted by Anthropic as one of the security partners validating #Mythos findings as part of Project #Glasswing! Contact us today to see how our research-driven approach shapes the future of #appsec! www.anthropic.com/research/gla... #doyensec #security #aianthropic.comProject Glasswing: An initial updateAn early update on what we've learned from Project Glasswing. 000
Doyensec @doyensec.bsky.social · 27/05/2026🤖 Just released - our latest whitepaper comparing the AI-powered penetration testing platforms from Aikido & XBOW. Read how each platform approaches automated security testing, detection, workflows, and usability. See the results 👇 blog.doyensec.com/2026/05/27/a... #ai #appsec #doyensec #security 020
Doyensec @doyensec.bsky.social · 26/05/2026Our new post shows how #AWS ELBs break #security boundaries via rule shadowing, CloudFront/WAF bypasses, & alternate routing. 📢 Plus ELBaph - a new tool to map routing graphs, detect exposed paths & find attack chains across ALBs/NLBs blog.doyensec.com/2026/05/25/c... #AppSec #Doyensec #cloudsec 000
Doyensec @doyensec.bsky.social · 19/05/2026After uncovering memory bugs in NASA’s CFITSIO, we looked at turning its *documented* features into attack primitives. Check out the blog post for details & a newly released Docker playground to reproduce the demos locally. #AppSec #doyensec #security blog.doyensec.com/2026/05/19/c... 000
Doyensec @doyensec.bsky.social · 14/05/2026While we're happy for our prize and that our exploit targeting OpenAI's Codex in the Coding Agent category was successful at #PWN2OWN, this was a collision💥 as the bug was previously known to the vendor. Back to the research! #P2OBerlin #doyensec #appsec #security #ai #openai 010
Doyensec @doyensec.bsky.social · 13/05/2026Proud to share that #Doyensec has 3 unpatched 0day submissions for this year's #PWN2OWN - one for each #AI Coding Agent category target & our #OpenAI Codex exploit was selected for the competition! The other vulnerabilities have been reported to the other vendors. #security 261
Doyensec @doyensec.bsky.social · 12/05/2026Read how #Doyensec went beyond the basic #AI & web testing to reshape how our client thinks about risks and how we enabled them to evaluate a previously unknown attack surface. It’s amazing when our passion for #appsec has such a big impact! #security www.unit21.ai/blog/risk-de...unit21.aiRisk Decisions in the Era of AI: What Happens When the Subject Fights Back? - Blog | Unit21 010
Doyensec @doyensec.bsky.social · 11/05/2026Use the Outline wiki? Ensure you have updated to the latest version. The latest coordinated disclosure from our Leonardo Giovannini helped to resolve a stored XSS in the project. Check out the details here: github.com/outline/outl... #doyensec #appsec #security 010
Doyensec @doyensec.bsky.social · 07/05/2026A great day 1 at DEVWorld Amsterdam is in the books! If you're attending on Friday, stop by our booth and let's talk about how Doyensec can help your team Build With Security! #doyensec #appsec #security #devworld 000
Doyensec @doyensec.bsky.social · 06/05/2026Check our Adrian Denkiewicz's talk - When Filenames Become Attack Surfaces: Weaponizing NASA’s CFITSIO Extended Filename Syntax, at BSides Luxembourg 🇱🇺, Thurs at 14:45! pretalx.com/bsidesluxemb... #doyensec #appsec #security #bsides #bsidesluxembourg 010
Doyensec @doyensec.bsky.social · 05/05/2026CloudSecTidbits series is back with a bang! 💥 In the latest edition, we're releasing maSSO - A weaponized Identity Provider (IdP) for security testing! Read all about it and the dangers of Multi-SSO AWS Cognito User Pools. #doyensec #appsec #security blog.doyensec.com/2026/05/05/c... 000
Doyensec @doyensec.bsky.social · 30/04/2026If you're attending DEVWorld Amsterdam 🇳🇱, stop by our booth to say hello! We'd love to chat about your security projects and show how we help teams "Build with Security"! Looking forward to seeing everyone there! #doyensec #appsec #security #DevWorld 000
Doyensec @doyensec.bsky.social · 27/04/2026Join #Doyensec at #DEFCON Singapore 🇸🇬 - Demo Labs! Our Mohamed Ouad & Francesco Lacerenza present CloudSec Tidbits: Breaking “Secure-Looking” Cloud Architectures Real-world cloud/AppSec bugs & labs Details - defcon.org/html/defcon-... 🗓 Tue 14:00 | Wed 12:00 | Thu 13:00 #cloudsec #appsec 000
Doyensec @doyensec.bsky.social · 23/04/2026If you want to ship features faster 🚀, without piling up security debt, make sure to check out our Szymon Drosdzol's presentation at #DevWorld 🇳🇱Amsterdam! Duck Stage 1 - Hall 3, May 7th, 17:00 agenda.devworldconference.com/DevworldConf... #doyensec #appsec #security 000
Doyensec @doyensec.bsky.social · 20/04/2026In our Adrian Denkiewicz's latest post, see how combining AFL++ with GPT-5 Codex sped up triaging the results from fuzzing NASA’s CFITSIO library and uncovered numerous vulnerabilities. blog.doyensec.com/2026/04/20/c... #doyensec #appsec #security #fuzzing 011
Doyensec @doyensec.bsky.social · 01/04/2026Please join us in welcoming **Matei Buzdea** as the newest intern at Doyensec! 🎉 They’re the latest in a long line of talented interns who’ve helped strengthen our team and we’re excited to see what they’ll accomplish. Welcome aboard, Matei! 🔐 #doyensec #appsec #security #internship 000
Doyensec @doyensec.bsky.social · 31/03/2026🚨 Breaking Secure-Looking Cloud Architectures At #defcon Singapore Demo Labs, we'll show real cloud security bugs involving AWS Cognito multi-SSO user pools & ELB routing paths. Including: • Malicious OIDC Server • ELBaph (AWS ELB testing utility) 🔗 defcon.org/html/defcon-... #appsec #doyensec 000
Doyensec @doyensec.bsky.social · 24/03/2026📢 #Doyensec is sponsoring DEV World! We'll be at our booth discussing security research & how to "Build with Security" directly with the #dev community. Stop by - we'd love to chat! 🗓 May 7–8 | 📍 Amsterdam, Netherlands 🇳🇱 devworldconference.com #DevWorld #AppSecdevworldconference.comDEVWorld 2026DEVWorld is The Developer Conference for Tech Team! A 2-day Festival of Tech, connecting amazing tech leaders, developers and companies all under one roof. 000
Doyensec @doyensec.bsky.social · 12/03/2026Did you know you can use #InQL to recreate #GraphQL schema even when the introspection query is disabled? Our Schema Bruteforcer ensures "hidden" doesn't actually mean "off-limits". Find out more at: blog.doyensec.com/2025/12/02/i... github.com/doyensec/inql #doyensec #appsec #security 000
Doyensec @doyensec.bsky.social · 06/03/2026AuthN/Z is always a #security minefield & MCP adds even more complexity with agents, remote servers, and transitive trust. This Teleport-sponsored deep dive breaks down attack vectors & why each authN/Z step is a potential trust boundary. 🔗 blog.doyensec.com/2026/03/05/m... #doyensec #appsec #ai 001
Doyensec @doyensec.bsky.social · 24/02/2026Check out the latest edition of @pagedout.bsky.social featuring Doyensec's own Bartłomiej (Bartek) Górkiewicz vibing on Reversing Python Bytecode, along with plenty of great articles! pagedout.institute/download/Pag... #appsec #doyensec #security #reversing #pagedout 020
Doyensec @doyensec.bsky.social · 19/02/2026Testing APIs? Stop guessing what's running under the hood. Use InQL's Engine Fingerprinter in Burp to identify the #GraphQL stack in seconds and save yourself the trial and error. blog.doyensec.com/2025/12/02/i... github.com/doyensec/inql #doyensec #appsec #inql #security #bugbountytips 010
Doyensec @doyensec.bsky.social · 17/02/2026Introducing SafeUpdater by Michael Pastor - A security-first update framework for Electron apps, built around explicit threat models, integrity and authenticity guarantees, and real attack mitigations. Check it out today! blog.doyensec.com/2026/02/16/e... #AppSec #Electron #doyensec #security 000
Doyensec @doyensec.bsky.social · 05/02/2026If you missed our Szymon Drosdzol's presentation on "API Authorization Antipatterns" at CONFidence (@confidenceconf), or just want to see it again, it's your lucky day! The video is now available here: www.youtube.com/watch?v=Jje2.... Hope you enjoy it! #appsec #doyensec #securityyoutube.comCONFidence 2025: Szymon Drosdzol - API Authorization AntipatternsYouTube video by PROIDEA Events 010
Doyensec @doyensec.bsky.social · 03/02/2026Humans vs. AI? We put them to the test in our new post! We went head-to-head with AI tools to see who would win? Check it out today to see the results! blog.doyensec.com/2026/02/03/o... #appsec #doyensec #outline #aiblog.doyensec.com Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms · Doyensec's Blog Auditing Outline. Firsthand lessons from comparing manual testing and AI security platforms 000
Doyensec @doyensec.bsky.social · 29/01/2026Set your #xss hunting 🎯 on easy mode! In the latest edition of our Eval Villain video series, Dennis Goodlett demonstrates the time-saving power of the "needles" feature. youtu.be/LI9QOuQDduE #appsec #doyensec #bugbountytips #securityyoutu.beEfficient sink mapping with needlesYouTube video by Doyensec 000
Doyensec @doyensec.bsky.social · 27/01/2026🥳Doyensec is proud to announce our sponsorship of the UC Davis Cyber Security Club!💻🔐 We're committed to supporting the next generation of #cybersecurity talent 📚🧗 daviscybersec.org/sponsors/ #appsec #doyensec #infosec #ucdavisdaviscybersec.orgSponsors 000
Doyensec @doyensec.bsky.social · 23/01/2026In our latest blog post, Szymon Drosdzol provides an in-depth walkthrough of using the #frida toolkit to demonstrate the right way to intercept OkHTTP traffic. This is essential knowledge for #android security research! Check it out: blog.doyensec.com/2026/01/22/f... #appsec #doyensec #security 000
Doyensec @doyensec.bsky.social · 19/01/2026🎉 We'd like to welcome our newest intern (and second Luca), Luca Molteni! We're confident he'll be the next amazing engineer to emerge from our proven internship program. 🚀 #appsec #doyensec #security #internship 000
Doyensec @doyensec.bsky.social · 15/01/2026📢Just published - the third video in our series on Eval Villain. Our Dennis Goodlett walks through using it to find 🔎 a DOM XSS to demonstrate its functionality. Check it out today! youtu.be/Hp7TexA6vFg #appsec #doyensec #security #evalvillain #xssyoutu.beSimple DOM XSS with Eval VillainYouTube video by Doyensec 000
Doyensec @doyensec.bsky.social · 08/01/2026In the second post on Eval Villain, @bemodtwz walks through the quick & easy setup and its configuration. Check it out & start finding those client-side vulnerabilities today! youtu.be/-hIA5uLNFck Download: github.com/swoops/eval_... #appsec #doyensec #securityyoutu.beEval Villain InstallationYouTube video by Doyensec 000
Doyensec @doyensec.bsky.social · 19/12/2025🥂🤖 A toast to 9 years of #Doyensec! Nine years of pushing application security forward, breaking things so others don’t, & helping teams build with security from day one. 🍸 Cheers to the bugs we’ve found, the apps we’ve strengthened, & the many secure years still to come. 🎉 001
Doyensec @doyensec.bsky.social · 15/12/2025Happy Holidays everyone!☃️ We’re taking a break next week for our annual shutdown to celebrate another successful year and give our team time to recharge. 🙌 #doyensec #appsec #security 000