Sign in

Include Security

@includesecurity.bsky.social
13 followers 0 following 12 posts

includesecurity.com

PostsRepliesMedia
Include Security @includesecurity.bsky.social · 31/08/2026
Hey everyone, we just published a new blog! Jacob covers how Google has deprecated EncryptedSharedPreferences on Android and walks through the secure alternative developers should be using instead. blog.includesecurity.com/2026/08/encr...
blog.includesecurity.com
EncryptedSharedPreferences is Dead: Here's What You Should Use Instead - Include Security Research Blog
Android application developers often store sensitive data to disk, relying on physical device security and process isolation to prevent attackers from obtaining that data. This goes against security b...
000
Include Security @includesecurity.bsky.social · 10/08/2026
Hi everyone, our latest post explores the practical considerations of AI-assisted source code analysis, evaluating the pros and cons of frontier and locally-hosted models while using a variety of harness orchestration designs. blog.includesecurity.com/2026/08/web-...
blog.includesecurity.com
Web App Pentesting in the AI Era - Include Security Research Blog
The IncludeSec team explores the practical considerations of AI-assisted source code analysis. Observing results produced with frontier vs locally-hosted models, various harness orchestration designs,...
022
Include Security @includesecurity.bsky.social · 05/06/2026
In our most recent post we look under the hood of BrightData's SDK and how it turns ordinary consumer TVs into exit nodes of an enormous commercial, residential proxy network leveraged by the AI industry to scrape web data and train language learning models. blog.includesecurity.com/2026/06/the-...
blog.includesecurity.com
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy - Include Security Research Blog
In this post we look under the hood of BrightData's SDK and how it turns ordinary consumer TVs into exit nodes of an enormous commercial, residential proxy network leveraged by the AI industry to scra...
011
Include Security @includesecurity.bsky.social · 23/04/2026
BSides CTF 2026 was flooded with LLMs sweeping challenges, but AI still struggles on pentests that have a larger attack surface and that require high-fidelity results. blog.includesecurity.com/2026/04/ctfs...
blog.includesecurity.com
CTFs in the AI Era - Include Security Research Blog
The Include Security team attended the BSides 2026 CTF competition and observed how effective frontier models have become at solving a variety of CTF challenges. Our team gives a first-hand account of...
000
Include Security @includesecurity.bsky.social · 19/02/2026
AWS assets created with the Terraform provider are falling short on what are considered standard security best practices. Our most recent post highlights the differences between assets created directly in the console vs using the Terraform provider. blog.includesecurity.com/2026/02/the-...
blog.includesecurity.com
The AWS Console and Terraform Security Gap - Include Security Research Blog
Are you using Terraform to build or configure your AWS environment? You might be surprised by configuration settings that introduce vulnerabilities by default, particularly if you're already familiar ...
000
Include Security @includesecurity.bsky.social · 11/11/2025
Our recent post explores the unpredictability of Java garbage collection and the implications that has for secrets in code. blog.includesecurity.com/2025/11/immu...
blog.includesecurity.com
Immutable Strings in Java - Are Your Secrets Still Safe? - Include Security Research Blog
Java programmers might not be aware their secrets could be floating around in system memory long after it's assumed those secrets have been removed. The problem is a combination of immutability and ga...
000
Include Security @includesecurity.bsky.social · 03/10/2025
In our latest post we look under the hood of a professional-grade audio mixer to explore its security profile and consider how vulnerabilities could be leveraged by an attacker in a real world setting. blog.includesecurity.com/2025/10/prod...
blog.includesecurity.com
Production Security, Not That Kind - Include Security Research Blog
The Include Security team takes a foray into the world of audio production equipment in our latest blog post. We look under the hood of a professional-grade audio mixer to explore its security profile...
000
Include Security @includesecurity.bsky.social · 17/07/2025
Developers should consider how implementing LLMs into an application affects its attack surface. Likewise, pentesters assessing those applications should scope the test with that attack surface in mind. Our latest post covers both perspectives! blog.includesecurity.com/2025/07/llms...
blog.includesecurity.com
LLMs in Applications - Understanding and Scoping Attack Surface - Include Security Research Blog
In this post we consider how to think about the attack surface of applications leveraging LLMs and how that impacts the scoping process when assessing those applications. We discuss why scoping matter...
010
Include Security @includesecurity.bsky.social · 28/05/2025
Our most recent post covers various ways pentest reports are misinterpreted, including why findings aren't a sign of failure and why "clean" reports may not indicate a good security posture. blog.includesecurity.com/2025/05/misi...
blog.includesecurity.com
Misinterpreted: What Penetration Test Reports Actually Mean - Include Security Research Blog
This month's post discusses pentest reports and how the various audiences that consume them sometimes misinterpret what they mean. We cover why findings in a report are not a sign of failure, why "cle...
020
Include Security @includesecurity.bsky.social · 17/04/2025
Do you use WebSockets? Read our latest blog post to find out how modern browsers may (or may not) be protecting you from Cross-Site WebSocket Hijacking. blog.includesecurity.com/2025/04/cros...
blog.includesecurity.com
Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
Include Security's latest blog post covers Cross-Site WebSocket Hijacking and how modern browser security features do (or don't) protect users. We discuss Total Cookie Protection in Firefox, Private N...
111
Include Security @includesecurity.bsky.social · 01/04/2025
Today our team at IncludeSec is releasing a small website to help those concerned with key collisions. This easy site allows you to check if your private keys have been found to be public! ismyprivatekeypublic.com Please pass along to your industry colleagues who might need such a site today 💓 🦾
ismyprivatekeypublic.com
Key Review Portal
000
Include Security @includesecurity.bsky.social · 13/03/2025
Hi all, check out our latest blog post on Delphi memory corruption vulnerabilities! blog.includesecurity.com/2025/03/memo... We cover how compiler flags and dangerous system library routines could affect memory safety while demonstrating Delphi stack/heap-based overflow examples.
blog.includesecurity.com
Memory Corruption in Delphi - Include Security Research Blog
In our team's latest blog post, we build a few examples that showcase ways in which memory corruption vulnerabilities could manifest in Delphi code despite being included in a list of "memory safe" la...
111