Sign in

Marco Squarcina

@minimalblue.bsky.social
945 followers 168 following 39 posts

Senior Scientist @TU Wien / Web & Mobile Security / #drumandbass DJ 🚩 with @mhackeroni.bsky.social We_0wn_Y0u kukhofhackerei Team Austria 🔗 minimalblue.com

PostsRepliesMedia
Marco Squarcina @minimalblue.bsky.social · 03/03/2026
The Austria Cyber Security Challenge #ACSC '26 has started! 🇦🇹 • Qualifications are live 1 March - 1 May • Juniors, Seniors & Open categories • Challenges from Web to Pwn, Crypto, Rev & more • Finale in Linz this September Join us & spread the word 👉 acsc.land
acsc.land
Austria Cyber Security Challenge 2026
010
Marco Squarcina @minimalblue.bsky.social · 01/12/2025
Few days left to submit your work to #MADWeb '26! The CfP is open until Dec 11 (AOE). We welcome full papers (10 pages) and work-in-progress submissions (6 pages, no proceedings). It's a great chance to showcase you work or get early feedback! 🔗 madweb.work @madwebwork.bsky.social
madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
010
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 07/10/2025
🌟 Want to help shape #MADWeb 2026? Nominate yourself for the Program Committee! Deadline: Oct 31, 2025 ⏰ Consider applying even if you don't have extensive reviewing experience! forms.gle/UovLWS78aa3t...
forms.gle
MADWeb 2026 PC Nomination Form
The web connects billions of devices, running a plethora of clients, and serves billions of users every day. To cope with such a widespread adoption, the web constantly changes. This is evident by som...
035
Marco Squarcina @minimalblue.bsky.social · 25/08/2025
🇦🇹 Team Austria placed 8th at #HITCON #CTF as part of the qualifier for #ECSC2025 in Warsaw. Everyone did a fantastic job, so proud of the team. We'll select the 10 final members in the next days, stay tuned! @hitcon.org @tuwien.at @informatics.tuwien.ac.at @cysecwien.bsky.social @hofhackerei.at
Team AT membersHITCON final scoreboard
020
Marco Squarcina @minimalblue.bsky.social · 13/08/2025
Meanwhile, our plane here in Vegas is "too heavy" and we can't take off. They are asking people to leave to reduce the weight. Please tell me this is perfectly normal.
020
Marco Squarcina @minimalblue.bsky.social · 13/08/2025
After a great run at #defcon33 #CTF, I'm heading to Seattle to attend #USENIX Sec. DM me if you'd like to meet up and join us Thursday at midday for our talk on #TapTrap (track 4) with @beerphilipp.bsky.social ! taptrap.click @lindorfer.in @cysecwien.bsky.social @informatics.tuwien.ac.at
taptrap.click
TapTrap: Animation‑Driven Tapjacking on Android
000
Marco Squarcina @minimalblue.bsky.social · 12/08/2025
From starting @mhackeroni.bsky.social in 2018 to heading @hofhackerei.at to 9th place at @defcon.bsky.social #CTF finals this year: what a journey. This team is amazing, I couldn't be prouder of all of them and the best is yet to come! 🔥 @cysecwien.bsky.social @tuwien.at @informatics.tuwien.ac.at
070
Marco Squarcina @minimalblue.bsky.social · 05/08/2025
First wave of our team (me included) is on the way to @defcon.bsky.social #CTF. Huge thx to the companies and unis backing us, we're extremely grateful. Special shoutout to @tuwien.at for the early support, as well as everyone who joined after. We'll give our best, wish us luck! See you Vegas 🌴🚩
020
Marco Squarcina @minimalblue.bsky.social · 22/07/2025
I'm part of the team that discovered the #TapTrap vulnerability. We confirmed that @grapheneos.org has properly fixed it, as detailed on our site taptrap.click Despite a small factual error, it's good to see #GrapheneOS getting some media attention.
taptrap.click
TapTrap: Animation‑Driven Tapjacking on Android
13510
Reposted by Marco Squarcina
GrapheneOS @grapheneos.org · 22/07/2025
foxnews.com/tech/new-and... > GrapheneOS, a security-focused operating system based on Android, confirmed that its current version is also affected. However, it plans to release a fix in its next update. No, we said that on July 7 and then shipped grapheneos.org/releases#202... fixing it.
1676
Marco Squarcina @minimalblue.bsky.social · 21/07/2025
ECSC 2025 prep has begun! First Team Austria qualifier wrapped up with 30 participants focusing on #ENOWARS and #DUCTF. Great vibes. Thanks to Ikarus Security for hosting us and everyone who joined! #ECSC2025 @tuwien.at @informatics.tuwien.ac.at @cysecwien.bsky.social
Team Austria, 1st qualifier event.
010
Marco Squarcina @minimalblue.bsky.social · 17/07/2025
Our #TapTrap attack got covered in @tuwien.at's news! This was such a fun project. Congrats to @beerphilipp.bsky.social on his second first-author paper at a top-tier conference ❤️ We'll present the paper at #USENIX in Seattle on August 14 . Looking forward to catching up with some of you there!
201
Marco Squarcina @minimalblue.bsky.social · 16/07/2025
For the second year in a row, @tuwien.at students have nominated our Introduction to Security course among the finalists for the Best Teaching Award! Balancing research, teaching & outreach isn't easy, but we give it our all. 🔗 www.tuwien.at/tu-wien/aktu... CC @informatics.tuwien.ac.at
tuwien.at
Das sind die Best Teaching Award-Finalist_innen 2025
Die Jury hat entschieden, für wen die Eulenjagd weitergeht.
151
Marco Squarcina @minimalblue.bsky.social · 10/07/2025
Our new Android attack, #TapTrap, is getting media coverage — so here's a quick explainer. It's a new tapjacking technique that exploits Android's UI animations to hijack user taps without requiring any permissions. @beerphilipp.bsky.social will present it at #USENIX Sec'25. 🌐 taptrap.click
taptrap.click
TapTrap: Animation‑Driven Tapjacking on Android
152
Marco Squarcina @minimalblue.bsky.social · 10/07/2025
It has been an honor to organize the bootcamp for 3 years in a row, and I am proud that it's getting better every time. Thanks to CSA, @cysecwien.bsky.social, ENISA, Joe Pichlmayer, Manuel Reinsperger and the entire team for making this possible. See you all next year ♥️ #CYBER #ECSC2025
020
Reposted by Marco Squarcina
KuK Hof­hackerei @hofhackerei.at · 12/06/2025
Help us choose our mascot! 🐾 Nautilus Institute is asking us to send them a animal mascot for the DEFCON CTF, and we need your help to pick the cutest contender! Dive into the threat to meet the 8 adorable candidates. #KuKHofhackerei #defcon33 #ctf #Mascot
121
Marco Squarcina @minimalblue.bsky.social · 15/05/2025
My team @kukhofhackerei.bsky.social is heading to the DEF CON CTF finals this August in Las Vegas 🔥 We're now looking for sponsors to help cover the trip. If you're interested in supporting us, please get in touch or share this around. Call for sponsors at hofhackerei.at 🇦🇹 Thank you! #CTF #DC33
KuK Hofhackerei - DEF CON 33 Sponsorship (Front)KuK Hofhackerei - DEF CON 33 Sponsorship (Description)KuK Hofhackerei - DEF CON 33 Sponsorship (Packages)
042
Marco Squarcina @minimalblue.bsky.social · 14/04/2025
After many years of battles with @mhackeroni.bsky.social, I'm blown away to announce that we've qualified for the #DEFCON CTF finals with KuK Hofhackerei 🇦🇹 this year! New friends, same love. Couldn't be prouder of this team. Thanks to nautilus.institute for organizing and see you in Vegas! 🚩
KuK Hofhackerei TeamDEF CON CTF Quals 2025 Scoreboard
180
Marco Squarcina @minimalblue.bsky.social · 01/04/2025
The 2nd wave of challenges for the Austria Cyber Security Challenge #ACSC will be live in 1h! You have 1 month left to compete and prove your skills! I contributed a hard web challenge this time, let's see who can solve it 👀 Ready? 👉 acsc.land @informatics.tuwien.ac.at @cysecwien.bsky.social
acsc.land
Austria Cyber Security Challenge 2025
001
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 02/03/2025
And the best paper award sponsored by @paloaltonetworks.bsky.social goes to... 📜 Can Public IP Blocklists Explain Internet Radiation? by D. Ravalico, S. Cossaro, R. Valentim, M. Trevisan, and I. Drago! Congratulations 👏 #MADWeb #NDSSsymposium2025
Best paper award ceremony at MADWeb 2025
042
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 26/02/2025
Can't wait for Friday? Get a sneak peek at #MADWeb '25 papers now! 📄✨ All papers are live on our website: madweb.work Safe travels, and see you in San Diego! ✈️ #NDSSsymposium2025
madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
031
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 12/02/2025
We're thrilled to announce Nick Nikiforakis (Stony Brook University) as our first keynote speaker of #MADWeb '25! 🎤 Building on Top of Shifting Sands: Web Security Through the Lens of Content Integrity Don't miss it! See the full program at madweb.work
madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
032
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 12/02/2025
Our 2nd Keynote is here! 🚨 We're excited to have Frederik Braun @freddyb.bsky.social (Mozilla) at #MADWeb '25! 🎤 With Carrots & Sticks: Can the Browser Handle Web Security? Join us in San Diego to attend this session! Full program: madweb.work#program
madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
031
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 12/02/2025
The #MADWeb '25 program is live! We've got 9 full papers, 3 work-in-progress papers, and 2 exciting keynotes lined up. Huge thanks to all the authors and the program committee! Check out the details and get ready for a great event! 🔥 🔗 madweb.work#program See you in San Diego! #NDSS #websecurity
madweb.work
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
022
Reposted by Marco Squarcina
James Kettle @jameskettle.com · 08/01/2025
Nominations are now open for the Top 10 Web Hacking Techniques of 2024! Browse the contestants and submit your own here: portswigger.net/research/top...
portswigger.net
Top ten web hacking techniques of 2024: nominations open
Nominations are now open for the top 10 new web hacking techniques of 2024! Every year, security researchers from all over the world share their latest findings via blog posts, presentations, PoCs, an
12819
Reposted by Marco Squarcina
MADWeb Workshop @madwebwork.bsky.social · 08/01/2025
🚨 Deadline Extended 🚨 By popular demand, the #MADWeb submission deadline is now January 14, 2025 (AoE)! 🗓️ You still have 1 week to send your papers and join us in San Diego! 📜 Submit here: madweb25.hotcrp.com 🔗 Details: madweb.work Spread the word! #websec #cfp #ndss
madweb25.hotcrp.com
MADWeb 2025
021
Marco Squarcina @minimalblue.bsky.social · 06/01/2025
Please consider submitting your work and help us spread the word! #MADWeb
041
Marco Squarcina @minimalblue.bsky.social · 29/12/2024
Help us make this year's edition of #MADWeb the best one yet! 📅 Deadline: January 9, 2025 (AoE) 📜 Submit here: madweb25.hotcrp.com 🔗 Website: madweb.work #CfP #websec #websecurity
madweb25.hotcrp.com
MADWeb 2025
030
Marco Squarcina @minimalblue.bsky.social · 02/12/2024
Websec folks, this is a good opportunity to join our team in Vienna. Feel free to contact me if you have any questions!
081
Reposted by Marco Squarcina
Lorenzo Leonardini @pianka.it · 22/11/2024
Yesterday my first PHP CVE was published: CVE-2024-11234. In some specific configurations, this vulnerability could allow for CRLF injection when using stream contexts. sec.leonardini.dev/blog/cve-202... Many thanks to @minimalblue.bsky.social for reviewing my original report
sec.leonardini.dev
CVE-2024-11234: Configuring a proxy in a PHP stream context might allow for CRLF injection in URIs 🐘
A vulnerability in PHP might allow an attacker to perform SSRF attacks when unsanitized user-controlled data is used in stream functions if a proxy is used.
0102
Reposted by Marco Squarcina
Matteo Maffei @matteomaffei.bsky.social · 22/11/2024
We have 3 tenure-track openings on "Transforming Science with AI/ML” at TU Wien, as part of the competitive WWTF Vienna Research Group for Young Investigators grant (1.6M EUR). Researchers working at the intersection between Security & AI are encouraged to apply! cysec.wien/calls/call_w...
cysec.wien
Cybersecurity Center TU Wien
Cybersecurity Center TU Wien
163
Marco Squarcina @minimalblue.bsky.social · 21/11/2024
Sharing CVE-2024-11234 affecting PHP. This vulnerability could lead to CRLF injection when using Stream Contexts under certain conditions. Discovered and reported by @p1anka.bsky.social, I only reviewed the report some time ago! github.com/php/php-src/...
github.com
Configuring a proxy in a stream context might allow for CRLF injection in URIs
### Summary Configuring a proxy in a [stream context](https://www.php.net/manual/en/stream.contexts.php) might allow for CRLF injection in URIs, resulting in HTTP request smuggling attacks. #...
0101
Marco Squarcina @minimalblue.bsky.social · 18/11/2024
TIL you can access your profile via <nickname>.bsky.social, like minimalblue.bsky.social. Thanks to @mebeim.bsky.social for sharing the tip.
minimalblue.bsky.social
Marco Squarcina (@minimalblue.bsky.social)
Senior Scientist @TU Wien / Web & Mobile security / CTF with @mhackeroni @We_0wn_Y0u / #drumandbass DJ
072
Reposted by Marco Squarcina
Hunter D Phoenix 🐦‍🔥🏴󠁧󠁢󠁳󠁣󠁴󠁿 @hunterdphoenix.bsky.social · 18/11/2024
I appreciate all of you who use the Alt-text description for the images you post. As a blind dude I feel so much more included here. For those of you who forget: Did you know there’s a reminder in Settings/Accessibility to toggle on & then it won’t let you post image without Alt-text. Thanks 🙏😎
21544091391
Marco Squarcina @minimalblue.bsky.social · 18/11/2024
Post a pic YOU took (no description) to bring some zen to the timeline
050
Marco Squarcina @minimalblue.bsky.social · 18/11/2024
👀
030
Reposted by Marco Squarcina
Lukas Weichselbaum @webappsec.dev · 17/11/2024
I'm in the process of creating a *web security* starter pack and need your help finding more webbies here. Please share and recommend folks passionate about web security in comments below so we can get this community started here 🙂 go.bsky.app/Uf8dZhz
165525
Marco Squarcina @minimalblue.bsky.social · 09/02/2024
The submission site for #SecWeb '24 is now live at secweb24.secpriv.tuwien.ac.at. The deadline is on Feb 22, just 2 weeks from now! It's time to get your papers ready, we are looking forward to your submissions! secweb.work
secweb.work
000
Marco Squarcina @minimalblue.bsky.social · 24/01/2024
The call for papers of the #SecWeb '24 workshop (co-located with IEEE S&P) is now online! Deadline Feb 22 secweb.work SecWeb is THE workshop to discuss provocative advancements in Web security, get feedback on early-stage research, and get in touch with amazing people (academic and not).
secweb.work
000
Marco Squarcina @minimalblue.bsky.social · 23/01/2024
Our work "Cookie Crumbles: Breaking and Fixing Web Session Integrity" is among the nominations for the PortSwigger top-10 Web hacking techniques of 2023! Consider voting for us if you enjoyed our BlackHat and USENIX talks or liked the research. Video & paper here ⤵️ www.usenix.org/conference/u...
000
Marco Squarcina @minimalblue.bsky.social · 31/10/2023
Our paper "Tabbed Out: Subverting the Android Custom Tab Security Model" got accepted at IEEE S&P 2024! Watch out this space for the preprint if you're into #mobile & #web (in)security. Congrats to my coauthors from TU Wien: Philipp Beer, Lorenzo Veronese and Martina Lindorfer! #ieeesp
111
Marco Squarcina @minimalblue.bsky.social · 20/10/2023
Had the pleasure of being interviewed by our amazing communications team at TU Wien Informatics! Here are some behind-the-scenes of the preparation of Team Austria for the European Cybersecurity Challenge next week in Norway: informatics.tuwien.ac.at/news/2513 #ECSC2023
informatics.tuwien.ac.at
Behind the Screens: Training Austria’s Elite for the ECSC
Coach Marco Squarcina tells us about this year’s European Cybersecurity Challenge, Austria’s team, and how to be part of cybersecurity competitions.
051