Sign in

paupu

@paupu.bsky.social
50 followers 167 following 2 posts

Penetration Tester @ShielderSec | Bachelor's Degree in Computer Engineering | IT and Cyber Security lover!

PostsRepliesMedia
Reposted by paupu
Shielder @shielder.com · 01/07/2026
Blogpost: www.shielder.com/blog/2026/06... Report: github.com/ShielderSec/...
011
Reposted by paupu
Shielder @shielder.com · 01/07/2026
With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬
144
Reposted by paupu
Shielder @shielder.com · 30/04/2026
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
shielder.com
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
097
Reposted by paupu
Osservatorio Nessuno OdV @osservatorionessuno.org · 09/04/2026
Today we are publishing our analysis of the latest version of Spyrtacus, a spyware agent from SIO/ASIGINT, produced by the same company that was exposed distributing fake WhatsApp client by Meta Read our analysis: osservatorionessuno.org/blog/2026/04...
osservatorionessuno.org
Italian spyware maker SIO still developing and distributing Spyrtacus
Italian spyware maker SIO still developing and distributing Spyrtacus
045
Reposted by paupu
Shielder @shielder.com · 24/03/2026
#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F
155
Reposted by paupu
Shielder @shielder.com · 19/03/2026
Attending @1ns0mn1h4ck.bsky.social? Meet @not4nhacker.bsky.social @luk3ros.bsky.social and Severus from our AppSec and Red teams! They are eager to discuss about breaking complex authentication implementations and relaying all the things to DA!
054
Reposted by paupu
Shielder @shielder.com · 31/01/2026
Love breaking things just to see how they work? 🐛🔨 ​A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers. ​If you are passionate about securing the Open Source world, we definitely need to talk!
033
Reposted by paupu
Shielder @shielder.com · 25/11/2025
Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...
luma.com
OSTIF Meetups · Events Calendar
View and subscribe to events from OSTIF Meetups on Luma.
023
paupu @paupu.bsky.social · 27/10/2025
Huge thanks to #theSAS25 organization and ppl who voted for this amazing prize! It's been a real pleasure!
000
Reposted by paupu
Shielder @shielder.com · 26/10/2025
Attending #theSAS25? Meet @paupu.bsky.social for his PAM pwnage talk! It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss 👀
013
paupu @paupu.bsky.social · 26/10/2025
Ready for #theSAScon25 in Khao Lak 🇹🇭 🌴 Ping me if u wanna say hi!
030
Reposted by paupu
Shielder @shielder.com · 31/07/2025
🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX: 🔍 11 issues found (1 critical, 3 still to be published) ✔️ Most fixed, others planned 🗣️ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org Full details in the blog post ⬇️🧵
144
Reposted by paupu
TumpiCon @tumpicon.org · 09/04/2025
Just published some talks on tumpicon.org Wanna join us? Follow the trail 🥾
063
Reposted by paupu
Shielder @shielder.com · 07/04/2025
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373
095
Reposted by paupu
Shielder @shielder.com · 13/03/2025
In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
075
Reposted by paupu
TumpiCon @tumpicon.org · 06/02/2025
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!
1117
Reposted by paupu
Shielder @shielder.com · 16/01/2025
🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io: 🔍 6 issues found (1 high, 1 medium, 2 low, 2 info) ✔️ Most fixed, others planned. 🗣️ to @suidpit.bsky.social and @thezero.org Full details in the blog post! www.shielder.com/blog/2025/01...
shielder.com
Shielder - Karmada Security Audit
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
065
Reposted by paupu
ϻг_ϻε @steven.srcincite.io · 26/11/2024
I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
srcincite.io
Remote Code Execution with Spring Properties
Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...
17636
Reposted by paupu
Shielder @shielder.com · 07/05/2024
In early 2023 we (@thezero.org & @smaury.bsky.social) collaborated with SecureDrop to start designing and prototyping the #E2EE messaging protocol for a future version of SecureDrop. 📄 blog post: securedrop.org/news/introdu... 💻 poc code: github.com/freedomofpre...
securedrop.org
Introducing SecureDrop Protocol
This blog post is a part of a series about our research toward the next generation of the SecureDrop whistleblowing …
053
Reposted by paupu
Shielder @shielder.com · 08/03/2024
During a recent Red Team Assessment @thezero.org and @smaury.bsky.social discovered a vulnerability in PostgreSQL's #PgAdmin which in the worst case allows unauthenticated attackers to run arbitrary server-side code. Check out the #RCE advisory and patch now! www.shielder.com/advisories/p...
shielder.com
Shielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing user's session in the session handling code. If the server is running on Windows, an unauthenticated attacker can load ...
053
Reposted by paupu
Shielder @shielder.com · 29/03/2024
We recently partnered with the Open Source Technology Improvement Fund (OSTIF) to perform a security audit sponsored by AWS on Bref. The audit resulted in 5 findings promptly addresses by @mnapoli.bsky.social. The report is now public, check the details here: www.shielder.com/blog/2024/03...
shielder.com
Shielder - Bref Security Audit
Bref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
022
Reposted by paupu
Shielder @shielder.com · 30/01/2024
Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @thezero.org and @suidpit.bsky.social combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 www.shielder.com/blog/2024/01...
shielder.com
Shielder - Hunting for ~~Un~~authenticated n-days in Asus Routers
Notes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240.
165