Reposted by paupuShielder @shielder.com · 01/07/2026Blogpost: www.shielder.com/blog/2026/06... Report: github.com/ShielderSec/... 011
Reposted by paupuShielder @shielder.com · 01/07/2026With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬ 144
Reposted by paupuShielder @shielder.com · 30/04/2026Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...shielder.comShielder - Inspektor Gadget Security AuditSecurity audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp... 097
Reposted by paupuOsservatorio Nessuno OdV @osservatorionessuno.org · 09/04/2026Today we are publishing our analysis of the latest version of Spyrtacus, a spyware agent from SIO/ASIGINT, produced by the same company that was exposed distributing fake WhatsApp client by Meta Read our analysis: osservatorionessuno.org/blog/2026/04...osservatorionessuno.orgItalian spyware maker SIO still developing and distributing SpyrtacusItalian spyware maker SIO still developing and distributing Spyrtacus 045
Reposted by paupuShielder @shielder.com · 24/03/2026#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F 155
Reposted by paupuShielder @shielder.com · 19/03/2026Attending @1ns0mn1h4ck.bsky.social? Meet @not4nhacker.bsky.social @luk3ros.bsky.social and Severus from our AppSec and Red teams! They are eager to discuss about breaking complex authentication implementations and relaying all the things to DA! 054
Reposted by paupuShielder @shielder.com · 31/01/2026Love breaking things just to see how they work? 🐛🔨 A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers. If you are passionate about securing the Open Source world, we definitely need to talk! 033
Reposted by paupuShielder @shielder.com · 25/11/2025Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...luma.comOSTIF Meetups · Events CalendarView and subscribe to events from OSTIF Meetups on Luma. 023
paupu @paupu.bsky.social · 27/10/2025Huge thanks to #theSAS25 organization and ppl who voted for this amazing prize! It's been a real pleasure! 000
Reposted by paupuShielder @shielder.com · 26/10/2025Attending #theSAS25? Meet @paupu.bsky.social for his PAM pwnage talk! It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss 👀 013
paupu @paupu.bsky.social · 26/10/2025Ready for #theSAScon25 in Khao Lak 🇹🇭 🌴 Ping me if u wanna say hi! 030
Reposted by paupuShielder @shielder.com · 31/07/2025🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX: 🔍 11 issues found (1 critical, 3 still to be published) ✔️ Most fixed, others planned 🗣️ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org Full details in the blog post ⬇️🧵 144
Reposted by paupuTumpiCon @tumpicon.org · 09/04/2025Just published some talks on tumpicon.org Wanna join us? Follow the trail 🥾 063
Reposted by paupuShielder @shielder.com · 07/04/2025Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373 095
Reposted by paupuShielder @shielder.com · 13/03/2025In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while! 075
Reposted by paupuTumpiCon @tumpicon.org · 06/02/2025Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk! 1117
Reposted by paupuShielder @shielder.com · 16/01/2025🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io: 🔍 6 issues found (1 high, 1 medium, 2 low, 2 info) ✔️ Most fixed, others planned. 🗣️ to @suidpit.bsky.social and @thezero.org Full details in the blog post! www.shielder.com/blog/2025/01...shielder.comShielder - Karmada Security AuditKarmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder. 065
Reposted by paupuϻг_ϻε @steven.srcincite.io · 26/11/2024I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy! Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...srcincite.ioRemote Code Execution with Spring PropertiesRecently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting... 17636
Reposted by paupuShielder @shielder.com · 07/05/2024In early 2023 we (@thezero.org & @smaury.bsky.social) collaborated with SecureDrop to start designing and prototyping the #E2EE messaging protocol for a future version of SecureDrop. 📄 blog post: securedrop.org/news/introdu... 💻 poc code: github.com/freedomofpre...securedrop.orgIntroducing SecureDrop ProtocolThis blog post is a part of a series about our research toward the next generation of the SecureDrop whistleblowing … 053
Reposted by paupuShielder @shielder.com · 08/03/2024During a recent Red Team Assessment @thezero.org and @smaury.bsky.social discovered a vulnerability in PostgreSQL's #PgAdmin which in the worst case allows unauthenticated attackers to run arbitrary server-side code. Check out the #RCE advisory and patch now! www.shielder.com/advisories/p...shielder.comShielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing user's session in the session handling code. If the server is running on Windows, an unauthenticated attacker can load ... 053
Reposted by paupuShielder @shielder.com · 29/03/2024We recently partnered with the Open Source Technology Improvement Fund (OSTIF) to perform a security audit sponsored by AWS on Bref. The audit resulted in 5 findings promptly addresses by @mnapoli.bsky.social. The report is now public, check the details here: www.shielder.com/blog/2024/03...shielder.comShielder - Bref Security AuditBref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder. 022
Reposted by paupuShielder @shielder.com · 30/01/2024Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @thezero.org and @suidpit.bsky.social combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 www.shielder.com/blog/2024/01...shielder.comShielder - Hunting for ~~Un~~authenticated n-days in Asus RoutersNotes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240. 165