Shielder @shielder.com · 01/07/2026Blogpost: www.shielder.com/blog/2026/06... Report: github.com/ShielderSec/... 011
Shielder @shielder.com · 01/07/2026With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬ 144
Reposted by ShielderInspektor Gadget @inspektor-gadget.io · 01/05/2026Our external security audit with @shielder.com @ostifofficial.bsky.social and @cncf.io is out! 3 CVEs were found, all of which have been addressed in v0.51.1. Thank you to everyone involved inspektor-gadget.io/blog/2026/04...inspektor-gadget.ioResults from the First Inspektor Gadget Security Audit | Inspektor GadgetInspektor Gadget completed its first independent security audit, conducted by Shielder and coordinated by OSTIF. The audit found three vulnerabilities — all now fixed — plus six hardening recommendati... 022
Shielder @shielder.com · 30/04/2026Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...shielder.comShielder - Inspektor Gadget Security AuditSecurity audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp... 097
Shielder @shielder.com · 24/03/2026kccnceu2026.sched.com/event/2CW4B/...kccnceu2026.sched.comKubeCon + CloudNativeCon Europe 2026: Kubernetes Third Party Audit Review - Ia...View more about this event at KubeCon + CloudNativeCon Europe 2026 000
Shielder @shielder.com · 24/03/2026#KubeCon EU starts today and guess what? Our very own @suidpit.sh will be on stage with a panel about the @kubernetes.io Security Audit we performed during 2025 with the support of @ostifofficial.bsky.social! 🗓️ March 25 - 16:45 CET 📍 Hall 8 | Room F 155
Shielder @shielder.com · 19/03/2026Attending @1ns0mn1h4ck.bsky.social? Meet @not4nhacker.bsky.social @luk3ros.bsky.social and Severus from our AppSec and Red teams! They are eager to discuss about breaking complex authentication implementations and relaying all the things to DA! 054
Reposted by Shielderostifofficial.bsky.social @ostifofficial.bsky.social · 30/01/2026Presenting our 2025 annual report! In our report, you’ll see that OSTIF's story and mission are intertwined. OSTIF will continue to fight for open source infrastructure and the privacy rights of users for as many decades as you’ll let us. Our statement and report link: ostif.org/2025-annual-...ostif.org2025 Annual Report – OSTIF.org 032
Shielder @shielder.com · 31/01/2026Love breaking things just to see how they work? 🐛🔨 A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers. If you are passionate about securing the Open Source world, we definitely need to talk! 033
Shielder @shielder.com · 31/12/2025Happy New Year, Hackers! 🎆 We’re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens. 021
Shielder @shielder.com · 27/12/2025Bootloaders acting weird? 🐛 If you are at #39c3, catch @shielder.com's own @thezero.org to geek out over bootloader oddities and low-level vulnerabilities. 001
Shielder @shielder.com · 25/11/2025Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...luma.comOSTIF Meetups · Events CalendarView and subscribe to events from OSTIF Meetups on Luma. 023
Shielder @shielder.com · 26/10/2025Attending #theSAS25? Meet @paupu.bsky.social for his PAM pwnage talk! It won't be recorded and it might *wink wink* contain a cool drop you don't want to miss 👀 013
Reposted by Shieldersmaury @smaury.bsky.social · 07/08/2025👋🏿 Hackers! Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge? @shielder.com is hiring a Red Teaming Lead to join our crew! More info ⬇️ (share appreciated) #hiring #redteaming romhack.io/job-opportun...romhack.ioRomHack - Job opportunitiesCheck for RomHack sponsor's job opportunities 023
Reposted by Shielderostifofficial.bsky.social @ostifofficial.bsky.social · 31/07/2025In partnership with @aswf.io, OSTIF and @shielder.com worked on audits of MaterialX and OpenEXR. Our deepest gratitude for this opportunity to work with incredible maintainers and cool projects such as these- read about them at our blogs: ostif.org/materialx-au..., ostif.org/openexr-audi... 032
Shielder @shielder.com · 31/07/2025Blog post: shielder.com/blog/2025/07... Reports: github.com/ShielderSec/... 000
Shielder @shielder.com · 31/07/2025🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & ASWF audited OpenEXR and MaterialX: 🔍 11 issues found (1 critical, 3 still to be published) ✔️ Most fixed, others planned 🗣️ ndaprela @smaury.bsky.social @suidpit.bsky.social @thezero.org Full details in the blog post ⬇️🧵 144
Shielder @shielder.com · 07/04/2025Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373 095
Shielder @shielder.com · 13/03/2025In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while! 075
Reposted by Shielderostifofficial.bsky.social @ostifofficial.bsky.social · 17/01/2025Ship happens- and that's why security audits are an important part of security efforts. We facilitated work on #Karmada thanks to support from the @cncf.io and with auditing performed by @shielder.com. You can now sea the impact of an audit for yourself at ostif.org/karmada-audi... 033
Shielder @shielder.com · 16/01/2025🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io: 🔍 6 issues found (1 high, 1 medium, 2 low, 2 info) ✔️ Most fixed, others planned. 🗣️ to @suidpit.bsky.social and @thezero.org Full details in the blog post! www.shielder.com/blog/2025/01...shielder.comShielder - Karmada Security AuditKarmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder. 065
Reposted by Shielderthezero @thezero.org · 10/11/2024The best infosec swag in town. @shielder.com 052
Shielder @shielder.com · 22/10/2024Attending #TheSASCon2024 in the beautiful Bali🏝️? Make sure not to miss @suidpit.bsky.social's talk about his novel research on the macOS 🍎 sandbox and how to bypass it. 🗓️ Wednesday, October 23 - 15:10 011
Shielder @shielder.com · 20/09/2024For the weekend, we gift you with not one, but TWO ways to escalate `sudo iptables` (+ a couple other boring preconditions) into a r00t shell - read how @smaury.bsky.social and @suidpit.bsky.social managed to climb your friendly neighborhood 🔥wall! www.shielder.com/blog/2024/09...shielder.comShielder - A Journey From `sudo iptables` To Local Privilege EscalationIn this post, we demonstrate two techniques allowing a low privileged user to escalate their privileges to root in case they can run iptables and/or iptables-save as 031
Shielder @shielder.com · 29/08/2024Our very own @suidpit.bsky.social will present his novel #macOS research at #TheSAS2024 - if you want to learn more about the macOS sandbox and how to escape it make sure to be in Bali 🏝️ from Oct 22 to Oct 25! Learn more here: thesascon.com 011
Shielder @shielder.com · 28/08/2024During a recent engagement Mindless hacked his way through Vtiger CRM which led to discover a privilege escalation and a SQL injection. Learn more in the dedicated advisories: - CVE-2024-42994 #sqli www.shielder.com/advisories/v... - CVE-2024-42995 #privesc www.shielder.com/advisories/v... 032
Shielder @shielder.com · 22/05/2024Back in December 2023 our researchers @thezero.org @suidpit.bsky.social and Mindless performed an audit sponsored by AWS and facilitated by OSTIF on boost. It resulted in 7 findings and 15 new fuzzers. The report is now public, check the details here: www.shielder.com/blog/2024/05...shielder.comShielder - Boost Security AuditBoost Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder. 022
Shielder @shielder.com · 07/05/2024In early 2023 we (@thezero.org & @smaury.bsky.social) collaborated with SecureDrop to start designing and prototyping the #E2EE messaging protocol for a future version of SecureDrop. 📄 blog post: securedrop.org/news/introdu... 💻 poc code: github.com/freedomofpre...securedrop.orgIntroducing SecureDrop ProtocolThis blog post is a part of a series about our research toward the next generation of the SecureDrop whistleblowing … 053
Shielder @shielder.com · 18/04/2024Check-out the original blog post by Element too! element.io/blog/securit...element.ioSecurity release: Element Android 1.6.12Hello, Today we have released a security update of Element Android to address a pair of vulnerabilities. Please upgrade to the new version (1.6.12) at your earliest convenience. The two vulnerabilitie... 000
Shielder @shielder.com · 18/04/2024Exciting news! We've just released a new blog post on mobile app security, where @suidpit.bsky.social and @thezero.org used their intent-fu to discover vulnerabilities (CVE-2024-26131, CVE-2024-26132) in Element, a @matrix.org client for Android. #writeup #CVE www.shielder.com/blog/2024/04...shielder.comShielder - Element Android CVE-2024-26131, CVE-2024-26132 - Never Take Intents From StrangersA writeup about two intent-based Android vulnerabilities CVE-2024-26131 and CVE-2024-26132 in Element (Matrix). 133
Shielder @shielder.com · 29/03/2024We recently partnered with the Open Source Technology Improvement Fund (OSTIF) to perform a security audit sponsored by AWS on Bref. The audit resulted in 5 findings promptly addresses by @mnapoli.bsky.social. The report is now public, check the details here: www.shielder.com/blog/2024/03...shielder.comShielder - Bref Security AuditBref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder. 022
Shielder @shielder.com · 14/03/2024Hey hackers - attending #Nullcon? Pop to say hi and talk about AppSec and VR! You can find @smaury.bsky.social @thezero.org @suidpit.bsky.social around 🖖🏿 021
Shielder @shielder.com · 08/03/2024During a recent Red Team Assessment @thezero.org and @smaury.bsky.social discovered a vulnerability in PostgreSQL's #PgAdmin which in the worst case allows unauthenticated attackers to run arbitrary server-side code. Check out the #RCE advisory and patch now! www.shielder.com/advisories/p...shielder.comShielder - pgAdmin (<=8.3) Path Traversal in Session Handling Leads to Unsafe Deserialization and Remote Code Execution (RCE)pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing user's session in the session handling code. If the server is running on Windows, an unauthenticated attacker can load ... 053
Shielder @shielder.com · 03/02/2024Hey hackers! Are you attending @fosdem.bsky.social? If you want to talk about open-source software and hardware security make sure to hit up @smaury.bsky.social and @thezero.org! 011
Shielder @shielder.com · 30/01/2024TL;DR Product security folks: do not blindly trust the attack requirements shared by the researchers. Security researchers: when testing embedded devices make sure to mimic correctly all their configurations (i.e. the NVRAM content). 7/7 000
Shielder @shielder.com · 30/01/2024Apparently most of the researchers are either keeping an authentication bypass private or they do their research in emulated environments only and no one ever checked the vulnerabilities before issuing the CVE numbers and releasing the advisories. 6/7 100
Shielder @shielder.com · 30/01/2024After some intense debugging sessions they discovered that not only that one but also a lot of other ASUS routers' vulnerabilities were probably incorrectly deemed as unauthenticated. 5/7 100
Shielder @shielder.com · 30/01/2024Once at home they used their research budget to buy a real device and prove the vulnerability there too, but ... it was not working 🤯 Know what? The vulnerability was not unauthenticated on the physical device! 4/7 100
Shielder @shielder.com · 30/01/2024They quickly bin-diffed the firmware versions, found the vulnerabilities, emulated the vulnerable firmware, and wrote and exploit for one of them. This was so fast they had a working exploit even before jumping off the wayback 🚂. 3/7 100
Shielder @shielder.com · 30/01/2024While attending Silvio Cesare's training at RomHack @thezero.org and @suidpit.bsky.social chose to do some practice. While looking at the news they discovered about some recently disclosed ASUS routers unauthenticated RCEs. 2/7 www.tomshardware.com/news/asus-pa... 100
Shielder @shielder.com · 30/01/2024Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @thezero.org and @suidpit.bsky.social combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 www.shielder.com/blog/2024/01...shielder.comShielder - Hunting for ~~Un~~authenticated n-days in Asus RoutersNotes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240. 165
Shielder @shielder.com · 30/01/2024Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @Th3Zer0 and @suidpit combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7 www.shielder.com/blog/2024/01...shielder.comShielder - Hunting for ~~Un~~authenticated n-days in Asus RoutersNotes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240. 020
Shielder @shielder.com · 21/10/2023Hey hackers - attending NoHat? Pop at the boot in the entrance for some swag and to chat about crazy 🦋🦗🐞🐝🐜🦟🪲! #nohat2023 041
Reposted by Shieldersmaury @smaury.bsky.social · 30/08/2023A vulnerability I've reported to Google was recently made public. TL;DR: Chrome implements credentialless iframes which should have a dedicated ephemeral cookie jar - I've found a way to break outside of it using ServiceWorkers to access long lived cookies. bugs.chromium.org/p/chromium/i...bugs.chromium.org 1420885 - chromium - An open-source project to help move the web forward. - Monorai... 032