Sign in

Louis Nyffenegger

@snyff.pentesterlab.com
931 followers 40 following 45 posts

Founder/CEO/Trainer/Researcher/CVE archeologist @PentesterLab. Security engineer. Bugs are my own, not of my employer...

PostsRepliesMedia
Louis Nyffenegger @snyff.pentesterlab.com · 31/03/2026
Everyone is panicking about AI-generated zero days like it's an attacker story. It's not. Defenders can use the best models against their own code right now. Your progress compounds. Attackers' job gets harder. pentesterlab.com/blog/defende...
pentesterlab.com
Defenders Finally Have the Edge - PentesterLab's Blog
AI agents are changing vulnerability research, but the real advantage goes to defenders. Attackers face air-gap constraints while defenders get full access to frontier models on their own code. Every ...
032
Louis Nyffenegger @snyff.pentesterlab.com · 31/03/2026
DO NOT JAVASCRIPT TODAY. I REPEAT: DO NOT, UNDER ANY CIRCUMSTANCES, JAVASCRIPT TODAY.
021
Louis Nyffenegger @snyff.pentesterlab.com · 17/03/2026
I spent last week, this week-end and the start of this week working on a redesign of @pentesterlab.com 's website. Aiming for something a bit more modern... Let me know what you think!
020
Reposted by Louis Nyffenegger
CrikeyCon @crikeycon.bsky.social · 09/03/2026
Our schedule is up, and we're excited to announce our speaker @snyff.pentesterlab.com is joining us on stage with I DON'T LIKE THIS CODE!!! Get ready to walk through a series of real-world inspired code snippets with one minute to figure it out. Only question, will there be jeopardy music?
094
Reposted by Louis Nyffenegger
Security BSides Prague @bsidesprg.bsky.social · 04/03/2026
Closing keynote for Day 1 announced for BSides Prague 2026 🎉 Louis Nyffenegger (@snyff.pentesterlab.com), application security expert and founder of PentesterLabs, is joining us! 📷 April 23, 2026 Don’t miss it. 📷🔥 #bsides #bsidesprg #keynote
001
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 01/03/2026
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟵, 𝟮𝟬𝟮𝟲 Mostly AI... 💻 𝗕𝗿𝗼𝘄𝘀𝗲𝗿-𝗕𝗮𝘀𝗲𝗱 𝗣𝗼𝗿𝘁 𝗦𝗰𝗮𝗻𝗻𝗶𝗻𝗴 𝗶𝗻 𝘁𝗵𝗲 𝗔𝗴𝗲 𝗼𝗳 𝗟𝗡𝗔 Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....
wiki.notveg.ninja
Browser-Based Port Scanning in the Age of LNA
123
Louis Nyffenegger @snyff.pentesterlab.com · 02/03/2026
I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars. vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days. pentesterlab.com/blog/what-yo...
pentesterlab.com
What you don't see - PentesterLab's Blog
More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...
045
Louis Nyffenegger @snyff.pentesterlab.com · 21/01/2026
SEE MUM, "I" CAN STILL FIND BUGS!
020
Louis Nyffenegger @snyff.pentesterlab.com · 29/12/2025
Today (2025-12-29) is 2026-W01-1 in ISO week-date 🤯\ So it’s the first day of ISO week-year 2026, even though the date is still 2025. (Week 1 = week with the first Thursday)
130
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 27/11/2025
Black Friday at @pentesterlab.com 🧨 For a limited time: 🔒 1 year of PRO for $146.52 🎓 Student special: 3 months PRO for $25.99 Hands-on labs. Real CVEs. Security code review training used by real AppSec & pentest teams. ⏰ Offer ends 2 Dec 2025, 23:59:59 UTC 👉 pentesterlab.com/pro
023
Louis Nyffenegger @snyff.pentesterlab.com · 21/11/2025
I have been using docker for 10 years... Today I learned that you don't need to provide the full container id when you run docker exec...
050
Reposted by Louis Nyffenegger
Christian @xntrik.wtf · 19/10/2025
Really awesome preso from @snyff.pentesterlab.com @pentesterlab.com over at BSides Perth. Jam packed with patterns, approaches, tips and tricks to level up finding bugs in code. #bsides #bsidesperth
132
Louis Nyffenegger @snyff.pentesterlab.com · 21/04/2025
I’ve spent 2 solid hours doing bug bounty and I still haven’t made $200k. Can someone tell me what I’m doing wrong? #bugbountytips
161
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 24/02/2025
AI-generated code is reshaping secure code review—fewer trivial bugs, but more hidden threats. Read more in our new blog post: pentesterlab.com/blog/secure-... What do you think?
pentesterlab.com
How AI-Generated Code Is Changing Secure Code Review
Learn how AI-generated code impacts secure code review and application security. Discover why AI excels at catching common vulnerabilities but needs human expertise for complex bugs.
001
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 13/02/2025
Think teaching devs to hack is risky? In reality, a bit of hacking knowledge helps them spot vulnerabilities early and build stronger apps. Discover why having devs with a 'hacker mindset' is a win for security: pentesterlab.com/blog/why-dev...
pentesterlab.com
I Don’t Want My Devs to Become Hackers! - PentesterLab's Blog
Discover why encouraging developers to learn ethical hacking boosts security, reduces bugs, and fosters a proactive security culture in your organization.
011
Louis Nyffenegger @snyff.pentesterlab.com · 07/02/2025
From now on, I'll call any snippet of vulnerable code shared on Social Media as "Security Code Review Porn" It gives the wrong expectations about what real code review actually involves.
050
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 02/02/2025
Articles worth reading discovered last week: 🤝 blog.doyensec.com/2025/01/30/o... ☠️ www.feistyduck.com/newsletter/i... 📚 pathonproject.com/zb/?871f0933... And as always, it’s in our blog: pentesterlab.com/blog/researc... #PentesterLabWeekly
blog.doyensec.com
Common OAuth Vulnerabilities · Doyensec's Blog
Common OAuth Vulnerabilities
063
Louis Nyffenegger @snyff.pentesterlab.com · 29/01/2025
I’m excited to share that in a few weeks I’ll be heading to the US for a series of talks and workshops focused on security code review and JWT—and I’ll be bringing some @pentesterlab.com swag along too!
152
Louis Nyffenegger @snyff.pentesterlab.com · 28/01/2025
091
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 25/01/2025
🚀 Level up your #CyberSecurity skills FOR FREE! 🛡️ Earn the Recon Badge with Pentesterlab and master: 🔍 Virtual Hosts 🌐 DNS Recon 🔒 TLS Recon ...and so much more! Start your journey today 👉 pentesterlab.com/badges/recon
pentesterlab.com
PentesterLab: Learn with our Recon Badge
The Recon badge is our set of exercises created to help you learn Reconnaissance. From findings usual files down to DNS and TLS exploration, this badge will help you get better at finding new targets
022
Louis Nyffenegger @snyff.pentesterlab.com · 22/01/2025
...
120
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 11/01/2025
Networking in InfoSec isn’t just about IP addresses and ports—it’s also about people! Discover how meetups, conferences, and volunteering can open big career doors in InfoSec. Read more: pentesterlab.com/blog/infosec...
pentesterlab.com
Networking but not TCP/IP - PentesterLab's Blog
Discover how building real-world connections in the InfoSec community can accelerate your journey into pentesting and cybersecurity. From local meetups and conferences to online communities, this guid...
0113
Louis Nyffenegger @snyff.pentesterlab.com · 05/01/2025
Someone shared this write-up in the @pentesterlab.com 's discord: www.wiz.io/blog/nuclei-... I love this article so much! The content and the analysis are A+ I really like the 🚩 (very similar to pentesterlab.com/blog/another...)
wiz.io
A Signature Verification Bypass in Nuclei (CVE-2024-43405) | Wiz Blog
Wiz's engineering team discovered a high-severity signature verification bypass in Nuclei which could potentially lead to arbitrary code execution.
080
Reposted by Louis Nyffenegger
joern @jrn.bsky.social · 04/01/2025
Have a great weekend and enjoy some tunes: youtu.be/j_Md8_7mhOU
youtu.be
joernchen - Friday 13th @ 1°C
YouTube video by Tiny Club Berlin
263
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 31/12/2024
If your New Year’s resolution is to get better at web security code review, don’t miss our upcoming live training. Learn how to find vulnerabilities and strengthen your skills: pentesterlab.gumroad.com
pentesterlab.gumroad.com
Subscribe to PentesterLab on Gumroad
PentesterLab is an easy and great way to learn security code review and penetration testing. We provide vulnerable systems that can be used to test and understand vulnerabilities.
032
Louis Nyffenegger @snyff.pentesterlab.com · 31/12/2024
Happy New Year! pentesterlab.com/gift/xDzcB35... (3-month) pentesterlab.com/gift/UBMtCsi... (3-month) pentesterlab.com/gift/BWEYEme... (3-month)
pentesterlab.com
Learn Web Penetration Testing: The Right Way
Learn Web Penetration Testing: The Right Way
021
Louis Nyffenegger @snyff.pentesterlab.com · 30/12/2024
Golang: because hackers haven’t given up on SQL injection in 2024...
0111
Louis Nyffenegger @snyff.pentesterlab.com · 24/12/2024
🎅 pentesterlab.com/gift/v5kegJq... (3-month) pentesterlab.com/gift/4VG6RYU... (3-month) pentesterlab.com/gift/lsgfEwJ... (3-month)
pentesterlab.com
Learn Web Penetration Testing: The Right Way
Learn Web Penetration Testing: The Right Way
293
Louis Nyffenegger @snyff.pentesterlab.com · 18/12/2024
I put together a VERY limited (for now) list of web hackers in a Starter pack: go.bsky.app/9uay4Ad A lot of people are missing (I will try to add more as I find them) but make sure you follow people already in the list!
33114
Reposted by Louis Nyffenegger
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/12/2024
Cross-Site POST Requests Without a Content-Type Header by @lukejahnke nastystereo.com/security/cross-site… #BBRENewsletter85
021
Reposted by Louis Nyffenegger
Dominique Righetto @righettod.eu · 14/12/2024
❤It is why I am a huge fan and student of @pentesterlab.com and @snyff.pentesterlab.com 😱This lab show me that I was wrong, since several years, recommending to dev teams using a hash of the token as identifier in a revocation list. 🥰Now, I know the correct recommendation to provide. #appsec #jwt
072
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 12/12/2024
Want to level up your learning in security? 🚀 Stop scrolling and start reflecting. 'Reading Between the Lines' challenges you to dig deeper: 1️⃣ What can I learn from this? 2️⃣ What patterns apply elsewhere? 3️⃣ Why didn’t I spot this? The real breakthroughs come when you ask the right questions. 💡 👇
pentesterlab.com
PentesterLab Blog: Reading Between the Lines: A Guide to Thoughtful Learning in Security
Discover how to extract deeper insights from security content by going beyond surface-level understanding. This post explores a reflective approach to learning, helping you uncover patterns, improve y...
154
Louis Nyffenegger @snyff.pentesterlab.com · 08/12/2024
2186
Louis Nyffenegger @snyff.pentesterlab.com · 06/12/2024
pentesterlab.com/gift/oNrufnj...
pentesterlab.com
Learn Web Penetration Testing: The Right Way
Learn Web Penetration Testing: The Right Way
131
Louis Nyffenegger @snyff.pentesterlab.com · 05/12/2024
These are simple issues, but they illustrate how, by thinking of vulnerabilities as patterns rather than code, you can move from one language to another.
141
Louis Nyffenegger @snyff.pentesterlab.com · 05/12/2024
Guess who has two thumbs, just found another algorithm confusion vulnerability, and got accepted to speak at @cactuscon.bsky.social on algorithm confusion vulnerabilities? 👍 THIS GUY 👍
3161
Louis Nyffenegger @snyff.pentesterlab.com · 03/12/2024
Cyber has more certs than /etc/ssl/certs/ca-certificates.crt
210
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 02/12/2024
If you are a new PRO subscriber, make sure you order your set of free stickers!
where to ask for stickers!
152
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 01/12/2024
Only content from Australia and New Zealand this week! Is the rest of the world asleep? 💎 nastystereo.com/security/rub... 🪄 srcincite.io/blog/2024/11... 🌐 nastystereo.com/security/cro... 👺 pulsesecurity.co.nz/articles/mss... 🔐 tierzerosecurity.co.nz/2024/11/26/d...
nastystereo.com
Ruby 3.4 Universal RCE Deserialization Gadget Chain / nastystereo.com
052
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 01/12/2024
Encoding isn't magic ✨: It doesn’t bypass filters or hack systems unless something decodes it. Learn how to avoid this common security misconception: pentesterlab.com/blog/encodin... #AppSec #CyberSecurity #BugBounty
pentesterlab.com
PentesterLab Blog: Encoding Is Not Magic
When talking with aspiring hackers, bug bounty hunters, or application security engineers, it often feels that there’s some misunderstanding around encoding. ...
194
Reposted by Louis Nyffenegger
Nicolas Grégoire @agarri.fr · 29/11/2024
Given that simps0n isn’t on Bluesky yet, allow me to repost a link to his excellent weekly ezine 💎 Here’s today’s edition, "AppSec Ezine - 563rd" 📚
pathonproject.com
AppSec Ezine
0137
Louis Nyffenegger @snyff.pentesterlab.com · 29/11/2024
Programming languages should have functions/methods to validate if a hostname or origin are part of a domain... That would kill a *LOT* of vulnerabilities...
210
Louis Nyffenegger @snyff.pentesterlab.com · 28/11/2024
When you're just minding your own business building code review labs for @pentesterlab.com, and a new vulnerability jumps out at you...
120
Louis Nyffenegger @snyff.pentesterlab.com · 28/11/2024
@nastystereo.com seems alright at computers...
030
Reposted by Louis Nyffenegger
Justin Gardner @rhynorater.bsky.social · 27/11/2024
nastystereo.com/security/cro...
nastystereo.com
Cross-Site POST Requests Without a Content-Type Header / nastystereo.com
0111
Reposted by Louis Nyffenegger
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 27/11/2024
‼️Only valid until‼️ Tuesday, 03 Dec 2024 23:59:59 Don't miss this opportunity! It's also the perfect time to renew/extend your existing subscription! pentesterlab.com/pro
pentesterlab.com
PentesterLab PRO: Learn Web Hacking and Security Code Review
Take your cybersecurity skills to the next level with PentesterLab PRO. Access exclusive advanced penetration testing exercises, expert tutorials, and hands-on learning. Upgrade now and become a top-t...
031
Reposted by Louis Nyffenegger
PentesterLab @pentesterlab.com · 27/11/2024
(H|Bl)ack Friday is Back! 🔥🔥🔥 Black Friday Special 🔥🔥🔥 Get full access to PentesterLab PRO for a year and pay $146.52 instead of $199.99 🎓📚✏️ Student Special ✏️📚🎓 Get full access to PentesterLab PRO for three months year and pay $25.99 instead of $34.99
131
Louis Nyffenegger @snyff.pentesterlab.com · 27/11/2024
I've been meaning to look into this for a while... the year of the latest commit for all the libraries on jwt.io.
040
Louis Nyffenegger @snyff.pentesterlab.com · 26/11/2024
I loved putting these challenges together. A good mix of simple code review and exploitation. 😈 𝐓𝐡𝐞 𝐝𝐞𝐯𝐢𝐥 𝐢𝐬 𝐢𝐧 𝐭𝐡𝐞 𝐝𝐞𝐭𝐚𝐢𝐥𝐬 😈
032