Tal Skverer @taltechtreks.com · 27/04/2026Look what just landed in GitHub's changelog 👀 A well-needed change to how GitHub Actions constructs the sub claim in its OIDC tokens, making OIDC trust relationships more secure for organizations by embedding immutable identifiers in the claim. 111
Tal Skverer @taltechtreks.com · 29/11/2025It happened! My #DEFCON 33 talk on hacking Pokémon Go is live! Looking back, it was an absolute pleasure to dip into that 2016 nostalgia and share with the security community the untold story of Team Unknown6, on stage in front of a packed full audience. m.youtube.com/watch?v=2En9...m.youtube.comDEF CON 33 - Breakin 'Em All – Overcoming Pokemon Go's Anti Cheat Mechanism - Tal SkvererYouTube video by DEFCONConference 020
Tal Skverer @taltechtreks.com · 28/10/2025וואו, איזה אווירה ואיזה קהל ב-Reversim Summit היום! שמחתי מאוד על הזכות להיות פה ולהציג בפניכם את המחקר שלי, תודה! 120
Tal Skverer @taltechtreks.com · 27/10/2025איזה כיף שהגיע הכנס השנתי של Reversim Summit! כנס שתמיד נהדר להיות בו עם הרצאות מעניינות ומעולות, והפעם הוא מתוק במיוחד כי יוצא לי להרצות בו בפעם הראשונה! מוזמנים לבוא לשמוע על איך נראה האקינג למשחקי אנדרואיד, ואיך ביליתי את ימי הקיץ אי שם ב2016 כדי לפרוץ לפוקימון גו. מחר, 27/10, ב13:20 באולם הגדול! 110
Tal Skverer @taltechtreks.com · 24/10/2025Had a great time presenting the OWASP Top 10 NHI Project today at #LASCON Austin with Tomer Yahalom! We've had the pleasure to give the talk to a great crowd and amazing people. Looking forward to the second day filled with interesting talks! 010
Tal Skverer @taltechtreks.com · 16/10/2025The #MCP framework took the world by storm. But is it safe? We downloaded over 5 thousand of the highest starred MCP implementations to answer that question! astrix.security/learn/blog/s...astrix.securityState of MCP Server Security 2025: Research Report | Astrix5K+ MCP servers analysis: 53% use insecure hard-coded credentials. Read the full 2025 research and download the open-source MCP Secret Wrapper to mitigate risks. 100
Tal Skverer @taltechtreks.com · 20/08/2025I am absolutely delighted to share that I'll be giving a talk at Reversim Summit 2025 on breaking Pokémon Go's anti-cheating mechanism! On a personal note, every time I visit Reversim, it shows me just how awesome, welcoming, and genuinely interesting community-driven events can be. 110
Tal Skverer @taltechtreks.com · 09/08/2025Breaking 'Em All! The blog posts going deeper into hacking Pokemon Go that accompany my #DEFCON talk are live on my blog! taltechtreks.com/2024/04/06/H... taltechtreks.com/2025/08/09/H... Happy to get questions on the research!taltechtreks.comBreaking Pokémon Go Anti-Cheating System - Part 2Overcoming Niantic's Anti Cheating Mechanism 061
Tal Skverer @taltechtreks.com · 09/08/2025Talking in an hour at #DEFCON about Pokemon Go on track 3. Couldn't be more excited! I've worked on it multiple nights in the past months, and I hope you'll enjoy it! If you're not here in person, you can catch the talk live at www.youtube.com/live/fzbrrKP... or www.twitch.tv/defcon_dctv_...twitch.tvDEFCON_DCTV_Three - TwitchDEFCON TV Channel 3: Track 3 Talks 051
Tal Skverer @taltechtreks.com · 09/08/2025Giving a talk on Pokemon Go, I just had to convert myself to a Pokemon trainer. The amazing Ryan Rockenbaugh surprised me with a limited edition sticker of Trainer Tal Sticker wall at #DEFCON got 2, and I will be giving what's left tomorrow at my talk Breaking 'Em All! 11:30 Track 3. See you! 060
Tal Skverer @taltechtreks.com · 07/08/2025Excited and humbled to speak once again in DEF CON. Talk is on Saturday at 11:30, track 3. I'll be in the conf till Sunday, hit me up if you want to chat over the talk or any other project. 020
Tal Skverer @taltechtreks.com · 22/07/2025The #DEFCON 33 schedule is live and I'm excited to announce I'll be giving a talk this year on unique research I was a part of a few years back! "Breakin 'Em All – Overcoming Pokémon Go's Anti-Cheat Mechanism" Join me on stage - Sat, 11:30 AM, Track 3 defcon.org/html/defcon-... 011
Tal Skverer @taltechtreks.com · 11/06/2025Looks like I'll be at Hacker Summer Camp this year! Exciting #DEFCON33 ☺ 050
Tal Skverer @taltechtreks.com · 06/06/2025Just got back from #AppSecIL2025! Ended up 4th place in the #CTF 🎉 Solved 12/15 challenges alone - Android pwn, JS sandbox escapes, cache poisoning, XSS bypasses. The usual suspects: SQLi, LDAP injection, XXE. Had a blast! Looking forward to the next one. Writeup: taltechtreks.com/2025/06/04/a...taltechtreks.comAppSec IL 2025 CTF - WriteupA writeup on all challenges I solved in the 2025 OWASP CTF 021
Tal Skverer @taltechtreks.com · 20/05/2025I'm building something cute and new, but as opposed to my normal ways, this time I'm using #Cursor heavily and the flow blows my mind. Although I'm certain that without prior good knowledge of coding it wouldn't work that well. 000
Tal Skverer @taltechtreks.com · 02/05/2025Ah, I wondered when this was due to come out. Can't wait to experiment! www.anthropic.com/news/integra...anthropic.comClaude can now connect to your worldToday we're announcing Integrations, a new way to connect your apps and tools to Claude. We're also expanding Claude's Research capabilities with an advanced mode that searches the web, your Google Wo... 000
Tal Skverer @taltechtreks.com · 01/05/2025Excited to present my research tomorrow at #RSAC! Come by to hear John and me share conclusions and insights on the first publicly available report on Non-Human identity security! See you there, May 1, 10:50 am at Moscone West 3004! 030
Tal Skverer @taltechtreks.com · 23/04/2025For today, a bit Friends content! Or, uhh, actually, computer science! What’s the largest sofa you can pivot around a corner? Heard about this problem in the past, but I thought it's one of those we will never be able to prove. (At least until quantum computers arrive to solve some NP problems)quantamagazine.orgThe Largest Sofa You Can Move Around a Corner | Quanta MagazineA new proof reveals the answer to the decades-old “moving sofa” problem. It highlights how even the simplest optimization problems can have counterintuitive answers. 010
Tal Skverer @taltechtreks.com · 17/04/2025Took a bit of hiatus from posting here, was quite busy the past few months (CFP season amiright…) But I do have more cool stuff ready for sharing as well as writing 2 blog posts about projects I worked on lately. Looking forward to sharing with you all 000
Tal Skverer @taltechtreks.com · 14/03/2025Great time presenting OWASP NHI Top 10 at #SnowFROC! If you're here, come say hi! 000
Tal Skverer @taltechtreks.com · 08/03/2025Well, that was an hour of my life well spent. An amazing adaptation of minesweeper to include old-school RPG elements. UPDATE: Had to go back and play, another 4 hours to achieve a perfect clear. Incredible game!danielben.itch.ioDragonsweeper by Daniel BenmerguiA roguelike minesweeper adventure 010
Tal Skverer @taltechtreks.com · 06/03/2025Great thread on the emerging new details on the ByBit breach 000
Tal Skverer @taltechtreks.com · 28/02/2025A cute post showcasing the basis of every website - HTML! The site goes over (almost) all HTML tags, by using them. Seeing this, it’s unfortunate that text inputs in websites don't allow most tags but rather encapsulate how the final result is displayed for users. Give us more, please!iamwillwang.comEvery HTML Element 010
Tal Skverer @taltechtreks.com · 27/02/2025Managed to squeeze in 2 talk submissions to #fwd:cloudsec just before the first round CFP closes. Hoping for good news, will be the perfect reason to finally attend in person! 000
Tal Skverer @taltechtreks.com · 24/02/2025Check out this wild project: #Steam #Brick. The author transformed the Steam Deck to a brick that still connects to screens or VR while reducing size by a third Projects like this (author used steam-provided data) are a great example of "right-to-own", critical to enhance electronics sustainabilitycrastinator-pro.github.ioNo screen, no controller, and absolutely no sense, just a power button and a USB port.Brick your Steam Deck - one way or another… 010
Tal Skverer @taltechtreks.com · 21/02/2025#OAuth #phishing apps are coming to get you - now on #X! It's annoying to see yet another case of how easy it is to fake consent screens that look identical to real companies. Why we still lack mandatory verification processes for new OAuth apps is beyond me. x.com/thealexbanks... 020
Tal Skverer @taltechtreks.com · 20/02/2025#OIDC identity providers in #AWS have been getting more attention lately and rightfully so: It’s unfortunately surprisingly easy (and common) to create misconfiguration within the necessary conditions on OIDC-based #IAM roles trust policy.offensai.comRogueOIDC: AWS Persistence and Evasion through attacker-controlled OIDC Identity ProviderThis research shows what an attacker can achieve after creating a malicious OIDC identity provider in AWS and how they can do it. The article presents novel techniques and tools for persistence and ev... 110
Tal Skverer @taltechtreks.com · 17/02/2025So, #OAuth implementations seem to always have some edge case or quirk making it vulnerable in odd ways. This particular exploit leveraged an open redirect in an app's OAuth callback, combined with #Google OAuth's quirks to steal authorization codes on visiting a malicious website.blog.voorivex.teamOAuth Non-Happy Path to ATOLearn how small errors in OAuth implementation can lead to significant security vulnerabilities like one-click account takeover in web applications 074
Tal Skverer @taltechtreks.com · 15/02/2025#DeepSeek roasts me based on my #UserAgent: Your browser history is so bare even your referrer ghosted you, your 2560x1440 screen is just compensating for how bland Firefox 134 on Windows 10 is, and 16 CPU cores in Tel Aviv? Congrats, you’re the NPC overclocking spreadsheets in the Silicon Wadi.jasonthorsness.comDeepSeek My User AgentDeepSeek My User Agent 021
Tal Skverer @taltechtreks.com · 14/02/2025Cute bit of #internet history, this post shows why #Git gives you 0.1 seconds to decide if it runs a fixed command. Turns out, backwards compatibility in code is hard, especially if the code is distributed widely, and can lead to these kind of funny instances (and other that can cause real damage)blog.gitbutler.comWhy is Git Autocorrect too fast for Formula One drivers?Why does Git's autocorrect wait 0.1s before executing a mistyped command? Let's dig in. 000
Tal Skverer @taltechtreks.com · 12/02/2025I love #hacking #embedded systems, and also #gaming when time permits. Imagine my delight seeing a post that blends both! Two decades after its release, someone revisits the idea of “just” using the original #Xbox CPU's #JTAG connector to debug it.blog.ret2.ioJTAG 'Hacking' the Original Xbox in 2023Released in November 2001, the original Xbox was Microsoft’s first venture into the game console industry. With its hardware closely resembling a cheap but v... 140
Tal Skverer @taltechtreks.com · 09/02/2025The Dead Internet Theory is just a meme, right? Well…something strange happens over at PhysicsForums. Once an active forum for physics students, now a quieter place. A year ago, posts appeared, made by users long after their last login. LLM-generated replies back-inserted into the DB Must read!hallofdreams.orgPhysicsForums and the Dead Internet TheoryAn exposé no one will read, about the widespread falsification of user posts in PhysicsForums, a scientific community founded in 2001. This is a microcosm of the death of the human-written Internet. 020
Tal Skverer @taltechtreks.com · 08/02/2025Still surprised with how people use LLMs for cool stuff. This one uses o1 and makes it play Codenames with itself. If you played it, you know it's tricky to give good hints, and o1 crushed it. Wonder how it works when not playing itself. If I played someone with my brain, the game would be easy :)suveenellawela.comCodenames AI - OpenAI's o1 Playing CodenamesI got OpenAI's o1 to play codenames and the results were surprisingly good 011
Tal Skverer @taltechtreks.com · 07/02/2025The #GPT #o1 model was very exciting initially, but I completely stopped using it. The long wait and the laziness of my prompts made the chat-based models much better. This post explains how to interact with o1. In short - it comes down to good #prompts so o1 one-shots the response.latent.spaceo1 isn’t a chat model (and that’s the point)How Ben Hylak turned from ol pro skeptic to fan by overcoming his skill issue. 000
Tal Skverer @taltechtreks.com · 04/02/2025Honey, wake up - #clickjacking is back. A decade ago, #clickjacking was the hot new #attack—tricking users into clicking invisible #frames layered over legit websites, unknowingly performing actions on their social media, corporate accounts, or even banks. 1/3paulosyibelo.comBlog: DoubleClickjacking: A New Era of UI Redressingdata:blog.metaDescription 131
Tal Skverer @taltechtreks.com · 02/02/2025#Hacker #News today: Well-written piece about a paper on #E2EE (end-to-end encryption) when it comes #AI. AI circled us back to the old problem: devices are too weak to handle computations, so we offload them to more powerful systems—essentially handing most sensitive data over to big data. (1/5)blog.cryptographyengineering.comLet’s talk about AI and end-to-end encryptionRecently I came across a fantastic new paper by a group of NYU and Cornell researchers entitled “How to think about end-to-end encryption and AI.” I’m extremely grateful to see th… 130
Tal Skverer @taltechtreks.com · 01/02/2025#Hacker #News daily: A month with Devin – an interesting log from a team that put one of the most hyped startups to the test. The conclusion? Potential is definitely there, but it’s still wrestling with similar challenges ML algos suffered from in the past - mostly the need to manually verify work.answer.aiThoughts On A Month With Devin – Answer.AIOur impressions of Devin after giving it 20+ tasks. 000
Reposted by Tal SkvererNathan McNulty @nathanmcnulty.com · 24/01/2025This provides important insights 💡 CA policies cannot block anything until AFTER authentication occurs This means CA cannot help with password spray/credential stuffing. This is why we have Password Protection and Smart Lockout. learn.microsoft.com/... learn.microsoft.com/...learn.microsoft.comPassword protection in Microsoft Entra ID - Microsoft Entra IDLearn how to dynamically ban weak passwords from your environment with Microsoft Entra Password Protection 1273
Tal Skverer @taltechtreks.com · 24/01/2025This old post from 2006 jumped on my feed and I recalled reading it back then, I wasn't too familiar with binary search, but was still shocked a simple #overflow bug was so prevalent. 20 years later, I totally see how generative #AI might cause thousands more of these issues to continuously pop upresearch.googleExtra, Extra - Read All About It: Nearly All Binary Searches and Mergesorts arePosted by Joshua Bloch, Software EngineerI remember vividly Jon Bentley's first Algorithms lecture at CMU, where he asked all of us incoming Ph.D. ... 0188
Tal Skverer @taltechtreks.com · 23/01/2025Oh boy, Sam Curry comes again with yet another critical #vulnerability, now in Subaru vehicles, basically allowing full remote control over the cars. #Automotive security is no joke, but manufacturer's still live by security standards from the beginning of the century. samcurry.net/hacking-subarusamcurry.netHacking Subaru: Tracking and Controlling Cars via the STARLINK Admin PanelOn November 20, 2024, Shubham Shah and I discovered a security vulnerability in Subaru’s STARLINK admin panel that gave us unrestricted access to all vehicles and customer accounts in the United State... 1155
Reposted by Tal SkvererOWASP® Foundation @owasp.org · 17/01/2025Got secrets? An API? Tokens? Or a fancy new AI bot? The OWASP NHI Project team just dropped the Non-Human Identities Top 10 Project, breaking down the biggest risks + how to secure them. :closed_lock_with_key: Check it out here: t.co/wmUD9x9sJOt.coOWASP Non-Human Identities Top 10 | OWASP FoundationThe primary goal of the 0135
Tal Skverer @taltechtreks.com · 12/01/2025#Hacker #News daily: Sometimes, you read amazing things online and just go with: What. This is one of these things. Apparently, it's entirely feasible for build a functional CPU using...regex? This madman has built it, and an entire chess engine on top of it. Simply incredible.nicholas.carlini.com Regex Chess: A 2-ply minimax chess engine in 84,688 regular expressions I wrote a (list of) regular expressions that will play a (not very good) chess game by running a 2-ply minimax search. 010
Tal Skverer @taltechtreks.com · 08/01/2025Excited to introduce the #OWASP Non-Human Identities Top 10 for 2025! 🚀 What risks do devs face using non-human identities? I tackled this together with other experts to shine light on this emerging issue. Check out the project's page for a sneak peek, or click on top to dive deeper into the risksowasp.orgOWASP Non-Human Identities Top 10 | OWASP FoundationThe primary goal of the 083
Tal Skverer @taltechtreks.com · 08/01/2025#Hacker #News daily: these 24 fun facts about SQLite, the most used database engine today. My favorites? #7/8 - It's not easy to contribute code to SQLite. #14 - Reading/writing blobs with SQLite can be faster than `fread` #19 - The reason why the prefix for temp files is `sqlite_` backwardsavi.imCollection of insane and fun facts about SQLite - blagSome of the interesting and insane facts I learned about SQLite 020
Tal Skverer @taltechtreks.com · 05/01/2025Back with some #Hacker #News. This time - some theory! I really like clustering algorithms. They tend to make order into data that can be really confusing. This blog explores a very important theorem from 2002 - showing no clustering algorithm can essentially fulfill all we want from it. (1/3)blog.codingconfessions.comThe CAP Theorem of Clustering: Why Every Algorithm Must Sacrifice SomethingNo clustering algorithm is perfect and you must make a trade-off. 230
Tal Skverer @taltechtreks.com · 27/12/2024Been a while since I've read some papers. My #LLM based monitoring pinged this paper on solutions for distributed cloud. Here's my review. #CompSky Token-based identity management in the distributed cloud A short article proposing a method for #IAM on #distributed #cloud environments. (1/5)arxiv.org 160
Reposted by Tal SkvererMartijn Grooten @martijngrooten.bsky.social · 24/12/2024I love the annual tradition of @lorenzofb.bsky.social @zackwhittaker.bsky.social and @carlypage.bsky.social highlighting the best cybersecurity stories (and, in quite a few cases, thorough investigations) that other people wrote techcrunch.com/2024/12/24/t...techcrunch.comThese are the cybersecurity stories we were jealous of in 2024 | TechCrunchThe very best work from our friends at competing publications. 02110
Tal Skverer @taltechtreks.com · 25/12/2024#Hacker #News daily: a directory for hosting verified SSH keys to email mapping. Might currently be a little niche, but I think that a wide adoption of this could ease both user management for SSH servers, and for CLI applications.keypub.sh 1162
Tal Skverer @taltechtreks.com · 21/12/2024#Hacker #News Daily: This time, turns out the internet is full of wrong bi-directional BFS implementations! This exceptional blog post covers the issue from the very beginning. Definitely worth reading! zdimension.fr/everyone-get... (1/4)zdimension.frEveryone gets bidirectional BFS wrongPeople really need to stop blindly copying code from the Internet. 140
Tal Skverer @taltechtreks.com · 19/12/2024Today, rspack, a rust-based tool that helps speed up the process of preparing code for websites and apps, has announced a compromise to two of their packages - rspack/core and rspack/cli. github.com/web-infra-de...github.comRelease v1.1.8 · web-infra-dev/rspackSecurity Vulnerability Report Overview This is a re-release version of 1.1.6 On 12/19/2024, 02:01 (UTC), we discovered that our npm packages @rspack/core and @rspack/cli were maliciously attacked. ... 100