Tal Skverer @taltechtreks.com · 27/04/2026Can't share more right now, but expect some announcements regarding a conference talk about this soon! 😉 000
Tal Skverer @taltechtreks.com · 27/04/2026This change follows a finding from last year by the amazing research team here at Astrix. This turned out to be a vulnerability with real, broad impact on organizations across the world, exploitable with zero prior access and public reconnaissance only. 100
Tal Skverer @taltechtreks.com · 27/04/2026Look what just landed in GitHub's changelog 👀 A well-needed change to how GitHub Actions constructs the sub claim in its OIDC tokens, making OIDC trust relationships more secure for organizations by embedding immutable identifiers in the claim. 111
Tal Skverer @taltechtreks.com · 29/11/2025It happened! My #DEFCON 33 talk on hacking Pokémon Go is live! Looking back, it was an absolute pleasure to dip into that 2016 nostalgia and share with the security community the untold story of Team Unknown6, on stage in front of a packed full audience. m.youtube.com/watch?v=2En9...m.youtube.comDEF CON 33 - Breakin 'Em All – Overcoming Pokemon Go's Anti Cheat Mechanism - Tal SkvererYouTube video by DEFCONConference 020
Tal Skverer @taltechtreks.com · 28/10/2025Amazing vibe and crowd at Reversim Summit today! I'm so humbled to be here and present my research to you all! 000
Tal Skverer @taltechtreks.com · 28/10/2025וואו, איזה אווירה ואיזה קהל ב-Reversim Summit היום! שמחתי מאוד על הזכות להיות פה ולהציג בפניכם את המחקר שלי, תודה! 120
Tal Skverer @taltechtreks.com · 27/10/2025So happy the Reveresim Summit is here! It’s always such a great event with awesome talks. This year is extra special because I get to speak for the first time! Come hear about Android hacking, and how I spent summer 2016 breaking into Pokémon Go. Tomorrow, October 27th, at 13:20 in the main hall! 000
Tal Skverer @taltechtreks.com · 27/10/2025איזה כיף שהגיע הכנס השנתי של Reversim Summit! כנס שתמיד נהדר להיות בו עם הרצאות מעניינות ומעולות, והפעם הוא מתוק במיוחד כי יוצא לי להרצות בו בפעם הראשונה! מוזמנים לבוא לשמוע על איך נראה האקינג למשחקי אנדרואיד, ואיך ביליתי את ימי הקיץ אי שם ב2016 כדי לפרוץ לפוקימון גו. מחר, 27/10, ב13:20 באולם הגדול! 110
Tal Skverer @taltechtreks.com · 24/10/2025Had a great time presenting the OWASP Top 10 NHI Project today at #LASCON Austin with Tomer Yahalom! We've had the pleasure to give the talk to a great crowd and amazing people. Looking forward to the second day filled with interesting talks! 010
Tal Skverer @taltechtreks.com · 16/10/2025Today, we released an open-source tool to help mitigate some of the security implications of today's #MCP server implementations: the "MCP Secret Wrapper", which in a simple 2-step flow, removes those pesky static credentials from your configuration files! github.com/astrix-secur...github.comGitHub - astrix-security/mcp-secret-wrapper: Astrix Security MCP Secret WrapperAstrix Security MCP Secret Wrapper. Contribute to astrix-security/mcp-secret-wrapper development by creating an account on GitHub. 010
Tal Skverer @taltechtreks.com · 16/10/2025Our analysis discovered that the majority of servers rely on long-lived API keys or credentials given to them through static configuration files. This unfortunate side effect of the rush to use #AI #Agents comes at a cost by downgrading security. 100
Tal Skverer @taltechtreks.com · 16/10/2025The #MCP framework took the world by storm. But is it safe? We downloaded over 5 thousand of the highest starred MCP implementations to answer that question! astrix.security/learn/blog/s...astrix.securityState of MCP Server Security 2025: Research Report | Astrix5K+ MCP servers analysis: 53% use insecure hard-coded credentials. Read the full 2025 research and download the open-source MCP Secret Wrapper to mitigate risks. 100
Tal Skverer @taltechtreks.com · 20/08/2025A few years later (and I still can't quite believe this is happening) I'm going to be that person on stage! So, despite me, I'll be presenting my research on the main stage on the second day (Tuesday, 28/10) at 13:20. Hope to see you there! 000
Tal Skverer @taltechtreks.com · 20/08/2025The first Reversim I attended was actually one of the first conferences I'd ever been to. I distinctly remember sitting in the audience, watching a speaker present their cool project, and thinking how incredible it must feel to be up there on stage sharing your work with such an engaged crowd. 100
Tal Skverer @taltechtreks.com · 20/08/2025I am absolutely delighted to share that I'll be giving a talk at Reversim Summit 2025 on breaking Pokémon Go's anti-cheating mechanism! On a personal note, every time I visit Reversim, it shows me just how awesome, welcoming, and genuinely interesting community-driven events can be. 110
Tal Skverer @taltechtreks.com · 09/08/2025Breaking 'Em All! The blog posts going deeper into hacking Pokemon Go that accompany my #DEFCON talk are live on my blog! taltechtreks.com/2024/04/06/H... taltechtreks.com/2025/08/09/H... Happy to get questions on the research!taltechtreks.comBreaking Pokémon Go Anti-Cheating System - Part 2Overcoming Niantic's Anti Cheating Mechanism 061
Tal Skverer @taltechtreks.com · 09/08/2025Talking in an hour at #DEFCON about Pokemon Go on track 3. Couldn't be more excited! I've worked on it multiple nights in the past months, and I hope you'll enjoy it! If you're not here in person, you can catch the talk live at www.youtube.com/live/fzbrrKP... or www.twitch.tv/defcon_dctv_...twitch.tvDEFCON_DCTV_Three - TwitchDEFCON TV Channel 3: Track 3 Talks 051
Tal Skverer @taltechtreks.com · 09/08/2025Giving a talk on Pokemon Go, I just had to convert myself to a Pokemon trainer. The amazing Ryan Rockenbaugh surprised me with a limited edition sticker of Trainer Tal Sticker wall at #DEFCON got 2, and I will be giving what's left tomorrow at my talk Breaking 'Em All! 11:30 Track 3. See you! 060
Tal Skverer @taltechtreks.com · 07/08/2025Excited and humbled to speak once again in DEF CON. Talk is on Saturday at 11:30, track 3. I'll be in the conf till Sunday, hit me up if you want to chat over the talk or any other project. 020
Tal Skverer @taltechtreks.com · 22/07/2025The #DEFCON 33 schedule is live and I'm excited to announce I'll be giving a talk this year on unique research I was a part of a few years back! "Breakin 'Em All – Overcoming Pokémon Go's Anti-Cheat Mechanism" Join me on stage - Sat, 11:30 AM, Track 3 defcon.org/html/defcon-... 011
Tal Skverer @taltechtreks.com · 11/06/2025Looks like I'll be at Hacker Summer Camp this year! Exciting #DEFCON33 ☺ 050
Tal Skverer @taltechtreks.com · 06/06/2025Just got back from #AppSecIL2025! Ended up 4th place in the #CTF 🎉 Solved 12/15 challenges alone - Android pwn, JS sandbox escapes, cache poisoning, XSS bypasses. The usual suspects: SQLi, LDAP injection, XXE. Had a blast! Looking forward to the next one. Writeup: taltechtreks.com/2025/06/04/a...taltechtreks.comAppSec IL 2025 CTF - WriteupA writeup on all challenges I solved in the 2025 OWASP CTF 021
Tal Skverer @taltechtreks.com · 20/05/2025I'm building something cute and new, but as opposed to my normal ways, this time I'm using #Cursor heavily and the flow blows my mind. Although I'm certain that without prior good knowledge of coding it wouldn't work that well. 000
Tal Skverer @taltechtreks.com · 02/05/2025Ah, I wondered when this was due to come out. Can't wait to experiment! www.anthropic.com/news/integra...anthropic.comClaude can now connect to your worldToday we're announcing Integrations, a new way to connect your apps and tools to Claude. We're also expanding Claude's Research capabilities with an advanced mode that searches the web, your Google Wo... 000
Tal Skverer @taltechtreks.com · 01/05/2025Excited to present my research tomorrow at #RSAC! Come by to hear John and me share conclusions and insights on the first publicly available report on Non-Human identity security! See you there, May 1, 10:50 am at Moscone West 3004! 030
Tal Skverer @taltechtreks.com · 23/04/2025For today, a bit Friends content! Or, uhh, actually, computer science! What’s the largest sofa you can pivot around a corner? Heard about this problem in the past, but I thought it's one of those we will never be able to prove. (At least until quantum computers arrive to solve some NP problems)quantamagazine.orgThe Largest Sofa You Can Move Around a Corner | Quanta MagazineA new proof reveals the answer to the decades-old “moving sofa” problem. It highlights how even the simplest optimization problems can have counterintuitive answers. 010
Tal Skverer @taltechtreks.com · 17/04/2025Took a bit of hiatus from posting here, was quite busy the past few months (CFP season amiright…) But I do have more cool stuff ready for sharing as well as writing 2 blog posts about projects I worked on lately. Looking forward to sharing with you all 000
Tal Skverer @taltechtreks.com · 14/03/2025Great time presenting OWASP NHI Top 10 at #SnowFROC! If you're here, come say hi! 000
Tal Skverer @taltechtreks.com · 08/03/2025Well, that was an hour of my life well spent. An amazing adaptation of minesweeper to include old-school RPG elements. UPDATE: Had to go back and play, another 4 hours to achieve a perfect clear. Incredible game!danielben.itch.ioDragonsweeper by Daniel BenmerguiA roguelike minesweeper adventure 010
Tal Skverer @taltechtreks.com · 06/03/2025Great thread on the emerging new details on the ByBit breach 000
Tal Skverer @taltechtreks.com · 28/02/2025A cute post showcasing the basis of every website - HTML! The site goes over (almost) all HTML tags, by using them. Seeing this, it’s unfortunate that text inputs in websites don't allow most tags but rather encapsulate how the final result is displayed for users. Give us more, please!iamwillwang.comEvery HTML Element 010
Tal Skverer @taltechtreks.com · 27/02/2025Managed to squeeze in 2 talk submissions to #fwd:cloudsec just before the first round CFP closes. Hoping for good news, will be the perfect reason to finally attend in person! 000
Tal Skverer @taltechtreks.com · 24/02/2025Check out this wild project: #Steam #Brick. The author transformed the Steam Deck to a brick that still connects to screens or VR while reducing size by a third Projects like this (author used steam-provided data) are a great example of "right-to-own", critical to enhance electronics sustainabilitycrastinator-pro.github.ioNo screen, no controller, and absolutely no sense, just a power button and a USB port.Brick your Steam Deck - one way or another… 010
Tal Skverer @taltechtreks.com · 24/02/2025Thanks for the shout-out! Happy to see the starterpack in use 😁 010
Tal Skverer @taltechtreks.com · 21/02/2025#OAuth #phishing apps are coming to get you - now on #X! It's annoying to see yet another case of how easy it is to fake consent screens that look identical to real companies. Why we still lack mandatory verification processes for new OAuth apps is beyond me. x.com/thealexbanks... 020
Tal Skverer @taltechtreks.com · 20/02/2025This researcher found a clever persistence trick: create a rogue #OIDC provider mimicking an existing one, then silently tweak the conditions. Easy to miss, but it lets an attacker retain access to a compromised account. How many orgs actually audit their OIDC roles? Feels like a blind spot. 000
Tal Skverer @taltechtreks.com · 20/02/2025#OIDC identity providers in #AWS have been getting more attention lately and rightfully so: It’s unfortunately surprisingly easy (and common) to create misconfiguration within the necessary conditions on OIDC-based #IAM roles trust policy.offensai.comRogueOIDC: AWS Persistence and Evasion through attacker-controlled OIDC Identity ProviderThis research shows what an attacker can achieve after creating a malicious OIDC identity provider in AWS and how they can do it. The article presents novel techniques and tools for persistence and ev... 110
Tal Skverer @taltechtreks.com · 17/02/2025So, #OAuth implementations seem to always have some edge case or quirk making it vulnerable in odd ways. This particular exploit leveraged an open redirect in an app's OAuth callback, combined with #Google OAuth's quirks to steal authorization codes on visiting a malicious website.blog.voorivex.teamOAuth Non-Happy Path to ATOLearn how small errors in OAuth implementation can lead to significant security vulnerabilities like one-click account takeover in web applications 074
Tal Skverer @taltechtreks.com · 15/02/2025#DeepSeek roasts me based on my #UserAgent: Your browser history is so bare even your referrer ghosted you, your 2560x1440 screen is just compensating for how bland Firefox 134 on Windows 10 is, and 16 CPU cores in Tel Aviv? Congrats, you’re the NPC overclocking spreadsheets in the Silicon Wadi.jasonthorsness.comDeepSeek My User AgentDeepSeek My User Agent 021
Tal Skverer @taltechtreks.com · 14/02/2025Cute bit of #internet history, this post shows why #Git gives you 0.1 seconds to decide if it runs a fixed command. Turns out, backwards compatibility in code is hard, especially if the code is distributed widely, and can lead to these kind of funny instances (and other that can cause real damage)blog.gitbutler.comWhy is Git Autocorrect too fast for Formula One drivers?Why does Git's autocorrect wait 0.1s before executing a mistyped command? Let's dig in. 000
Tal Skverer @taltechtreks.com · 12/02/2025The author created a CPU #JTAG breakout and by inserting it between the balls and the CPU—manages to successfully debug the Xbox and extract the holy grail—a secret 512-byte boot ROM. This ROM was originally extracted in other methods which allowed #Jailbreaking the #Xbox in the first place. 000
Tal Skverer @taltechtreks.com · 12/02/2025Of course, it can't that simple. #Microsoft took a straightforward but effective countermeasure—grounding the #TRST pin, effectively locking out #JTAG access on retail consoles. Additionally, the #CPU is soldered on a ball-grid-array, making direct patching nearly impossible. But - there’s a way! 101
Tal Skverer @taltechtreks.com · 12/02/2025I love #hacking #embedded systems, and also #gaming when time permits. Imagine my delight seeing a post that blends both! Two decades after its release, someone revisits the idea of “just” using the original #Xbox CPU's #JTAG connector to debug it.blog.ret2.ioJTAG 'Hacking' the Original Xbox in 2023Released in November 2001, the original Xbox was Microsoft’s first venture into the game console industry. With its hardware closely resembling a cheap but v... 140
Tal Skverer @taltechtreks.com · 09/02/2025The Dead Internet Theory is just a meme, right? Well…something strange happens over at PhysicsForums. Once an active forum for physics students, now a quieter place. A year ago, posts appeared, made by users long after their last login. LLM-generated replies back-inserted into the DB Must read!hallofdreams.orgPhysicsForums and the Dead Internet TheoryAn exposé no one will read, about the widespread falsification of user posts in PhysicsForums, a scientific community founded in 2001. This is a microcosm of the death of the human-written Internet. 020
Tal Skverer @taltechtreks.com · 08/02/2025Still surprised with how people use LLMs for cool stuff. This one uses o1 and makes it play Codenames with itself. If you played it, you know it's tricky to give good hints, and o1 crushed it. Wonder how it works when not playing itself. If I played someone with my brain, the game would be easy :)suveenellawela.comCodenames AI - OpenAI's o1 Playing CodenamesI got OpenAI's o1 to play codenames and the results were surprisingly good 011
Tal Skverer @taltechtreks.com · 07/02/2025The #GPT #o1 model was very exciting initially, but I completely stopped using it. The long wait and the laziness of my prompts made the chat-based models much better. This post explains how to interact with o1. In short - it comes down to good #prompts so o1 one-shots the response.latent.spaceo1 isn’t a chat model (and that’s the point)How Ben Hylak turned from ol pro skeptic to fan by overcoming his skill issue. 000
Tal Skverer @taltechtreks.com · 04/02/2025Using the technique on a newly opened window, the first click closes it, underneath is an #authorization button that the second click presses, approving access for a #malicious app. Pretty clever—and hopefully, defenses catch up before this trick gets widely abused. 3/3 010
Tal Skverer @taltechtreks.com · 04/02/2025Over time, defenses evolved: #CSRF protections, X-Frame-Options to prevent framing, and SameSite: Lax cookies to block cross-site authentication made clickjacking obsolete. But guess what? It’s back — #DoubleClickjacking bypasses these defenses #exploiting how #browsers handle mouse events. 2/3 110